Kaspersky Warns of Malware Hidden in AI Agents

TechCentral reported on July 27 that Kaspersky researchers warned externally retrieved instructions, plugins, and counterfeit agent installers can turn AI-agent adoption into a malware path that signature-only checks may miss. Kaspersky separately reported more than 92,000 detections of malware or potentially unwanted applications disguised as AI services from January through early May 2026; that vendor telemetry is not a count of affected organizations.
TechCentral reported on July 27 that Kaspersky researchers warned AI-agent skills, plugins, and counterfeit installers can become malware delivery paths that signature-only antivirus checks may miss. At a Kaspersky cybersecurity event in Tbilisi, Georgia, Sergey Lozhkin described apparently legitimate skills that retrieve instructions or connect to external resources after installation.
Lozhkin told TechCentral that the risk increasingly sits outside an organization's network perimeter, including in APIs, frameworks, plugins, and the agents themselves. He argued that a one-time signature scan can fail when a skill initially appears legitimate and its externally sourced behavior changes later. TechCentral also reported Kaspersky's recommendation to pair behavioral monitoring with isolation and internet-access guardrails.
Counterfeit tools target the installation path
Kaspersky's March 12 research documented campaigns that used Google Search ads to direct people seeking AI tools to counterfeit documentation and installation pages. The company said pages impersonating Claude Code, OpenClaw, and Doubao instructed visitors to run malicious commands.
According to Kaspersky, macOS targets in these campaigns received the Atomic macOS Stealer, or AMOS, while Windows targets received the Amatera infostealer. One fake Claude Code documentation site used Squarespace, a legitimate website-building platform that Kaspersky said helped the page bypass some anti-phishing filters.
The described attack is aimed at the software-installation workflow. Kaspersky did not report a compromise of the legitimate Claude Code product or its official documentation.
Vendor telemetry uses different measures
In a separate May 21 press release, Kaspersky reported more than 92,000 detections worldwide of malware and potentially unwanted applications disguised as AI agents and services from January through the beginning of May 2026. The company said fake ChatGPT applications accounted for 49% of those detected attacks, while Claude and Gemini each represented 18%.
TechCentral separately reported Kaspersky's figure of more than 15,000 unique samples masquerading as ChatGPT, Claude, or Gemini clients and agents during the first five months of 2026. The figures are not interchangeable: one counts detections or attacks, while the other counts unique samples. Both are Kaspersky-provided measures, and the retrieved public sources do not identify the number of affected organizations or independently validate the telemetry.
TechCentral also cited the March compromise of LiteLLM, an AI gateway distributed through the Python Package Index, as a supply-chain example that exposed credentials, authentication tokens, cloud keys, and cryptocurrency keys. The report attributed that incident to attackers tracked as TeamPCP.
Where practitioners can place controls
The reported mechanics put controls at two boundaries: before installation and during runtime. Teams can verify official distribution channels, pin and review dependencies, restrict outbound access from agent runtimes, and monitor for credential access or unusual connections after a new tool or skill is installed. These are LDS interpretations of the reported attack paths, not measured findings about the effectiveness of any specific control.
The retrieved evidence does not establish how widely externally triggered agent malware has affected enterprise deployments. It does show how familiar search-ad, counterfeit-installer, and package-distribution tactics can exploit demand for AI assistants and workflow-automation tools.
Key Points
- 1TechCentral's July 27 report describes externally sourced instructions, agent skills, and counterfeit installers as malware paths that one-time signature checks can miss.
- 2Kaspersky's March research documented fake AI-tool pages distributing AMOS on macOS and Amatera on Windows; it did not report a compromise of the legitimate products.
- 3Kaspersky's 92,000 detection figure and TechCentral's 15,000 sample figure measure different things and should not be treated as affected-user or affected-company counts.
- 4The public evidence does not quantify enterprise prevalence or independently validate Kaspersky's telemetry, so the strongest practitioner takeaway is control placement rather than incident-rate estimation.
Scoring Rationale
The report concerns a material attack surface for organizations deploying AI agents, coding assistants, and third-party skills. Its value is primarily defensive: it connects familiar search-ad and package-distribution abuse with agent installation and externally sourced instructions, while the available evidence does not quantify enterprise prevalence or independently validate Kaspersky's telemetry.
Sources
Public references used for this report.
Practice interview problems based on real data
1,625 SQL & Python problems across 15 industry datasets — the exact type of data you work with.
Try 250 free problems

