Infosecurity

Cybercriminals Are Planting Malicious AI Agents in Open Source Repositories — Here’s What That Means

Published

on

AI Agents: The New Frontier for Cyberattacks

Cybercriminals have found a fresh playground: open source repositories hosting AI agents and chatbots. According to a new analysis from cybersecurity firm ESET, these platforms are now littered with malicious AI tools designed to automate attacks.

Researchers at ESET scanned 900,000 AI skills — small functional components that power AI agents — listed in public repositories. What they found is alarming: tens of thousands of suspicious entries and thousands of outright malicious ones.

The findings come from ESET’s threat report for the first half of 2026, published on July 8. The report warns that the growing availability of these tools has expanded the attack surface for cybercriminals, putting organizations at greater risk.

What Are AI Agents — and Why Do Attackers Want Them?

AI agents can plan tasks, browse the web, interact with third-party services, write files, execute commands, and take actions on behalf of users. Legitimate users tap them to boost productivity. But as agentic AI has gone mainstream, cybercriminals have taken notice.

ESET’s analysis shows a sharp spike in both suspicious and malicious tools over recent months. Suspicious AI agent skills grew from roughly 10,000 to over 25,000 during the reporting period. Meanwhile, those blocked as malicious jumped from about 600 to more than 3,000.

That’s a fivefold increase in malicious tools. And the trend shows no signs of slowing.

How Malicious AI Agents Operate

These AI toolkits can be abused — or purpose-built — to act on behalf of an attacker. They’re often planted in open source repositories where unsuspecting users might download them. Others are offered directly to attackers as ready-made malicious weapons.

Either way, the capabilities are dangerous. Malicious AI agents can:

  • Exfiltrate sensitive data
  • Download and execute malware
  • Override user instructions
  • Subtly alter the agent’s behavior to avoid detection

One example: a set of tools advertised as legitimate red-teaming software. On the surface, it looked like a standard penetration testing kit. But the agent had hidden features that allowed credential exfiltration and achieved highly privileged, persistent access. Some of these tools even dropped remote access trojans like Mimikatz — a tool commonly associated with ransomware attacks.

The Blurry Line Between Suspicious and Malicious

Thousands of other tools aren’t outright malicious — at least, not yet. But their design makes them easy to adapt for cyberattacks. That gray area is a growing concern for security teams.

ESET notes that this isn’t a new tactic. Cybercriminals have used similar methods to distribute malicious browser extensions and mobile apps. What’s different now is the addition of AI, which dramatically increases the stakes.

“When it comes to handling of sensitive data, making purchases, running API calls, or instruction chains, the higher level of autonomy of AI agents increases the risk and scope of such attacks,” the report states.

What Organizations Can Do About Malicious AI Agents

The availability of these tools creates a new cybersecurity risk for enterprises. ESET’s global cybersecurity advisor Jake Moore offers straightforward advice: stick with familiar defenses.

“Although AI uses impressive speed and autonomy, we can still do our best in protecting data with familiar defences such as looking for tools demanding sweeping access to files or credentials for a simple task and anything pushed through hype rather than official sources,” Moore told Infosecurity.

His bottom line? “If a free AI tool promises the world and asks for the keys to your machine in return, there may well be a slight mismatch.”

Organizations should also ensure they have clear policies around AI tool usage. Restrict suspicious downloads. Educate users about the risks of grabbing free tools from unfamiliar sources. And monitor for unusual AI agent behavior — especially agents that request excessive permissions.

For more on securing your environment, check out our guide on protecting against AI-powered cyber threats and learn how to spot malicious open source dependencies before they compromise your systems.

Leave a Reply

Your email address will not be published. Required fields are marked *

Trending

Exit mobile version