Security firm Zenity Labs uncovered a supply-chain campaign in which attackers created lookalike GitHub organizations impersonating the AI tools Paperclip and Browser Use, then uploaded trojanized “skills” (agent configuration/instruction files) to the skills.sh marketplace. The malicious skills initially appeared as faithful copies of the legitimate tools to build install counts and trust before being modified to deploy a credential stealer targeting SSH keys, cloud credentials, Git and package-manager tokens, Kubernetes/Docker configuration, and .env files on developer workstations, CI runners, and agent workspaces. Uploaded around July 11, 2026, the skills accumulated more than 1.7 million downloads before Vercel and GitHub removed the listings and repositories within 12 hours of being notified.