Seventy-three packages now deploy self-replicating credential stealers the moment an AI agent opens them. This second wave of attacks targets Microsoft ecosystems by exploiting how autonomous tools interact with code. It proves that agentic workflows introduce critical new attack vectors. Developers must restrict agent permissions to prevent automated credential theft.