Trojanized Paperclip and Browser Use skills hit 1.7 million installs: why it is not safe to use
Malicious lookalike AI skills for Paperclip and Browser Use were downloaded heavily before reports linked them to credential theft.
What happened
Security firm Zenity reported an active malware campaign involving fake, lookalike skills for Paperclip and Browser Use on the skills.sh marketplace. A trojanized skill is a tool that appears useful but secretly runs harmful code. Zenity says the skills were later weaponized on July 11, 2026 and kept trending through July. By August 2, the listed install counters totaled more than 1.7 million, although Zenity says those numbers were not unique-user counts.
According to Zenity, the skills told AI agents to fetch and run a payload designed to steal credentials, which are secrets used to sign in or access systems. The reported targets included SSH keys, cloud credentials, Git and package-manager tokens, Kubernetes and Docker configuration files, and project .env files. CSO reported that individual skills reached roughly 300,000 installs each and said the campaign targeted ecosystems used with tools including Claude Code and OpenAI Codex.
What it means for you
If you use an AI agent with third-party skills, a popular listing is not the same as a safe one. A malicious skill may ask the agent to access local files, development secrets, or cloud settings that you did not expect it to touch.
What to do instead
Use skills only from sources you trust and review what a skill is supposed to do before installing it. Be careful with lookalike names and unexpected updates. Limit which folders, keys, and cloud accounts your agent can access. Rotate exposed tokens or keys if you think a risky skill may have run. AgentPod lists only reviewed, tested skills, but you should still keep permissions narrow and remove tools you do not need.
Sources:
- https://labs.zenity.io/post/attackers-target-agents-via-the-skill-supply-chain
- https://www.csoonline.com/article/4206851/trojanized-ai-skills-gain-1-7m-installs-in-agent-targeted-attack.html
Source: https://labs.zenity.io/post/attackers-target-agents-via-the-skill-supply-chain
We report what our security review found at the time we checked, with the goal of keeping people safe. Projects change; if a maintainer has since fixed this, we are glad to recheck it. Email hello@agentpod.com.