Skip to content
Malicious AI Skill Compromises 26,000 Users by Bypassing Security Checks

Malicious AI Skill Compromises 26,000 Users by Bypassing Security Checks

First seen 23 Jun 2026, 21:30 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •June 24, 2026 at 20:28 UTC
  • •A malicious AI skill reached over 26,000 users by bypassing security checks.
  • •The skill exploited external hosting for malicious instructions, evading detection.
  • •Security assessments need to evolve to address dynamic behaviors of AI skills.

A security experiment revealed that a malicious AI agent skill, named 'brand-landingpage', successfully bypassed security checks and reached over 26,000 users. The skill was designed to appear legitimate, targeting non-technical corporate users. By hosting malicious instructions externally, the attackers evaded detection by major security scanners from Cisco, Nvidia, and others. The skill initially collected users' email addresses but could have been used to compromise systems further. Researchers from AIR conducted this test to highlight vulnerabilities in AI agent ecosystems, emphasizing that skills should be treated as part of the software supply chain. The experiment demonstrated that security assessments based solely on static reviews are insufficient. No agents were harmed during the research, and AIR stated that the malicious behavior could change after trust was granted.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 108d ago How this analysis works

Timeline

2026-06-23
Malicious AI skill launched via Instagram ad
The 'brand-landingpage' skill was promoted through an Instagram ad, attracting over 26,000 users.
Feeds.4Sysops
2026-06-24
Security experiment reveals vulnerabilities
AIR's experiment showed that the malicious skill could bypass security scanners and change behavior post-installation.
Csoonline
2026-06-24
Research highlights AI skill risks
The experiment indicated that AI skills should be treated as part of the enterprise software supply chain.
Cybersecuritynews

More articles in this cluster (4)