A malicious skill shows up on a public registry and starts reading credentials it has no business touching. You pull the maintainer handle and it tells you nothing. The account is six days old and connected to nothing. You file a takedown, and within hours the same payload is back under a new name. Most people read that as proof that attribution is hopeless. It is not.
Attribution has a reputation for being impossible, and that reputation comes from one version of the job: putting a real-world name to a nation-state intrusion. There the evidence is deliberately scarce, the bar is near-certainty, and a wrong answer becomes a diplomatic problem. That work is genuinely hard. The mistake is assuming every attribution question is that hard.
The agent supply chain is a different problem
The adversary poisoning agent registries is rarely a disciplined state crew. It is a commodity adversary chasing scale, and that scale is hard to hide. Making money means shipping volume, and volume means reuse. The same malicious skill gets repackaged under new names. The same MCP server logic turns up across marketplaces with the labels changed. An adversary pushing hundreds of near-identical variants leaves a pattern in the repetition.
The evidence is easier to reach too. A nation-state implant is built to stay hidden on one machine. A malicious skill has to be published and run to do any harm, so it is publicly available by necessity, where a victim and an investigator can both find it.
You do not need a person to indict or sanction either. You need the adversary behind the campaign, one pseudonymous identity, and every artifact it is responsible for, including what they will ship next. Their real-world name does not matter for that.
Blocking a malicious skill by its hash buys nothing past the next upload. You can win that fight a hundred times and still lose, because the adversary just renames the file. Identifying the operation is the only move that holds.
What attribution buys you
Knowing that twelve listings are one operation, not twelve separate problems, changes what you do next.
It changes priority. A beginner running a copied exploit and a professional shipping a hundred-variant campaign look identical from a single flagged file. The adversary behind each does not. Without attribution every artifact looks equally urgent, so nothing gets the attention it deserves.
It also makes detection last. Names, hashes, domains, publisher handles, all of it is cheap to discard and re-create, so a defense built on those ages in days. How an adversary builds and behaves is far harder to change. Public frameworks like MITRE ATT&CK exist for this reason: the field learned that behavior is more stable than the disposable indicators sitting on top of it. A detection tied to the operation survives the next rename. One tied to a hash stops working the moment a byte changes.
The limits are real
Attribution is not always conclusive, and pretending otherwise is its own failure. An adversary can copy another’s habits on purpose to get a rival blamed. Shared and rented infrastructure muddies things, since one host serves a hundred legitimate sites and the occasional malicious one. Plenty of cases are just thin, and the honest answer is that you do not yet know.
None of that justifies waiting for certainty. Certainty is the courtroom bar, and importing it here means you never act while the adversary keeps shipping. The right bar is a probability you can defend, attached to the evidence behind it. A finding of “these listings are very likely one operation, and here is why” beats a confident guess with nothing under it, and beats a silence waiting for proof that never comes. High confidence with a clear footprint, block the set. Lower confidence, watch and gather more.
Naming the actual human is almost never the goal, and usually the wrong one. That is law-enforcement work. A defender does not need someone’s identity to act, only enough confidence that one adversary is behind this artifact and others like it.
In practice
This is the problem Aephix solves. Give us a malicious package, model, skill, MCP server, extension, or container and we link it to the wider operation behind it, with a confidence level and the evidence for it. From that one artifact we surface the rest of that operation’s footprint across the registries and marketplaces it reaches, and hand you a blocklist to export. You block the operation and the campaign, including variants that have not shipped yet, instead of deleting one file and waiting for the next.