{
 "license": "CC-BY-4.0",
 "attribution": "Fide AI, Agentic Cyber Explorer",
 "url": "https://agentic-cyber-explorer.pages.dev/findings/malicious-agent-packages-in-the-wild/",
 "asOf": "2026-09-26",
 "id": "malicious-agent-packages-in-the-wild",
 "claim": "Malicious or compromised agent extensions, MCP servers, and skills have been published to public registries and used against real users.",
 "evidenceKind": "observed",
 "scope": "Individual incidents; prevalence is unknown. The Amazon Q instruction failed to run and VirusTotal does not report installs; postmark-mcp is the clearest case of use against real users. The Nx case shows malware abusing installed agents, not a malicious agent package.",
 "topics": [
  "agent-supply-chain",
  "tool-and-mcp-security"
 ],
 "atlas": [
  "supply-chain",
  "tools"
 ],
 "evidence": [
  {
   "event": "amazon-q-vscode-malicious-prompt-release-2025",
   "note": "The injected instruction was malformed and did not run."
  },
  {
   "event": "nx-s1ngularity-weaponized-ai-clis-2025",
   "note": "Not an agent package: a compromised build-tool package whose install script tried to use locally installed AI coding CLIs."
  },
  {
   "event": "postmark-mcp-malicious-npm-2025",
   "note": "An impersonating MCP server on npm; version 1.0.16 blind-copied sent emails to the publisher."
  },
  {
   "event": "virustotal-malicious-openclaw-skills-2026",
   "note": "Hundreds of malicious skills among 3,016+ analyzed, 314 from one publisher; install counts not reported."
  }
 ],
 "relations": [],
 "statusHistory": [
  {
   "status": "reported",
   "on": "2025-07-23",
   "why": "A malicious prompt shipped in an Amazon Q extension release.",
   "event": "amazon-q-vscode-malicious-prompt-release-2025",
   "kind": "evidence"
  },
  {
   "status": "corroborated",
   "on": "2025-08-26",
   "why": "The Nx compromise abused installed AI coding CLIs.",
   "event": "nx-s1ngularity-weaponized-ai-clis-2025",
   "kind": "evidence"
  },
  {
   "status": "corroborated",
   "on": "2026-09-25",
   "why": "Correction: the Nx compromise was a malicious build-tool package that invoked installed AI CLIs, not a malicious agent extension, MCP server or skill. Corroboration rests on the malicious postmark-mcp server (found by Koi Security, disclosed by Postmark), independent of the Amazon Q incident.",
   "event": "postmark-mcp-malicious-npm-2025",
   "kind": "correction"
  }
 ],
 "halfLifeDays": 365,
 "wouldChange": "Registry controls that measurably reduce malicious agent packages.",
 "fideQuestions": [],
 "methods": [
  "malicious-agent-extensions"
 ],
 "review": "assistant-drafted",
 "addedOn": "2026-09-25"
}