Seventy-three packages now deploy self-replicating credential stealers the moment an AI agent opens them. This second wave of attacks targets the autonomous nature of Microsoft ecosystem tools. It proves that agentic workflows create new, high-risk vectors for automated malware distribution. Developers must restrict agent permissions to prevent systemic credential theft.