Findings/malicious-agent-packages-in-the-wild

Malicious or compromised agent extensions, MCP servers, and skills have been published to public registries and used against real users.

Corroboratedobserved4 evidence records from 4 independent sourcesassistant-drafted
Scope: what this does not show

Individual incidents; prevalence is unknown. The Amazon Q instruction failed to run and VirusTotal does not report installs; postmark-mcp is the clearest case of use against real users. The Nx case shows malware abusing installed agents, not a malicious agent package.

Corroborated: Supported by at least two independent sources.

Evidence

Key questions that rely on this finding

Status history

  1. 2025-07-23ReportedA malicious prompt shipped in an Amazon Q extension release. · record
  2. 2025-08-26CorroboratedThe Nx compromise abused installed AI coding CLIs. · record
  3. 2026-09-25CorroboratedcorrectionThe Nx compromise was a malicious build-tool package that invoked installed AI CLIs, not a malicious agent extension, MCP server or skill. Corroboration rests on the malicious postmark-mcp server (found by Koi Security, disclosed by Postmark), independent of the Amazon Q incident. · record