CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Cybercriminals Plant Malicious AI Agents in Open Source Tool Repositories

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 6403

As cited

Copy frozen at (site build).

Cybercriminals Plant Malicious AI Agents in Open Source Tool Repositories

No summary had been written when this copy was frozen.

First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

Cybercriminals Plant Malicious AI Agents in Open Source Tool Repositories

ESET researchers identified a significant increase in malicious toolsets planted in open source repositories by cybercriminals. These tools target users with cyber-attacks through compromised packages. The threat leverages the trust placed in open source software to distribute malware at scale.

Why it matters: Developers and organizations using open source dependencies are at risk of supply chain compromise; review recent package installations and monitor for anomalous behavior from third-party code.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary