Original sourceCyber Security News
Summary
Researchers have uncovered malicious skill kits targeting Claude Code and OpenAI Codex, using structural obfuscation and self-extracting techniques to bypass eight common scanners, with hidden malicious code capable of stealing developer keys and crypto wallets.
Key points
- Alerts developers to supply chain risks in AI coding tool skill marketplaces, providing specific defense recommendations.
- AI coding skills become a new attack surface; malicious skills can bypass existing scanners, requiring heightened developer vigilance.
- Developers should avoid auto-executing unknown skills, use sandbox behavior analysis, and manually review skill source code.
- Similar to npm supply chain attacks, but this targets AI agent skill marketplaces, with a newer attack surface and stronger evasion capabilities.
Editorial note
This page is Code & Chain's editorial summary of public sources. It may be prepared with AI assistance and published through an automated workflow. Refer to the original sources; this content is not investment, legal, or tax advice.