Malicious AI agents steal 600K credit cards, infect 100+ sites with skimmers
Summary
Threat actors are using three open-source AI agent frameworks (Strix for scanning, Cairn for exploitation, and Hermes for coordination) to automatically attack hundreds of online retailers, stealing over 600,000 credit card records and injecting skimmer malware (code that secretly captures payment card data) onto 119+ websites since at least July. The attacker gives the AI agents high-level instructions and lets them execute attacks autonomously at scale, with an average cost of only $25 per target and success rates varying across at least 27 compromised companies including major retailers and airlines.
Classification
Affected Vendors
Related Issues
CVE-2026-63086: text-generation-inference through 3.3.7 contains a server-side request forgery (SSRF) vulnerability in the OpenAI-compat
CVE-2026-34371: LibreChat is a ChatGPT clone with additional features. Prior to 0.8.4, LibreChat trusts the name field returned by the e
Original source: https://www.bleepingcomputer.com/news/security/malicious-ai-agents-steal-600k-credit-cards-infect-100-plus-sites-with-skimmers/
First tracked: September 23, 2026 at 02:01 PM
Classified by LLM (prompt v3) · confidence: 95%