Promptware: Trojanized AI Skills Targeting skills.sh and GitHub
A novel supply chain attack campaign, dubbed "Promptware," has compromised the AI agent ecosystem via typosquatted skills on skills.sh and GitHub. Adversaries impersonated legitimate services like Paperclip AI and Browser Use to distribute credential-stealing payloads. The campaign utilizes a "progressive discovery" technique, where malicious instructions are embedded in secondary documentation files (e.g., setup-installation.md) to bypass static analysis and LLM context window limitations. Instead of standard package managers, the prompts trick AI agents into cloning malicious repositories and executing pnmp dev, facilitating the theft of SSH keys, cloud credentials, and Kubernetes/Docker configurations across platforms like Claude Code and Cursor.