HackMyIP
← Back to News
2026-07-20 The Hacker News

FakeGit Malware Hits 7,600 GitHub Repos to Target AI Agents

MalwareAI ThreatsSupply Chain

Cybersecurity researchers at Island have uncovered a sprawling malware distribution operation dubbed FakeGit that has flooded GitHub with nearly 7,600 malicious repositories, more than 800 of which impersonate AI skills and Model Context Protocol (MCP) servers to deliver a loader known as SmartLoader. Lead researcher Oleg Zaytsev told The Hacker News that the operators behind the campaign rely on copied projects, lookalike developer profiles, polished READMEs, and weaponized ZIP archives to lure victims. Once executed, the ZIP triggers a LuaJIT loader chain that runs an obfuscated Lua script to drop SmartLoader, which in turn deploys StealC, an information stealer capable of harvesting credentials, browser data, and other sensitive material from compromised systems. According to Island, the operation had logged more than 14 million downloads across roughly 200 GitHub Release assets as of July 2026, with bogus repositories posing as integrations for Gmail, WhatsApp, Databricks, Jenkins, and Docker tooling.

The campaign's most alarming innovation is a technique called AgentBaiting, which weaponizes AI assistants themselves. When an agent such as Anthropic Claude Code, Google Gemini, or OpenAI ChatGPT is asked to find a skill or MCP server, the FakeGit repositories are surfaced as legitimate results, causing the model to fetch and run attacker code without any user-supplied link or human intervention. This blurs the line between social engineering humans and socially engineering AI on their behalf. Similar trojanized MCP server activity was previously flagged by Straiker AI and Derp.ca earlier this year, but Island's analysis shows the threat has scaled dramatically across about 6,600 attacker-controlled GitHub profiles.

The implications extend beyond developers experimenting with AI tooling. Any organization deploying autonomous agents that can browse repositories, install packages, or invoke MCP servers inherits the risk of an agent pulling SmartLoader directly into a production environment. Security teams should audit which GitHub sources their agents are permitted to query, apply strict allow-listing, and monitor outbound connections for suspicious LuaJIT or StealC indicators. Individual users concerned about credential exposure can run a password checker to see whether stolen credentials tied to this campaign have surfaced in known breaches, while a broader privacy checkup can help identify what data is currently exposed online. For defenders investigating suspicious agent traffic, a DNS leak test is a quick way to confirm whether hostnames are resolving through unintended channels that could indicate command-and-control activity.

Source: The Hacker News →

Related Tools

Check whether this kind of story affects you — free, no signup:

My IP →IP Lookup →Privacy Checkup →

Related Guides

Learn the background behind this story:

What is my IP and why it matters →IP address security →How to stop being tracked online →