AI Briefing
KO

Malware spreads through AI model and agent repositories

·2026.05.08 23:47

Key point

Hundreds of malicious models and skills have been identified in the Hugging Face and ClawHub repositories.

Details

AI supply chain malware has been identified in Hugging Face and ClawHub.

  • On Hugging Face, hundreds of malicious models were found, and Protect AI scanned over 4 million models, finding roughly 352,000 risk signals across 51,700 models.
  • JFrog found that over 100 models were capable of arbitrary code execution. nullifAI exploits Python pickle serialization and 7z compression to evade detection, executing a reverse shell, credential theft, and environment variable exfiltration as soon as it is loaded.
  • On ClawHub, Koi Security audited all 2,857 skills and found 341 malicious entries, of which 335 were linked to the ClawHavoc campaign. Snyk found that across the broader ecosystem, 36% of skills had security flaws, with about 900 being malicious.

Because the structure combines a central repository with automatic downloading and automatic execution, an attack can begin the moment a model or skill is loaded, and in production environments this can expose even database, API, and cloud credentials.

This summary was generated automatically by AI. Check the original for the author's claims and context. Copyright belongs to the original author.

Our guide explains how the AI works. Report summary errors, attribution issues, or removal requests via Contact.