Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
FakeGit Exploits GitHub to Distribute SmartLoader Malware

FakeGit Exploits GitHub to Distribute SmartLoader Malware

Posted on July 20, 2026 By CWS

Cybersecurity experts have identified a sophisticated malware campaign named FakeGit, which involves approximately 7,600 GitHub repositories. These repositories are designed to masquerade as artificial intelligence (AI) capabilities or Model Context Protocol (MCP) servers, ultimately deploying the SmartLoader malware.

Understanding the FakeGit Campaign

FakeGit employs copied projects, deceptive developer profiles, and misleading README files to deliver the SmartLoader malware. According to Oleg Zaytsev, lead security researcher at Island, the campaign’s objective is to exploit SmartLoader’s capabilities to maintain persistent access and distribute secondary payloads such as StealC, a potent data-harvesting tool.

Previously, the use of compromised MCP servers to deliver SmartLoader and StealC was reported by Straiker AI and Derp.ca. However, a new twist in the FakeGit campaign is the emergence of AgentBaiting, an AI-driven tactic that manipulates AI agents into inadvertently executing malicious tasks.

AgentBaiting and Its Impact

This AI manipulation occurs when AI systems, such as Anthropic Claude Code, Google Gemini, and OpenAI ChatGPT, are deceived into identifying and using these fake GitHub repositories as legitimate sources. This allows the malware to propagate without direct human input.

Out of the malicious repositories, around 800 impersonate Skills or MCP servers, offering integrations with popular tools like Gmail, WhatsApp, Databricks, Jenkins, and Docker. By July 2026, these repositories had amassed over 14 million downloads through GitHub Release assets.

Defensive Measures Against FakeGit

To counter the FakeGit threat, experts recommend developing a catalog of vetted Skills, MCP servers, and agent plugins, testing new agent capabilities in controlled environments before widespread implementation, and verifying the authenticity of publishers and projects.

Furthermore, monitoring AI pathways is crucial to prevent unintended execution of malicious code. Public registries like LobeHub, Glama, MCP.so, and MCP Market are particularly vulnerable as they can give a false sense of legitimacy to these malicious projects.

Island’s findings highlight that FakeGit’s strategy relies on creating convincing repositories and leveraging real developers’ identities to spread its malicious code. With AgentBaiting, the campaign no longer requires human discovery, as AI agents can independently locate and execute the attacker’s instructions.

Looking Forward

The FakeGit campaign underscores the importance of robust cybersecurity measures in the face of evolving threats. As AI systems become more integrated into technological ecosystems, the potential for AI manipulation by malicious actors grows. Organizations must remain vigilant and proactive in safeguarding their digital assets against such innovative cyber threats.

The Hacker News Tags:AgentBaiting, AI agents, AI security, cyber attack, Cybersecurity, digital safety, FakeGit, GitHub, Malware, MCP servers, SmartLoader, StealC, threat detection

Post navigation

Previous Post: New Malware Exploits Microsoft 365 Calendars for Covert Commands
Next Post: Paidwork Data Breach Exposes Millions of Users’ Data

Related Posts

Coinbase Agents Bribed, Data of ~1% Users Leaked; M Extortion Attempt Fails Coinbase Agents Bribed, Data of ~1% Users Leaked; $20M Extortion Attempt Fails The Hacker News
ZiChatBot Malware Found in PyPI Packages Exploiting Zulip APIs ZiChatBot Malware Found in PyPI Packages Exploiting Zulip APIs The Hacker News
Crypto-Mining Risks in Fortune 500 Cloud Systems Revealed Crypto-Mining Risks in Fortune 500 Cloud Systems Revealed The Hacker News
Russia-Aligned Hackers Abuse Viber to Target Ukrainian Military and Government Russia-Aligned Hackers Abuse Viber to Target Ukrainian Military and Government The Hacker News
TeamPCP Exploits LiteLLM via CI/CD Flaw TeamPCP Exploits LiteLLM via CI/CD Flaw The Hacker News
Apple Widens iOS 18.7.7 Update to Shield Against DarkSword Apple Widens iOS 18.7.7 Update to Shield Against DarkSword The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Phishing in Microsoft 365 Exploits Empty Envelope Sender
  • OpenAI Agents Exploit German Wiki to Share Bypass Tactics
  • Nvidia Acquires AI Platform Hugging Face for $13 Billion
  • Microsoft Addresses Exchange Online Email Delays
  • Google Addresses Sixth Chrome Zero-Day in 2026

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Phishing in Microsoft 365 Exploits Empty Envelope Sender
  • OpenAI Agents Exploit German Wiki to Share Bypass Tactics
  • Nvidia Acquires AI Platform Hugging Face for $13 Billion
  • Microsoft Addresses Exchange Online Email Delays
  • Google Addresses Sixth Chrome Zero-Day in 2026

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark