Cybersecurity researchers have uncovered a large scale malware campaign known as FakeGit that uses nearly 7,600 malicious GitHub repositories to distribute SmartLoader malware. According to a report from Island shared with The Hacker News, more than 800 of these repositories impersonate artificial intelligence skills or Model Context Protocol (MCP) servers to lure developers and organizations into downloading malicious files. Researchers said the campaign relies on copied open source projects, lookalike developer profiles, convincing README documentation, and weaponized ZIP archives to infect victims. Oleg Zaytsev, Lead Security Researcher at Island, explained that the primary objective of the operation is to deploy SmartLoader, which establishes persistence on compromised systems and delivers secondary malware such as StealC, an information stealing malware capable of collecting sensitive data from infected devices.
The researchers noted that the use of trojanized MCP servers to spread SmartLoader and StealC had previously been identified by Straiker AI and later by Derp.ca. However, FakeGit introduces a more advanced technique called AgentBaiting that extends the attack beyond human users. Instead of relying solely on social engineering, the campaign is designed to deceive artificial intelligence assistants searching for AI skills or MCP servers. During testing, Island found that Anthropic Claude Code, Google Gemini, and OpenAI ChatGPT could all surface malicious repositories without being provided with direct links. This means an AI assistant searching for software components on behalf of a user may independently discover a FakeGit repository, interpret the included README as legitimate documentation, and recommend installation steps that ultimately execute the attacker’s instructions. Researchers believe this represents an important shift in how malicious actors exploit AI assisted discovery, transforming a technique traditionally aimed at people into one capable of misleading AI agents performing automated tasks.
According to Island, approximately 6,600 developer profiles were used to create the 7,600 malicious repositories, with more than 800 presenting themselves as AI Skills or MCP servers supporting both consumer and enterprise services. These fake projects claimed to offer integrations for platforms including Gmail, WhatsApp, Databricks, Jenkins, and Docker. By July 2026, around 200 campaign repositories had collectively generated more than 14 million downloads of GitHub Release assets. Researchers explained that the repositories were intentionally designed to match growing demand for artificial intelligence tools, borrowing familiar names and workflows to make the downloads appear trustworthy. Some repositories were entirely fabricated while others copied legitimate open source projects. Victims downloading the provided ZIP archives unknowingly triggered a LuaJIT based loader chain that executed an obfuscated Lua script responsible for installing SmartLoader before deploying StealC. Island also demonstrated how attackers could influence AI assistants with prompts requesting free AI skills or MCP servers, causing the models to locate malicious repositories without any attacker supplied link. Once discovered, the AI assistant could pass the malicious installation instructions directly to the user, unknowingly assisting the attack.
Researchers warned that the risk increases further because many of the fake repositories were also listed in public MCP and AI Skill registries, including LobeHub, Glama, MCP.so, and MCP Market, giving the projects additional credibility. More than 600 campaign listings have already been identified across these public registries. To reduce exposure, Island recommends that organizations maintain a trusted catalog of reviewed AI Skills, MCP servers, and agent plugins while evaluating new AI capabilities in isolated sandbox environments before production deployment. Security teams are also advised to verify both the publisher and the project before installation and continuously monitor AI driven workflows for suspicious behavior. Researchers emphasized that the FakeGit campaign did not rely on exploiting software vulnerabilities or breaching systems directly. Instead, it created convincing repositories, impersonated legitimate developers, distributed listings across trusted public registries, and relied on AI assisted discovery to reach victims. The emergence of AgentBaiting highlights how AI powered software discovery can become an effective delivery channel for malware if organizations do not verify the authenticity of repositories before allowing AI assistants or users to install new tools.
Follow the SPIN IDG WhatsApp Channel for updates across the Smart Pakistan Insights Network covering all of Pakistan’s technology ecosystem.