logo

Modern Malware — Spyware Skills, Hijacked Base URLs, and 1,230+ Leaking API Keys in AI Instruction Files

ID: 36e94f9b-7cbc-57e4-b902-b2089601bcaf

STIX ID: report--36e94f9b-7cbc-57e4-b902-b2089601bcaf

Feed Name: Mitiga

Threat Score
75/100

Date Published: 2026-07-16

Date Updated: 2026-07-29

...
...

Mitiga Labs documents a new class of supply-chain and agent-targeting threats delivered via AI instruction files (skills, hooks, CLAUDE/AGENTS.md, MCP configs and related artifacts) that can exfiltrate developer prompts, proxy agent traffic through attacker-controlled endpoints, and expose hardcoded credentials; the team scanned ~50,000 files across 7,000+ repos, found widespread risky configurations and 1,230+ hardcoded keys, and released the free Skillgate scanner to detect these techniques and recommend mitigation workflows.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.