Someone publishes a malicious skill on a public registry, and it starts reading credentials it has no business touching. You pull the maintainer handle and it tells you nothing. The account is six days old and connected to nothing. You file a takedown, and within hours the same payload is back under a new name. Most people read that as proof that attribution is hopeless, but this conclusion comes from judging the problem by its hardest version.
Nation-state intrusion attribution demands near-certainty from deliberately scarce evidence, and a wrong answer becomes a diplomatic problem. That version of the job built attribution’s reputation as impossible. The mistake is importing that difficulty to every attribution question.
The agent supply chain is a different problem
The adversary poisoning agent registries is rarely a disciplined state crew. It is a commodity adversary chasing scale, and that scale is hard to hide. Making money means shipping volume, and volume means reuse. Repackaged malicious skills appear under new names, and identical MCP server logic turns up across marketplaces with only the labels changed. An adversary pushing hundreds of near-identical variants leaves a pattern in the repetition.
Malicious skills have to be published on a public registry and run on victim machines to do any harm, making them visible to both victims and investigators from the moment they appear.
You do not need a person to indict or sanction either. You need the adversary behind the campaign, one pseudonymous identity, and every artifact it is responsible for, including what they will ship next. Their real-world name does not matter for that.
Blocking a malicious skill by its hash buys nothing past the next upload. You can delete a hundred copies and still face new ones, because the adversary just renames the file. Identifying the operation is the only move that holds.
What attribution buys you
Twelve listings linked to one operation become one problem to block instead of twelve independent fires. A single flagged file on its own does not reveal whether the publisher is a beginner running a copied exploit or a professional shipping a hundred-variant campaign. Without that linkage every artifact looks equally urgent, so nothing gets the attention it deserves.
Names, hashes, domains, and publisher handles are all cheap to discard and re-create, so defenses built on them become obsolete within days. How an adversary builds and behaves is far harder to change. Public frameworks like MITRE ATT&CK exist for this reason: the field learned that behavior is more stable than the disposable indicators sitting on top of it. Detections tied to the operation survive the next rename, while hash-based rules break the moment a byte changes.
Shared infrastructure and deliberate mimicry
Adversaries can copy another operator’s habits on purpose to get a rival blamed. Shared and rented infrastructure muddies things, since one host serves a hundred legitimate sites and the occasional malicious one. Plenty of cases are just thin, and the honest answer is that you do not yet know.
None of that justifies waiting for certainty. The courtroom bar is near-proof, and importing it here means you never act while the adversary keeps shipping. The right bar is a probability you can defend, attached to the evidence behind it. A finding of “these listings are very likely one operation, and here is why” beats a confident guess with nothing under it, and beats silence waiting for proof that never comes. When confidence is high and the footprint is clear, block the set. If not, watch and gather more.
Defenders do not need someone’s real-world identity to act, only enough confidence that one adversary is behind this artifact and others like it. Real-world identification is law-enforcement work.
In practice
Aephix Sleuth starts from one flagged artifact and surfaces the rest of the adversary’s footprint across registries, with a confidence level and the evidence behind it. Aephix Vantage gives you a free cross-ecosystem lookup before you install. You block the operation, including variants not yet shipped, instead of deleting one file and waiting for the next.