AI Agent Baiting: Forging AI Skills to Inject Malicious Code
Most victims are small and medium-sized tech teams and independent developers who blindly adopt third-party AI skill packages in their pursuit of model performance optimization. Furthermore, enterprise platform engineers—lacking strict dependency management and code auditing—have mistakenly planted hidden backdoors into production environments. Additionally, amateur programmers unfamiliar with secure search methods can download malicious plugins and inadvertently become tools for attackers, making them susceptible to exploitation by fraud syndicates. Common traits include a lack of dependency auditing and signature verification processes, alongside an over-reliance on external skill packages (summarized from source accounts, independently unverified).
Key Fields
FIELD STAMPSWho Gets Targeted
Most victims are small and medium-sized tech teams and independent developers who blindly adopt third-party AI skill packages in their pursuit of model performance optimization. Furthermore, enterprise platform engineers—lacking strict dependency management and code auditing—have mistakenly planted hidden backdoors into production environments. Additionally, amateur programmers unfamiliar with secure search methods can download malicious plugins and inadvertently become tools for attackers, making them susceptible to exploitation by fraud syndicates. Common traits include a lack of dependency auditing and signature verification processes, alongside an over-reliance on external skill packages (summarized from source accounts, independently unverified).
骗局怎么运作
- Create Fake AI Skill Projects: Fraudsters publish a downgraded 'AI skill' claiming to significantly improve model performance on well-known AI skill sharing platforms (such as GitHub), providing complete source code and trial reports to entice ecosystem developers to download it.
- Supply Chain Poisoning: Embed malicious scripts within the project, utilizing CI/CD pipelines to automatically inject malicious code into payload dependency submodules or the dependency chains of other projects, ensuring subsequent users execute the malicious code without their knowledge.
- Guided Propagation and Social Deception: Promote the skill through technical communities, Telegram discussion groups, tech blogs, and other channels, claiming it can 'one-click' boost model accuracy and offset manual tuning costs, encouraging teams to integrate it into production projects to create information resonance.
- Backdoor Implantation and Data Theft: The malicious script secretly connects to a remote control server in an encrypted manner, steals project credentials, sensitive configurations, or directly executes commands to covertly collect and upload user information, and even initiates other mining pool programs.
- Evasion and Cleanup: Once deployed, attackers can instantly modify source code files or delete projects, utilizing repository deletion or renaming to evade security scans. Meanwhile, slow community responses often mean that discoveries are made only after losses have already occurred.
红旗信号(看到这些快跑)
- 🚩 The project claims massive performance gains, yet lacks publicly reproducible evaluation reports or comparative data against mainstream models.
- 🚩 The publisher requires registration for direct use, or demands an API Key upon release to access additional features, accompanied by abnormal permission requests.
- 🚩 Repository links are frequently reposted to technical forums and Telegram groups with an exaggerated, rushed promotional tone emphasizing 'limited-time free' or 'invite-only users'.
- 🚩 The source code hides anonymous network requests, Socket connections, or common backdoor programs (such as reverse shells) with logs compressed and encrypted.
- 🚩 The project goes black shortly after release, or the author suddenly loses contact with a drastic drop in update frequency, and communication channels are forcibly transferred to less common instant messaging tools.
真实案例
- Other cases of counterfeit skill packages utilize technical communities and blogs for traffic diversion, enticing integration via limited-time free and invitation-only rhetoric, with actual behaviors matching the aforementioned poisoning chain (summarized from source accounts, independently unverified).
- In September 2025, the self-replicating worm Shai-Hulud swept through the npm software supply chain: at least 187 code packages distributed via the JavaScript repository npm were implanted with self-replicating worms. After developers installed infected packages, the malware searched for npm tokens in the environment and stole developer credentials to publish on GitHub. Multiple code packages from security vendor CrowdStrike were also briefly compromised. The Cybersecurity and Infrastructure Security Agency (CISA) issued an alert regarding this incident. (Source: [https://krebsonsecurity.com/2025/09/self-replicating-worm-hits-180-software-packages/](https://krebsonsecurity.com/2025/09/self-replicating-worm-hits-180-software-packages/))
- In September 2025, security firm Socket disclosed another npm supply chain poisoning incident: over 40 npm packages belonging to different maintainers were implanted with bundle.js malicious code, which downloaded package files, tampered with package.json, and republished them to achieve automatic trojanization of downstream packages. Attackers used the TruffleHog credential scanner to scrape keys from developers' machines and transmit them back to external servers, affecting both Windows and Linux systems. (Source: [https://thehackernews.com/2025/09/40-npm-packages-compromised-in-supply.html](https://thehackernews.com/2025/09/40-npm-packages-compromised-in-supply.html))
Official Stance
- On July 22, 2026, Tempest's '800 Fake AI Skills and MCP Servers' disclosed how the AI agent expansion ecosystem was turned into a malware supply chain (media disclosure account, as of July 2026). Source: [https://blog.jiayun.info/2026/07/tempest-deep-dive-2026-07-22-d1c434e53d12/](https://blog.jiayun.info/2026/07/tempest-deep-dive-2026-07-22-d1c434e53d12/)
- On July 28, 2026, CN-SEC's 'Behind AgentBaiting and 7,600 Malicious Repositories' disclosed over 800 repositories disguised as AI Skills or MCP servers, with Release downloads exceeding 14 million times (media disclosure account, as of July 2026). Source: [https://cn-sec.com/archives/5365663.html](https://cn-sec.com/archives/5365663.html)
- On August 7, 2026, 80aj's 'Beware of AI Account Trading Scams' cross-cited a Linux.do exposure: Telegram ad groups offering a 500 RMB Claude 20X Max black-market top-up service were empty shell phishing operations (media cross-cited account, as of August 2026). Source: [https://www.80aj.com/2026/08/07/ai-scam-telegram-claude/](https://www.80aj.com/2026/08/07/ai-scam-telegram-claude/)
How to Protect Yourself
- ✅ Trust only official or authoritative platform AI skill packages, verify author information and project review status, and avoid using unsigned third-party repositories.
- ✅ Integrate code auditing and static scanning tools into CI/CD pipelines to perform integrity verification and compliance checks on newly added dependencies.
- ✅ Reference the checklist disclosed by Island: check recent changes to the Skill directory and MCP configuration files, confirming the absence of unreviewed new entries before installation and execution. Source: [https://cn-sec.com/archives/5365663.html](https://cn-sec.com/archives/5365663.html)