• Tech Support ⤴
  • Projects
  • Services
    • AI Development
    • UI/UX Design
    • Web Development
    • Technology Support
    • Mobile App Development
    • Banking ATM Interfaces
    • Process Automation
    • Security Auditing
    • Local AI Servers
  • odoo ERP
get in touchStart with Eva
logo
Tech Support ⤴
Projects
Services
AI DevelopmentUI/UX DesignWeb DevelopmentTechnology SupportMobile App DevelopmentBanking ATM InterfacesProcess AutomationSecurity AuditingLocal AI Servers
odoo ERP
get in touchStart with Eva
Loading…
logo

Transforming businesses through AI-powered digital innovation and creative excellence.

Quick Links

BlogAinexProjectsContact us

Contact Us

pinDubai Digital Park, A5, DTEC - Silicon Oasisemail[email protected]phone+971 55 7538087
© 2026 aratech. All rights reserved.
Privacy PolicyTerms of ServiceCookie Policy
Home / Blog / FakeGit: How 7,600 Malicious GitHub Repos Tricked AI Agents Into Installing Malware

FakeGit: How 7,600 Malicious GitHub Repos Tricked AI Agents Into Installing Malware

Researchers uncovered nearly 7,600 malicious GitHub repositories disguised as AI Skills and MCP servers, spreading SmartLoader malware in a campaign called FakeGit. Here's what this means for your AI supply chain.

July 31, 2026 - 0 min read
FakeGit: How 7,600 Malicious GitHub Repos Tricked AI Agents Into Installing Malware

The AI tooling ecosystem just hit a supply-chain landmine. Researchers at Island uncovered nearly 7,600 malicious GitHub repositories, over 800 of them disguised as AI Skills or Model Context Protocol (MCP) servers, spreading SmartLoader malware in a campaign they're calling FakeGit. And here's the twist: you don't even need to be fooled by the repo yourself. AI agents can be fooled on your behalf.

This is a new class of attack. It doesn't exploit a code vulnerability. It exploits trust in the AI agent you delegated discovery to.

How FakeGit Works

The mechanics are deceptively simple. Attackers created around 6,600 GitHub profiles that published repositories mimicking legitimate AI integrations — Gmail helpers, WhatsApp connectors, Databricks tooling, Jenkins pipelines, Docker automation. Each included convincing READMEs, borrowed legitimate developer identities, and ZIP archives loaded with SmartLoader.

When a developer (or an AI agent) discovers the repo and follows installation instructions, the ZIP triggers a LuaJIT loader chain that executes an obfuscated script, drops SmartLoader, and then deploys StealC — an infostealer that harvests browser credentials, crypto wallets, session tokens, and system data.

As of July 2026, the operation had accumulated over 14 million downloads across GitHub Release assets. That's not a small phishing run. That's industrial-scale deception.

AgentBaiting: The AI-Powered Evolution

This is where FakeGit gets genuinely novel. Island researchers tested whether AI coding agents could be tricked into discovering and recommending these malicious repos without any human prompting toward a specific malicious link.

They could. Claude Code, Google Gemini, and OpenAI ChatGPT all surfaced malicious FakeGit repositories autonomously when asked general-purpose prompts like "Find a free Walmart MCP server" or "give me installation instructions for a Claude cinematic prompt skill."

The term they gave it: AgentBaiting. An AI agent, acting on your behalf, goes searching for a tool, stumbles on a malicious repo, reads the attacker's README as legitimate documentation, and passes the attacker's instructions directly to your execution environment. No human ever inspected the source. No human ever noticed the red flags. The agent did exactly what it was asked to do, and the malware rode right through.

Supply Chain Meets AI Registry

The campaign didn't stay on GitHub. Over 600 listings from the operation were flagged across public MCP and Skill registries: LobeHub, Glama, MCP.so, and MCP Market. These registries aggregate and surface AI capabilities to developers and agents alike. By flooding them with polished lures, the attackers built a false sense of legitimacy that compounded the GitHub deception.

This is the supply chain problem, remixed for the AI era. Instead of poisoning npm packages, you poison the discovery pipeline that feeds AI agents and the developers who use them.

What Your Team Should Do Now

Catalog your AI tooling. If your developers or agents are pulling MCP servers or AI Skills from public registries without review, you have an open door. Build an internal registry of reviewed and approved capabilities.

Sandbox agent discoveries. Any AI agent that surfaces a new tool, repo, or integration should trigger a sandboxed evaluation before anything touches production code or credentials.

Verify publishers and projects. Look beyond the README. Check contributor history, cross-reference profiles, verify commit patterns. FakeGit's profiles were convincing at a glance but collapsed under light scrutiny. The problem was, nobody scrutinized.

Monitor agentic pathways. Log what your agents discover, recommend, and execute. Anomaly detection here isn't about code signatures. It's about behavioral patterns that don't match legitimate discovery workflows.

The Bottom Line

FakeGit didn't breach anything. It didn't exploit a zero-day. It published convincing repositories, copied real developers' identities, spread across public registries, and let discovery do the rest. The AI agents, eager to help, did the delivery work.

This is the shape of attacks to come. Not exploits against models, but exploits through models — using their helpfulness, their autonomy, and their access to your toolchain as the attack surface.

Treat your AI agent's recommendations the same way you'd treat a stranger's USB drive found in the parking lot. The era of blind trust in AI-assisted discovery is over.

Table of Contents

  • ↗How FakeGit Works
  • ↗AgentBaiting: The AI-Powered Evolution
  • ↗Supply Chain Meets AI Registry
  • ↗What Your Team Should Do Now
  • ↗The Bottom Line

Related Posts

Stripe Acquires OpenRouter for $7B: Payments Giant Takes the AI Routing Layer

Stripe has finalized a deal to acquire OpenRouter for over $7 billion, more than 5x its $1.3 billion valuation from just 82 days ago. The acquisition gives the payments giant control of the routing layer that 8 million developers use to access 400+ AI models, signaling that fintech and AI infrastructure are converging fast.

Necolas HamwiNecolas Hamwi
August 20, 2026 - 7 min read
Dark cyberpunk illustration of an AI copilot chatbot being manipulated by digital attackers, with neon purple and cyan circuits and red security warnings

Microsoft Copilot CoSnitch: When Your AI Assistant Becomes Its Own Whistleblower

Varonis Threat Labs discovered three chained vulnerabilities in Microsoft Copilot Personal that allow one-click data exfiltration from connected apps like Gmail and Google Drive. Dubbed 'CoSnitch' (CVE-2026-24301), the attack chain is notable because the AI itself revealed how to exploit it through a technique researchers call meta-hacking.

Necolas HamwiNecolas Hamwi
August 19, 2026 - 7 min read
Dark cyberpunk data center visualization with neon purple and cyan energy streams flowing through massive server infrastructure

Nvidia's $105B Data Center Bet: What OpenAI's Ohio Mega-Project Means for AI Infrastructure

Nvidia just guaranteed up to $105 billion for OpenAI's massive Ohio data center and invested $1.5B in SB Energy. The PORTS-Pike project will deliver 8 GW of AI compute, create 35,000 construction jobs, and transform a Cold War-era site into America's largest AI infrastructure hub.

Necolas HamwiNecolas Hamwi
August 18, 2026 - 7 min read