More on the topic...
Generating detailed summary...
Failed to generate summary. Please try again.
Trail of Bits built four cloaked βskillsβ that slip past Ciscoβs skill-scanner, Vercelβs skills.sh marketplace and ClawHubβs filters. ClawHubβs scanner folded once testers padded a benign preamble with 10,000 newlines before the prompt injection. The others fell when the team hid payloads inside a .docx or compiled Python bytecode. In every case, the scanners never saw the trigger buried in what looked like harmless code.
Appleβs Siri-AI leans on Google Gemini running in Apple Private Cloud Compute with Confidential Inference. It pulls in context from messages, email, notes and calendars to fine-tune scheduling and search. But any agent that queries web search or an LLM can spill private data. Injected prompts in your inbox or on a webpage can herd the agent into revealing emails or attachments. And if you give it crime-reporting or messaging rights, it can quietly flag wrongdoing or forward sensitive material.
On June 7, security firm Socket revealed a PyPI supply-chain attack that hijacked 19 science and deep-learning packages. Attackers pushed 37 malicious wheels that drop a hades-setup.pth file into site-packages. That hook auto-launches an embedded Bun runtime to run _index.js at startup. The code grabs AWS, GCP and Azure tokens plus GitHub, npm and SSH keys, then uploads them to attacker-controlled GitHub repos named βHades β The End for the Damned.β To mask its trail it mimes HTTPS calls to Anthropicβs API. Defenders should scan requirements.txt, poetry.lock and local site-packages for names like bramin, executor-engine, executor-http, funcdesc, coolbox, dynamo-release and magique. Treat any hit as a full compromise, rotate all cloud and VCS credentials and hunt CI/CD logs for hades-setup.pth, _index.js or unexpected Bun downloads.
Questions about this article
No questions yet.