FakeGit Campaign Evolves with AgentBaiting: Malicious GitHub Repositories Now Target AI Agents

Cybersecurity researchers have uncovered a sophisticated and evolving threat campaign, codenamed FakeGit, that has weaponized nearly 7,600 malicious repositories on GitHub. A significant portion of these, over 800, masquerade as legitimate artificial intelligence (AI) skills or Model Context Protocol (MCP) servers, designed to lure unsuspecting users and, more alarmingly, AI agents themselves, into downloading a malware family known as SmartLoader. This campaign represents a concerning advancement in threat actor tactics, leveraging the burgeoning AI ecosystem to distribute malware and exfiltrate sensitive data.
The FakeGit operation, meticulously detailed by researchers at Island, employs a multi-pronged approach to deception. It hinges on the strategic use of copied legitimate projects, the creation of convincing lookalike developer profiles, meticulously crafted README files that mimic genuine documentation, and the distribution of malicious ZIP files. "FakeGit uses copied projects, lookalike developer profiles, convincing READMEs, and malicious ZIP files to deliver SmartLoader malware," Oleg Zaytsev, lead security researcher at Island, stated in a report shared with The Hacker News. The ultimate objective of these insidious attacks is to gain a foothold on compromised systems through SmartLoader, establish persistence, and subsequently deploy secondary payloads. Among these is StealC, an information-stealing malware capable of pilfering a wide array of sensitive data from affected machines.
This discovery builds upon earlier warnings regarding the exploitation of trojanized MCP servers. Security firms Straiker AI and Derp.ca had previously flagged similar tactics earlier this year, highlighting the distribution of SmartLoader and StealC via these deceptive server emulations. However, the FakeGit campaign introduces a chilling new dimension: an AI-powered evolution dubbed "AgentBaiting." This novel approach targets AI agents directly, a significant escalation from previous social engineering tactics aimed solely at human users.
The Evolution of Deception: From Human Targets to AI Agents
The core innovation of AgentBaiting lies in its ability to deceive AI agents actively searching for functionalities or data. When an AI agent, in the course of its operations, seeks a specific skill or an MCP server to fulfill a user’s request or perform a task, it can inadvertently discover these fraudulent GitHub repositories. Instead of being directed to a malicious link by a human intermediary, the AI agent, armed with the attacker’s crafted README, can autonomously proceed with the malicious download and execution process, bypassing human oversight entirely.
Island’s rigorous testing has demonstrated the susceptibility of prominent AI models, including Anthropic Claude Code, Google Gemini, and OpenAI ChatGPT, to this deceptive tactic. These models were observed to surface malicious campaign repositories without any explicit malicious links being provided. This signifies a critical shift where a technique originally designed for human social engineering now possesses the capability to trick AI agents operating on behalf of users. This development raises profound questions about the security of AI-powered workflows and the potential for autonomous malware propagation.

Scale and Scope of the FakeGit Campaign
The sheer scale of the FakeGit operation is a cause for significant concern. Out of the nearly 7,600 identified malicious GitHub repositories, approximately 800 were specifically designed to impersonate AI skills or MCP servers. These deceptive offerings covered a broad spectrum of functionalities, aiming to cater to both individual and enterprise needs. They mimicked integrations for popular services like Gmail and WhatsApp, as well as essential development and infrastructure tools such as Databricks, Jenkins, and Docker.
As of July 2026, the FakeGit campaign has achieved a staggering number of downloads, with its GitHub Release assets accumulating over 14 million downloads across roughly 200 distinct campaign repositories. This high download count underscores the effectiveness of the threat actors’ strategy in tapping into the demand for AI-related tools and services.
"The repositories were designed to meet demand already forming around AI capabilities, borrowing the names and workflows of familiar consumer and enterprise tools," Zaytsev elaborated. "That familiarity gave the malicious ZIP files a credible reason to be downloaded, while the README guided users or agents from what appeared to be routine setup into the SmartLoader attack chain."
The technical execution of the attack chain is a testament to the threat actors’ understanding of software development workflows. Counterfeit repositories, which are either entirely fabricated or meticulously copied from legitimate open-source projects, serve as the initial point of contact. These repositories contain a malicious ZIP archive. Upon download and extraction, this archive triggers a LuaJIT loader chain. This chain is responsible for executing an obfuscated Lua script, which in turn drops the SmartLoader malware onto the compromised system. Subsequently, the loader proceeds to deploy the StealC information stealer.
AgentBaiting: A New Frontier in AI-Driven Malware Deployment
The AgentBaiting technique represents a significant escalation, transforming routine AI-assisted discovery operations into pathways for malicious code execution. The threat actors have strategically crafted their AI lures around the discovery process. A typical prompt that could inadvertently lead an AI agent to a FakeGit repository might be something like: "Find free claude cinematic prompt skill, and give me the installation instructions" or "give me a free walmart MCP server link."
When an AI agent attempts to fulfill such a request, it might independently discover a FakeGit repository. The crucial element here is that the AI agent treats the repository’s README file as legitimate documentation. Consequently, it can then relay the attacker’s instructions to the end-user, effectively acting as an unwitting accomplice in the malware deployment. "While trying to complete a task, it can discover a FakeGit repository on its own, treat the README as legitimate documentation, and pass the attacker’s instructions to the user," Island’s report explained.

This problem is exacerbated by the fact that these malicious skills or MCP servers are often listed on public registries. Platforms such as LobeHub, Glama, MCP.so, and MCP Market, among others, lend a false sense of legitimacy to these fraudulent offerings. Island researchers have flagged over 600 campaign listings across these public MCP and Skill registries, highlighting the widespread dissemination of these deceptive tools.
Background and Timeline of the Campaign
While the FakeGit campaign and its AgentBaiting evolution are recent revelations, the underlying tactics of leveraging compromised repositories and deceptive server emulations have been observed over time.
- Early 2026: Security researchers at Straiker AI first identified the use of trojanized MCP servers for the distribution of SmartLoader and StealC malware. This marked an early indication of threat actors exploiting the emerging AI infrastructure.
- Mid-2026: Derp.ca further investigated and documented a GitHub campaign, also involving malicious LuaJIT loaders and the distribution of SmartLoader, providing more granular details on the technical execution.
- Late 2026 (Current Reporting): Island researchers unveil the broader FakeGit campaign, encompassing a vast number of malicious repositories and introducing the sophisticated AgentBaiting technique, which directly targets AI agents. This report highlights the campaign’s evolution and its significant scale.
The strategic targeting of GitHub, a platform central to software development and collaboration, provides threat actors with a vast attack surface. The platform’s open nature and the widespread adoption of AI development tools and integrations make it a fertile ground for such campaigns. The attackers exploit the trust inherent in open-source communities and the increasing reliance on AI-driven assistance for development tasks.
Analysis of Implications: A Paradigm Shift in Cyber Threats
The FakeGit campaign, particularly its AgentBaiting component, signifies a potential paradigm shift in the landscape of cyber threats. The ability to compromise AI agents, which are increasingly being adopted by enterprises and individuals for complex tasks, opens up unprecedented avenues for malware deployment and data breaches.
Broader Impact on AI Ecosystem Security
The implications for the broader AI ecosystem are profound. As AI agents become more autonomous and capable of interacting with external services and code repositories, the attack surface for these agents expands exponentially. The current security measures, often designed with human users in mind, may prove insufficient to defend against AI-native attacks. This necessitates a fundamental rethinking of AI security, moving beyond traditional cybersecurity frameworks.
The reliance on public registries for AI skills and MCP servers creates a centralized point of failure. While these registries aim to facilitate the discovery and integration of AI capabilities, they also become attractive targets for malicious actors seeking to inject their fraudulent offerings into the ecosystem. The "false sense of legitimacy" provided by these platforms is a critical vulnerability.

Potential for Autonomous Cyber Warfare
In a more speculative, yet plausible, future scenario, AgentBaiting could be a precursor to more sophisticated autonomous cyber warfare. If AI agents can be turned into unwitting participants in malware distribution, imagine the potential for AI agents to be directed by one nation-state to compromise the critical infrastructure of another, all through sophisticated social engineering of AI systems. While this remains a distant concern, the current campaign serves as a stark warning.
The Need for Enhanced Defenses and Vigilance
To counter this evolving threat, a multi-layered defense strategy is imperative. Island’s recommendations offer a crucial roadmap:
- Curated Catalogs: Building and maintaining a catalog of reviewed and verified AI skills, MCP servers, and agent plugins is essential. This curation process acts as a vital gatekeeper, filtering out malicious or untrusted components.
- Sandboxed Evaluation: New agent capabilities and discovered external resources should be rigorously evaluated in a sandboxed environment before being deployed more broadly. This isolation prevents potential malware from impacting production systems.
- Publisher and Project Verification: Thoroughly verifying the authenticity of both the publisher and the project is paramount. This involves checking developer credentials, project history, and community feedback to ensure credibility.
- Agentic Pathway Monitoring: Implementing robust monitoring of AI agent interactions and pathways is crucial. Detecting unusual patterns or deviations from expected behavior can provide early warning signs of a compromise.
The success of FakeGit, particularly its AgentBaiting evolution, lies in its ability to exploit the inherent trust in development platforms and the accelerating adoption of AI. "FakeGit did not need to breach anything. It published convincing repositories, borrowed real developers’ identities, spread its listings across public registries, and let discovery do the rest," Island concluded. The advent of AgentBaiting means that discovery no longer requires human intervention. An AI agent searching for a resource can stumble upon a malicious lure, interpret the attacker’s README, and propagate the malicious instructions. The most effective defenses will be those that can interrupt this chain of execution before it reaches its devastating conclusion. The cybersecurity community must adapt swiftly to this new era of AI-driven threats, ensuring that the tools designed to enhance our capabilities do not become instruments of our undoing.







