Summary
Experts warn that malicious AI skills are increasingly being used in supply chain attacks, with researchers at Zenity Labs uncovering a credential-stealing campaign on skills.sh where cloned AI skills were later updated with malicious code, leading to millions of installs and dozens of dangerous variants.