Security

97% of AI-Built Malware Never Left the Sandbox. The AI Tools Themselves Became the Way In

Unit 42 traced 405 AI-enabled malware samples and found only 12 on a real production endpoint. Meanwhile attackers seeded hundreds of poisoned AI agent skills and cloned AI installer pages, turning the tools employees trust into the delivery route.

September 25, 2026 · Security
A dark office workstation with a monitor showing lines of code and a data window, a keyboard and a second screen blurred in the background

Key Takeaways

  • Palo Alto Networks Unit 42 examined 405 AI-enabled malware samples and found only 12, or 3.0%, on production endpoints, with roughly 97% existing only in sandboxes and on VirusTotal.
  • Koi Security audited 2,857 skills on the ClawHub marketplace for the OpenClaw AI agent and found 341 malicious ones, 335 of them delivering the Atomic macOS Stealer to users who followed fake setup steps.
  • Recorded Future's H1 2026 review found threat actors using AI only at low to mid maturity, while fake Claude installers, cloned Claude Code pages and Cursor agent sessions were used to deliver infostealers.
  • Check Point's AI Security Report 2026 found malicious indirect prompt injection payloads rose roughly fivefold between March and May 2026, approaching 1% of observed prompts by May.

The fear that artificial intelligence would produce a wave of undetectable malware has driven a great deal of security spending in the past two years. The first large look at what AI-enabled malware actually does in the field suggests that fear was aimed at the wrong target. Most AI-built malware never reaches a real machine. What does reach real machines, in growing numbers, is ordinary malware that arrives through the AI tools employees have been encouraged to adopt.

Most AI-Built Malware Never Leaves the Lab

Unit 42's State of AI-Enabled Malware report, published August 25, 2026, assembled 405 unique samples with AI components and checked each against real customer telemetry. Only 12, or 3.0%, appeared on a production endpoint. Roughly 97% existed only in sandboxes and on VirusTotal, the output of proof-of-concept work, security validation testing and researcher submissions rather than live campaigns. Every sample that did try to reach a customer environment was detected and blocked.

The report's central finding is blunt: "The AI component does not evade detection. It changes how the code is authored, not how it executes." Where AI showed up in the wild, its effect was speed. Seven variants of FunkSec ransomware were compiled within six days in January 2025, a cadence Unit 42 links to language-model-assisted development. That matters, but it is a productivity story for attackers, not a new class of threat that existing endpoint controls cannot see.

The ceiling is rising. Check Point Research documented VoidLink, a command-and-control framework for Linux and cloud environments that it describes as authored almost entirely by AI, with more than 88,000 lines of code produced in roughly a week. Recorded Future's H1 2026 malware and vulnerability review still places observed threat actor use of AI at low to mid maturity, supporting discrete functions rather than running operations on its own.

The Delivery Route Now Runs Through AI Tools

The more immediate problem is not what AI writes but where malware now hides. In February, Koi Security audited 2,857 skills on ClawHub, the marketplace for add-ons to the OpenClaw AI agent, and found 341 malicious ones. Of those, 335 delivered the Atomic macOS Stealer, known as AMOS. The lure was mundane. "The skill's documentation looks professional," Koi researcher Oren Yomtov said. "But there's a 'Prerequisites' section that says you need to install something first."

Trend Micro's analysis of a related campaign found 39 malicious skills that manipulated OpenClaw into installing fake command-line tools, and more than 2,200 malicious skills on GitHub overall. The infection chain ends with a fake password dialog on the Mac. Once the user types their password, the stealer harvests Apple and KeePass keychains, data from 19 browsers and 150 cryptocurrency wallets, and office documents. Trend Micro's researchers called it a shift "to using the AI itself as a trusted intermediary to trick humans."

Recorded Future's review shows the same pattern well beyond one marketplace. Fake Claude installers delivered infostealers and proxy malware through GitHub and search results. The Amatera stealer spread through cloned Claude Code installation pages. AMOS also reached Macs through Cursor AI agent sessions, and the MacSync stealer used Google-sponsored results and ClickFix-style lures hosted on claude.ai and Medium. None of this required novel malware. It required a user who trusted an AI tool enough to follow its instructions without question.

The Agent Is Now Part of the Attack Surface

Check Point's AI Security Report 2026 shows the channel getting busier. Malicious indirect prompt injection payloads rose roughly fivefold between March and May 2026, approaching 1% of observed prompts by May. The report describes attackers exploiting agent architectures through a planted configuration file that an agent loads and trusts across sessions, the same trust relationship the poisoned skills abuse. High-risk generative AI prompts doubled from 2% to 4% year over year, and organizations averaged 10 AI applications a month, many of them unapproved.

The picture for IT leaders is not that AI malware is a myth. It is that the familiar threats, stealers, trojanized installers and ransomware, have found a faster route in, and that route runs through software most organizations have not yet put under the same controls as a browser extension or a package manager. Macs deserve particular attention because so much of this activity targets them, and because developer-heavy Mac fleets are exactly where AI coding agents are most widely installed.

Three percent of AI-built samples reached a real endpoint. Hundreds of poisoned skills reached real users. The lesson from 2026 so far is that attackers did not need AI to invent better malware. They needed AI tools that users would trust enough to install whatever came next.

Share

More in Security

All Resources →