- Cybersecurity researchers uncovered nearly 7,600 malicious GitHub repositories in the FakeGit campaign, with over 800 posing as AI skills or MCP servers.
- The repositories deliver SmartLoader malware, which deploys the StealC information stealer to harvest sensitive data.
- A new technique called AgentBaiting allows AI agents to discover these bogus repositories without human intervention.
- Tests show Anthropic Claude Code, Google Gemini, and OpenAI ChatGPT are susceptible to this trickery.
- The campaign has recorded more than 14 million downloads across about 200 repository releases as of July 2026.
Cybersecurity researchers have identified a massive campaign dubbed FakeGit, involving nearly 7,600 malicious GitHub repositories that deliver SmartLoader malware, with over 800 specifically designed to mimic AI skills or Model Context Protocol (MCP) servers. Island lead researcher Oleg Zaytsev said the campaign uses copied projects, lookalike profiles, and convincing READMEs to trick users into downloading malicious ZIP files.
The ultimate goal is to deploy StealC, an information stealer capable of harvesting a wide range of data from compromised systems. The use of trojanized MCP servers to distribute SmartLoader and StealC was flagged earlier this year by Straiker AI and subsequently by Derp.ca.
A concerning evolution called AgentBaiting enables AI agents to discover these bogus repositories on their own. Island tests showed that Anthropic Claude Code, Google Gemini, and OpenAI ChatGPT can be tricked into surfacing malicious repositories without being given a direct link.
The FakeGit operation has recorded more than 14 million downloads across GitHub Release assets in about 200 campaign repositories. These repositories borrowed names of familiar tools like Gmail, WhatsApp, Databricks, Jenkins, and Docker to appear legitimate.
Over 600 campaign listings have been found on public MCP and Skill registries such as LobeHub, Glama, MCP.so, and MCP Market. Island advises building a catalog of reviewed skills and verifying publishers to counter the threat.
✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.
