Modern Malware — Spyware Skills, Hijacked Base URLs, and 1,230+ Leaking API Keys in AI Instruction Files
ID: 36e94f9b-7cbc-57e4-b902-b2089601bcaf
STIX ID: report--36e94f9b-7cbc-57e4-b902-b2089601bcaf
Feed Name: Mitiga
Mitiga Labs documents a new class of supply-chain and agent-targeting threats delivered via AI instruction files (skills, hooks, CLAUDE/AGENTS.md, MCP configs and related artifacts) that can exfiltrate developer prompts, proxy agent traffic through attacker-controlled endpoints, and expose hardcoded credentials; the team scanned ~50,000 files across 7,000+ repos, found widespread risky configurations and 1,230+ hardcoded keys, and released the free Skillgate scanner to detect these techniques and recommend mitigation workflows.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
