logo

Cybercriminals Plant Malicious AI Agents in Open Source Tool Repositories

ID: fd14a587-6894-5c44-a6df-852e170a4d62

STIX ID: report--fd14a587-6894-5c44-a6df-852e170a4d62

Feed Name: Infosecurity Magazine (News)

Threat Score
70/100

Date Published: 2026-07-09

Date Updated: 2026-07-19

...
...

ESET analyzed 900,000 AI agent skills and found a rapid increase in suspicious and malicious toolsets—suspicious skills rose from ~10,000 to >25,000 and malicious ones from ~600 to >3,000—capable of browsing the web, executing commands, exfiltrating data, and deploying credential-stealing tools like Mimikatz; the report warns this proliferation of agentic AI tools expands the attack surface and urges organizations to restrict untrusted tools and enforce controls.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.