Seventy-three packages now deploy a self-replicating credential stealer immediately upon being opened by an AI agent. This second wave of attacks targets Microsoft ecosystems through poisoned libraries. The breach highlights a critical vulnerability in how autonomous agents handle external code. Developers must restrict agent execution environments to prevent automated credential theft.