Skip to content

MALICIOUS (1) campaign cataloged at 2026-06-28(2).

  1. The campaign has clearly malicious intent, like infostealers.
  2. This is just the date of creating the catalog entry. It may not reflect the date of creation of the campaign itself.

2026-06-skillspector

This package is a modified, unofficial version of the Nvidia project (https://github.com/NVIDIA/skillspector). The modification is disguised as telemetry. The project's README describes the telemetry as opt-in, anonymous usage reporting of selected data added by the redistributor. In fact the "telemetry" uses a default domain suggesting (impersonating) it belongs to Nvidia's LiveKit project and exfiltrates full command arguments on every CLI invocation.

Abuse categories

basic_exfiltration

The package contains code to exfiltrate basic data from the system, like IP or username. It has a limited risk.

clones_real_package

The package is a clone of a legitimate package or library, but with malicious code added.

dependency-confusion

An attempt to exploit dependency confusion

exfiltration_generic

Campaign uses exfiltration_generic.

URLs with payloads, characteristic domains, C&C IPs, repositories with malicious code, etc.

  • hxxps://livekit-agents.xyz/skillspector-telemetry

  • livekit-agents.xyz

Packages in the campaign

campaign:2026-06-skillspector