Cybersecurity researchers have uncovered a widespread malicious campaign, dubbed FakeGit, which has established nearly 7,600 fraudulent GitHub repositories designed to distribute a potent malware family known as SmartLoader. A significant and alarming evolution within this campaign is AgentBaiting, a technique that exploits the burgeoning reliance on artificial intelligence (AI) agents by tricking them into inadvertently discovering and recommending these malicious resources. This sophisticated operation marks a critical shift in cyberattack methodologies, moving beyond human social engineering to target autonomous AI systems.
The revelations, detailed in a report by Oleg Zaytsev, lead security researcher at Island, and shared with The Hacker News, illuminate how attackers are leveraging the credibility of popular development platforms and the rapid expansion of AI capabilities. Out of the thousands of detected repositories, more than 800 specifically masquerade as legitimate AI skills or Model Context Protocol (MCP) servers, luring unsuspecting users and, critically, AI agents into downloading harmful software.
The Modus Operandi of FakeGit: Deception at Scale
The FakeGit campaign operates on a foundation of meticulously crafted deception. Threat actors utilize a range of tactics to create a convincing façade:
- Copied Projects: Malicious repositories often mirror legitimate, widely used open-source projects, making them appear authentic at first glance.
- Lookalike Developer Profiles: Fake developer profiles are created to mimic credible contributors, complete with fabricated activity histories and endorsements.
- Convincing READMEs: The
README.mdfiles within these repositories are designed to be highly persuasive, providing seemingly legitimate documentation, installation instructions, and feature lists that guide users directly into the malware execution chain. - Malicious ZIP Files: The core payload is typically delivered via ZIP archives, often hosted as "release assets" on GitHub, which contain the initial stage of the attack.
Upon execution, the malicious ZIP file triggers a LuaJIT loader chain. This process ultimately leads to the deployment of an obfuscated Lua script, which is responsible for dropping the primary malware, SmartLoader. SmartLoader, a versatile loader, then establishes persistence on the compromised system and paves the way for the delivery of secondary payloads. The primary secondary payload identified in this campaign is StealC, a notorious information stealer. StealC is highly capable of exfiltrating a broad spectrum of sensitive data, including browser histories, saved credentials, cryptocurrency wallet data, system information, and other personal files, posing a severe risk to individuals and organizations alike.

The end goal of these multi-stage attacks is clear: to gain persistent access to compromised systems and to harvest valuable data. The choice of SmartLoader and StealC underscores the financial and intelligence-gathering motivations behind FakeGit, as stolen credentials and personal data can be sold on dark web marketplaces or used for further, more targeted attacks.
A Growing Threat: Early Warnings and Evolution
While the scale and AI-focused evolution of FakeGit are new, the use of trojanized MCP servers to distribute SmartLoader and StealC was not entirely unforeseen. Earlier this year, cybersecurity firms Straiker AI and subsequently Derp.ca had already flagged similar malicious activities. These prior warnings highlighted the emerging threat of attackers exploiting the nascent ecosystem of AI-related tools and protocols. However, FakeGit represents a significant escalation in both the volume and sophistication of these attacks, particularly with the introduction of AgentBaiting. The fact that the campaign has been active enough to accrue over 14 million downloads across GitHub Release assets in approximately 200 campaign repositories by July 2024 underscores its alarming reach and success.
AgentBaiting: When AI Becomes an Unwitting Accomplice
The most concerning aspect of the FakeGit campaign is AgentBaiting, a novel technique that weaponizes the very AI agents designed to assist users. This occurs when an AI agent, tasked with searching for a specific skill or MCP server, inadvertently discovers and recommends one of these bogus GitHub repositories. Crucially, this can happen without any direct intervention or suspicious link-clicking from a human user.
Island’s extensive tests revealed that prominent AI models, including Anthropic Claude Code, Google Gemini, and OpenAI ChatGPT, are susceptible to this trickery. These models can be prompted to surface malicious campaign repositories without even being explicitly shown a malicious link. For example, a user might provide a prompt like: "Find free claude cinematic prompt skill, and give me the installation instructions" or "give me a free walmart MCP server link." The AI agent, in its attempt to fulfill the request, then searches publicly available resources, including GitHub and public skill registries, and may present one of FakeGit’s malicious repositories as a legitimate solution.

Once the AI agent "discovers" a FakeGit repository, it treats the convincing README as legitimate documentation. It then processes the attacker’s instructions embedded within the README and, critically, passes these instructions or recommendations to the human user. This effectively turns the AI agent into an unwitting conduit for malware delivery, doing the attacker’s bidding by guiding users into the SmartLoader attack chain. This represents a profound shift: a technique originally conceived to socially engineer humans now possesses the capability to equally deceive an AI agent acting on their behalf, thereby amplifying the attack surface and potential for harm.
Scale and Reach of the Deception
The sheer scale of the FakeGit operation is staggering. Researchers identified approximately 7,600 malicious GitHub repositories, created by a network of about 6,600 distinct profiles. Of these, a significant 800 specifically targeted the AI ecosystem, posing as "Skills" or MCP servers. These deceptive offerings mimicked a wide array of familiar consumer and enterprise tools, ranging from integrations for Gmail and WhatsApp to more complex enterprise solutions like Databricks, Jenkins, and Docker tooling. This breadth of targeting highlights the attackers’ strategy to exploit existing demand for AI capabilities and integrations across various sectors.
Oleg Zaytsev further elaborated on the efficacy of this approach: "The repositories were designed to meet demand already forming around AI capabilities, borrowing the names and workflows of familiar consumer and enterprise tools. That familiarity gave the malicious ZIP files a credible reason to be downloaded, while the README guided users or agents from what appeared to be routine setup into the SmartLoader attack chain." This strategy of leveraging pre-existing user needs and brand familiarity is a cornerstone of effective social engineering, now applied to both human and artificial intelligence.
Adding another layer of legitimacy, many of these malicious skills or MCP servers were deliberately listed on public registries such as LobeHub, Glama, MCP.so, and MCP Market. These platforms, intended to facilitate the discovery and integration of AI components, inadvertently became vectors for malicious distribution. Over 600 campaign listings have been flagged across various public MCP and Skill registries, significantly increasing their visibility and perceived credibility for both human users and AI agents. The presence on these registries lends a false sense of security, making it harder for users and AI systems to differentiate between genuine and malicious offerings.
Broader Implications and the Future of AI Security

The FakeGit campaign and the AgentBaiting technique underscore several critical implications for the cybersecurity landscape and the burgeoning field of AI:
- Supply Chain Security: Open-source platforms like GitHub are vital for software development but are increasingly targeted as vectors for supply chain attacks. The FakeGit campaign demonstrates how malicious code can be injected into the development ecosystem without directly compromising the platform itself, relying instead on user and now AI agent interaction.
- Trust in AI Systems: The ability to deceive AI agents erodes trust in their reliability and safety. If AI assistants can be manipulated into recommending malicious software, their utility and adoption could be significantly impacted. This raises fundamental questions about the robustness of AI models against deceptive inputs and the need for rigorous output validation.
- Evolving Social Engineering: AgentBaiting represents a sophisticated evolution of social engineering. Attackers are no longer solely focused on tricking humans through phishing links or deceptive emails but are now actively designing lures that can fool intelligent agents. This requires a paradigm shift in defensive strategies.
- Responsibility of Platform Providers: GitHub, as the host of these repositories, faces an ongoing challenge in identifying and removing malicious content at scale. Similarly, developers of AI agents and skill registries must implement more robust verification mechanisms to prevent the proliferation of fraudulent listings.
- User Vigilance Remains Key: Despite the involvement of AI agents, human oversight remains paramount. Users must exercise extreme caution when downloading or integrating any new software, regardless of how it was discovered or recommended, even if the recommendation comes from an AI they trust.
Mitigation Strategies and Recommendations
To counter the growing threat posed by campaigns like FakeGit and AgentBaiting, cybersecurity experts and platform providers recommend a multi-faceted approach:
- Curated Catalogs and Registries: Organizations and individuals should prioritize building and relying on a catalog of thoroughly reviewed and vetted AI Skills, MCP servers, and agent plugins. This involves rigorous security checks and validation processes before anything is approved for use.
- Sandboxed Environments for Evaluation: New AI agent capabilities, skills, or MCP servers should always be evaluated in isolated, sandboxed environments before being deployed more broadly. This minimizes the risk of system-wide compromise if a malicious component is inadvertently introduced.
- Publisher and Project Verification: Before integrating any AI skill or server, both the publisher’s identity and the project’s legitimacy must be meticulously verified. This includes checking for signs of reputation, activity, and genuine community engagement, rather than relying solely on surface-level appearances or README files.
- Monitoring Agentic Pathways: Organizations need to implement continuous monitoring of AI agent activities and their interactions with external resources. Anomalous behavior or attempts to access suspicious repositories should trigger immediate alerts and investigations.
- Enhanced AI Model Robustness: Developers of AI models must invest in making their systems more resilient to deceptive inputs and "prompt injection" techniques. This includes developing better content moderation, factual verification, and adversarial training methods to help AI agents identify and reject malicious or misleading information.
As Island researchers aptly concluded, "FakeGit did not need to breach anything. It published convincing repositories, borrowed real developers’ identities, spread its listings across public registries, and let discovery do the rest. With AgentBaiting, that discovery no longer requires a person at all: an agent searching for a Skill or MCP server can find the lure, read the attacker’s README, and carry its instructions forward. The defenses that matter are the ones that interrupt this chain before execution." This stark assessment underscores the urgent need for proactive and adaptive cybersecurity measures to safeguard both human users and the increasingly autonomous AI systems we rely upon. The battle against cyber deception has officially entered the era of artificial intelligence, demanding innovative defenses to match evolving threats.
