Cybersecurity & Protection

The Rise of AgentBaiting: How Malicious GitHub Repositories Are Now Deceiving AI Agents

Cybersecurity researchers have uncovered a sophisticated and rapidly evolving threat campaign, codenamed FakeGit, which has deployed nearly 7,600 malicious repositories on GitHub. A significant portion of these, over 800, are designed to impersonate artificial intelligence (AI) skills or Model Context Protocol (MCP) servers. Their insidious purpose is to distribute a malware family known as SmartLoader, a stealthy tool capable of establishing persistence on compromised systems and deploying further malicious payloads, such as the information-stealing malware StealC. The latest alarming development within this campaign is an AI-powered evolution, termed AgentBaiting, which allows these malicious repositories to ensnare AI agents directly, bypassing human interaction entirely.

The Genesis of FakeGit: Exploiting the AI Boom

The FakeGit campaign, first identified and detailed by cybersecurity researchers at Island, capitalizes on the burgeoning demand for AI capabilities and integrations. As businesses and individuals increasingly seek to enhance their workflows and applications with AI functionalities, a fertile ground for deception has emerged. The attackers meticulously craft their malicious repositories to mirror legitimate projects, complete with convincingly designed developer profiles, detailed README files, and the distribution of malicious ZIP archives. This multi-pronged approach aims to exploit both human trust and the emergent capabilities of AI agents seeking to discover and integrate new functionalities.

"FakeGit uses copied projects, lookalike developer profiles, convincing READMEs, and malicious ZIP files to deliver SmartLoader malware," Oleg Zaytsev, lead security researcher at Island, stated in a detailed report. "The repositories were designed to meet demand already forming around AI capabilities, borrowing the names and workflows of familiar consumer and enterprise tools. That familiarity gave the malicious ZIP files a credible reason to be downloaded, while the README guided users or agents from what appeared to be routine setup into the SmartLoader attack chain."

The core of the FakeGit operation involves the distribution of a ZIP archive, often presented as an installation package or a necessary component for an AI skill or MCP server. Upon execution, this archive initiates a complex loader chain, typically involving a LuaJIT loader. This loader then executes an obfuscated Lua script, which is responsible for deploying the SmartLoader malware. Once SmartLoader is established, it acts as a gateway for secondary payloads, most notably StealC. StealC is designed to exfiltrate a wide range of sensitive data from compromised systems, including credentials, financial information, and other confidential data, posing a significant risk to both individuals and organizations.

FakeGit Campaign Uses 7,600 GitHub Repositories to Spread SmartLoader Malware

A Chronology of Deception and Escalation

The tactic of using trojanized MCP servers to distribute SmartLoader and StealC is not entirely new. Earlier this year, security researchers from Straiker AI and subsequently Derp.ca flagged similar activities, highlighting the persistent nature of these threats. However, the FakeGit campaign represents a significant escalation due to its scale and the introduction of AgentBaiting.

The FakeGit operation has been active for a considerable period, with research indicating its presence and growth. As of July 2026, the campaign has amassed an alarming number of downloads, exceeding 14 million across GitHub Release assets within approximately 200 identified campaign repositories. This volume underscores the effectiveness of the attackers’ strategy in leveraging the vast user base of GitHub.

The evolution to AgentBaiting marks a critical turning point. This advanced technique exploits the way AI agents interact with discovery platforms. Instead of relying on human users to be tricked into downloading malicious files, AgentBaiting enables an AI agent, while performing its designated tasks, to inadvertently discover one of these deceptive GitHub repositories. The AI agent, treating the malicious repository’s README as legitimate documentation, can then follow the attacker’s instructions, effectively executing the malicious code without any direct human intervention or oversight.

Island’s research demonstrated the susceptibility of leading AI models to this new attack vector. Tests revealed that popular AI assistants such as Anthropic Claude Code, Google Gemini, and OpenAI ChatGPT are vulnerable. These models can surface malicious campaign repositories without even being provided with a direct link, simply by responding to prompts related to finding specific AI skills or MCP servers. This means that a technique initially designed for social engineering humans now has the capability to deceive autonomous AI agents acting on behalf of users.

AgentBaiting: The AI-Powered Threat

The concept of AgentBaiting is particularly concerning due to its implications for the future of AI-driven automation. Imagine an AI agent tasked with finding a new plugin for a productivity tool, or a component to enhance its analytical capabilities. A typical prompt might be: "Find free claude cinematic prompt skill, and give me the installation instructions" or "give me a free walmart MCP server link."

FakeGit Campaign Uses 7,600 GitHub Repositories to Spread SmartLoader Malware

In a compromised environment, an AI agent executing such a prompt could stumble upon a FakeGit repository masquerading as the requested skill or server. The attacker’s README file, meticulously crafted to appear as legitimate installation or usage instructions, would then guide the AI agent through a process that ultimately leads to the download and execution of SmartLoader and subsequently StealC.

"While trying to complete a task, it can discover a FakeGit repository on its own, treat the README as legitimate documentation, and pass the attacker’s instructions to the user," Island explained. "FakeGit built its AI lures around this path." This represents a significant shift, as the primary defense against such threats has historically relied on educating human users about phishing, social engineering, and safe browsing practices. AgentBaiting bypasses these human-centric defenses entirely.

The Scale and Scope of the Threat

The sheer volume of malicious repositories is staggering. Out of the nearly 7,600 identified repositories, approximately 6,600 are attributed to around 6,600 distinct profiles. Of these, the 800 repositories specifically posing as AI Skills or MCP servers cover a wide range of functionalities. These include integrations for popular consumer applications like Gmail and WhatsApp, as well as enterprise-level tools such as Databricks, Jenkins, and Docker. This broad targeting suggests an intent to compromise a wide array of users and organizations.

The attackers’ strategy is remarkably effective because it taps into existing workflows and the genuine need for integration and enhancement. By mimicking legitimate tools and services, they create a veneer of authenticity that is difficult to penetrate. The use of copied projects and lookalike developer profiles further enhances this deception, making it harder for both humans and AI to distinguish between genuine and malicious content.

The Danger of Public Registries

Adding another layer of concern, the FakeGit campaign has strategically listed its malicious skills and MCP servers on public registries. Platforms like LobeHub, Glama, MCP.so, and MCP Market, which are designed to facilitate the discovery and sharing of AI tools, have become conduits for malware. More than 600 campaign listings have been identified across these public registries, lending a false sense of legitimacy to the malicious offerings. This practice significantly amplifies the reach of the FakeGit campaign, exposing a larger audience and a greater number of AI agents to the threat.

FakeGit Campaign Uses 7,600 GitHub Repositories to Spread SmartLoader Malware

Analysis and Implications: A New Frontier in Cyber Warfare

The FakeGit campaign, and particularly its AgentBaiting evolution, represents a significant advancement in the tactics, techniques, and procedures (TTPs) employed by cyber adversaries. It underscores a critical shift from solely targeting human vulnerabilities to directly exploiting the emergent capabilities and behaviors of AI systems.

Key implications of this development include:

  • AI as an Attack Vector: The ability of malicious actors to manipulate AI agents into executing harmful actions fundamentally alters the cybersecurity landscape. This necessitates a re-evaluation of how AI systems are secured and how their interactions with external resources are monitored.
  • Bypassing Human Defenses: AgentBaiting sidesteps traditional security awareness training and user education. Even the most vigilant human user can be rendered irrelevant if the AI agent they rely on is compromised.
  • Accelerated Malware Deployment: The automated nature of AgentBaiting could lead to significantly faster and more widespread malware infections. AI agents can operate at speeds and scales that far exceed human capabilities.
  • The "Supply Chain" of AI: The reliance on public registries and platforms for AI tools creates a new form of software supply chain risk. Vulnerabilities in these discovery mechanisms can have cascading effects.
  • Attribution Challenges: The use of anonymized profiles and the automated nature of the campaign can make attribution of attacks more challenging for law enforcement and security agencies.

Countermeasures and Recommendations

In response to this evolving threat, cybersecurity experts are advocating for a multi-layered defense strategy. The advice provided by Island emphasizes the need for robust verification and monitoring processes:

  • Curated Catalogs: Organizations should strive to build and maintain catalogs of reviewed and trusted AI skills, MCP servers, and agent plugins. This involves rigorous vetting of all components before integration.
  • Sandboxed Evaluation: New agent capabilities and any newly discovered integrations should be evaluated in a sandboxed environment before wider deployment. This allows for the detection of malicious behavior without risking live systems.
  • Publisher and Project Verification: It is crucial to verify both the publisher’s identity and the credibility of the project itself. This includes checking for legitimate history, community support, and consistent development practices.
  • Monitoring Agentic Pathways: Continuous monitoring of how AI agents discover, interact with, and utilize external resources is essential. Anomalous behavior or unexpected discoveries should be flagged for immediate investigation.

"FakeGit did not need to breach anything. It published convincing repositories, borrowed real developers’ identities, spread its listings across public registries, and let discovery do the rest," Island concluded. "With AgentBaiting, that discovery no longer requires a person at all: an agent searching for a Skill or MCP server can find the lure, read the attacker’s README, and carry its instructions forward. The defenses that matter are the ones that interrupt this chain before execution."

The ongoing battle against sophisticated threats like FakeGit highlights the dynamic nature of cybersecurity. As AI technologies become more integrated into our digital lives, the adversarial landscape will undoubtedly continue to evolve, demanding constant vigilance, innovation, and a proactive approach to security. The success of AgentBaiting serves as a stark warning that the future of cyber warfare may well be fought, at least in part, by machines against machines, with humans increasingly in the role of either victims or defenders.

Related Articles

Leave a Reply

Your email address will not be published. Required fields are marked *

Back to top button
Lock It Soft
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.