正在開啟 SecureFlow仿冒 Agent Skill:先累積人氣,再換成惡意內容竊取憑證
案例摘要與來源

AIDEFEND SecureFlow / SecureFlow 案例索引

Zenity Labs aidefend-sf0032

仿冒 Agent Skill:先累積人氣,再換成惡意內容竊取憑證

  • 自主式 agent
  • AI 供應鏈
  • 憑證與身分竊取
  • 資料外洩

skills.sh 是讓使用者尋找 Agent Skill 的公開登錄平台;Agent Skill 是供 AI Agent 載入的工作說明與工具設定。攻擊者建立仿冒 Paperclip 與 Browser Use Agent 專案的資產;Paperclip Skill 先以正常文件累積顯示安裝次數,之後才換成惡意設定指令,Browser Use 誘餌則安裝含木馬的 PyPI 套件。兩條路徑最後都執行憑證竊取程式,並把 Base64 編碼的純文字資料送到攻擊者端點。

對應的威脅技術

  • AML.T0074 Masquerading
  • AML.T0111 AI Supply Chain Reputation Inflation
  • AML.T0109 AI Supply Chain Rug Pull
  • AML.T0110.000 AI Agent Tool Poisoning: Definition and Instructions
  • AML.T0011.002 User Execution: Poisoned AI Agent Tool
  • AML.T0050 Command and Scripting Interpreter
  • AML.T0055 Unsecured Credentials
  • AML.T0025 Exfiltration via Cyber Means

來源