73 packages were found running a self-replicating credential stealer as soon as they were opened by an AI agent. The incident underscores a growing security concern for agentic workflows: automated tools can trigger malicious package behavior while handling development tasks.
Jun 8, 2026
Malicious packages target AI agents with credential stealers
Source
Ars Technica AI