Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
FakeGit Exploits GitHub to Distribute SmartLoader Malware

FakeGit Exploits GitHub to Distribute SmartLoader Malware

Posted on July 20, 2026 By CWS

Cybersecurity experts have identified a sophisticated malware campaign named FakeGit, which involves approximately 7,600 GitHub repositories. These repositories are designed to masquerade as artificial intelligence (AI) capabilities or Model Context Protocol (MCP) servers, ultimately deploying the SmartLoader malware.

Understanding the FakeGit Campaign

FakeGit employs copied projects, deceptive developer profiles, and misleading README files to deliver the SmartLoader malware. According to Oleg Zaytsev, lead security researcher at Island, the campaign’s objective is to exploit SmartLoader’s capabilities to maintain persistent access and distribute secondary payloads such as StealC, a potent data-harvesting tool.

Previously, the use of compromised MCP servers to deliver SmartLoader and StealC was reported by Straiker AI and Derp.ca. However, a new twist in the FakeGit campaign is the emergence of AgentBaiting, an AI-driven tactic that manipulates AI agents into inadvertently executing malicious tasks.

AgentBaiting and Its Impact

This AI manipulation occurs when AI systems, such as Anthropic Claude Code, Google Gemini, and OpenAI ChatGPT, are deceived into identifying and using these fake GitHub repositories as legitimate sources. This allows the malware to propagate without direct human input.

Out of the malicious repositories, around 800 impersonate Skills or MCP servers, offering integrations with popular tools like Gmail, WhatsApp, Databricks, Jenkins, and Docker. By July 2026, these repositories had amassed over 14 million downloads through GitHub Release assets.

Defensive Measures Against FakeGit

To counter the FakeGit threat, experts recommend developing a catalog of vetted Skills, MCP servers, and agent plugins, testing new agent capabilities in controlled environments before widespread implementation, and verifying the authenticity of publishers and projects.

Furthermore, monitoring AI pathways is crucial to prevent unintended execution of malicious code. Public registries like LobeHub, Glama, MCP.so, and MCP Market are particularly vulnerable as they can give a false sense of legitimacy to these malicious projects.

Island’s findings highlight that FakeGit’s strategy relies on creating convincing repositories and leveraging real developers’ identities to spread its malicious code. With AgentBaiting, the campaign no longer requires human discovery, as AI agents can independently locate and execute the attacker’s instructions.

Looking Forward

The FakeGit campaign underscores the importance of robust cybersecurity measures in the face of evolving threats. As AI systems become more integrated into technological ecosystems, the potential for AI manipulation by malicious actors grows. Organizations must remain vigilant and proactive in safeguarding their digital assets against such innovative cyber threats.

The Hacker News Tags:AgentBaiting, AI agents, AI security, cyber attack, Cybersecurity, digital safety, FakeGit, GitHub, Malware, MCP servers, SmartLoader, StealC, threat detection

Post navigation

Previous Post: New Malware Exploits Microsoft 365 Calendars for Covert Commands
Next Post: Paidwork Data Breach Exposes Millions of Users’ Data

Related Posts

Google Cloud API Key Exposure Risks Highlighted in New Study Google Cloud API Key Exposure Risks Highlighted in New Study The Hacker News
DNS Poisoning Flaw, Supply-Chain Heist, Rust Malware Trick and New RATs Rising DNS Poisoning Flaw, Supply-Chain Heist, Rust Malware Trick and New RATs Rising The Hacker News
Preinstalled Apps on Ulefone, Krüger&Matz Phones Let Any App Reset Device, Steal PIN Preinstalled Apps on Ulefone, Krüger&Matz Phones Let Any App Reset Device, Steal PIN The Hacker News
Proxy Botnet, Office Zero-Day, MongoDB Ransoms, AI Hijacks & New Threats Proxy Botnet, Office Zero-Day, MongoDB Ransoms, AI Hijacks & New Threats The Hacker News
Europol Shuts Down Six DDoS-for-Hire Services Used in Global Attacks Europol Shuts Down Six DDoS-for-Hire Services Used in Global Attacks The Hacker News
New PathWiper Data Wiper Malware Disrupts Ukrainian Critical Infrastructure in 2025 Attack New PathWiper Data Wiper Malware Disrupts Ukrainian Critical Infrastructure in 2025 Attack The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • UNC6671 Cyber Threat Intensifies with Vishing Attacks
  • ChainDrop Worm Targets npm Packages for Credential Theft
  • macOS Malware Steals Crypto via ClickFix Attacks
  • Malware Exploits Windows Hello Keys to Access Entra ID
  • 800 Malicious npm Packages Spread Cross-Platform Malware

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • UNC6671 Cyber Threat Intensifies with Vishing Attacks
  • ChainDrop Worm Targets npm Packages for Credential Theft
  • macOS Malware Steals Crypto via ClickFix Attacks
  • Malware Exploits Windows Hello Keys to Access Entra ID
  • 800 Malicious npm Packages Spread Cross-Platform Malware

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark