Scope: what this does not show
Individual incidents; prevalence is unknown. The Amazon Q instruction failed to run and VirusTotal does not report installs; postmark-mcp is the clearest case of use against real users. The Nx case shows malware abusing installed agents, not a malicious agent package.
Corroborated: Supported by at least two independent sources.
Evidence
Jul 23, 2025
Malicious agent instruction merged into Amazon Q Developer VS Code extension release 1.84.0
The injected instruction was malformed and did not run.
Aug 26, 2025
s1ngularity: compromised Nx npm packages used local AI coding CLIs to hunt for secrets
Not an agent package: a compromised build-tool package whose install script tried to use locally installed AI coding CLIs.
Sep 25, 2025
Malicious postmark-mcp npm package quietly copied every sent email to an outside address
An impersonating MCP server on npm; version 1.0.16 blind-copied sent emails to the publisher.
Feb 2, 2026
VirusTotal finds hundreds of malicious OpenClaw agent skills distributing stealers and backdoors
Hundreds of malicious skills among 3,016+ analyzed, 314 from one publisher; install counts not reported.
Key questions that rely on this finding
- Where are deployed AI agents actually being exploited?Mostly around the model: connectors, credentials, tools, and packages, rather than the model alone.
- How are attackers using AI agents in real operations?Increasingly to run parts of intrusions: providers and vendors report agent-driven espionage, extortion and credential theft, and malware that queries LLMs.
Status history
- 2025-07-23ReportedA malicious prompt shipped in an Amazon Q extension release. · record
- 2025-08-26CorroboratedThe Nx compromise abused installed AI coding CLIs. · record
- 2026-09-25CorroboratedcorrectionThe Nx compromise was a malicious build-tool package that invoked installed AI CLIs, not a malicious agent extension, MCP server or skill. Corroboration rests on the malicious postmark-mcp server (found by Koi Security, disclosed by Postmark), independent of the Amazon Q incident. · record