Cybersecurity experts have identified a sophisticated malware campaign named FakeGit, which involves approximately 7,600 GitHub repositories. These repositories are designed to masquerade as artificial intelligence (AI) capabilities or Model Context Protocol (MCP) servers, ultimately deploying the SmartLoader malware.
Understanding the FakeGit Campaign
FakeGit employs copied projects, deceptive developer profiles, and misleading README files to deliver the SmartLoader malware. According to Oleg Zaytsev, lead security researcher at Island, the campaign’s objective is to exploit SmartLoader’s capabilities to maintain persistent access and distribute secondary payloads such as StealC, a potent data-harvesting tool.
Previously, the use of compromised MCP servers to deliver SmartLoader and StealC was reported by Straiker AI and Derp.ca. However, a new twist in the FakeGit campaign is the emergence of AgentBaiting, an AI-driven tactic that manipulates AI agents into inadvertently executing malicious tasks.
AgentBaiting and Its Impact
This AI manipulation occurs when AI systems, such as Anthropic Claude Code, Google Gemini, and OpenAI ChatGPT, are deceived into identifying and using these fake GitHub repositories as legitimate sources. This allows the malware to propagate without direct human input.
Out of the malicious repositories, around 800 impersonate Skills or MCP servers, offering integrations with popular tools like Gmail, WhatsApp, Databricks, Jenkins, and Docker. By July 2026, these repositories had amassed over 14 million downloads through GitHub Release assets.
Defensive Measures Against FakeGit
To counter the FakeGit threat, experts recommend developing a catalog of vetted Skills, MCP servers, and agent plugins, testing new agent capabilities in controlled environments before widespread implementation, and verifying the authenticity of publishers and projects.
Furthermore, monitoring AI pathways is crucial to prevent unintended execution of malicious code. Public registries like LobeHub, Glama, MCP.so, and MCP Market are particularly vulnerable as they can give a false sense of legitimacy to these malicious projects.
Island’s findings highlight that FakeGit’s strategy relies on creating convincing repositories and leveraging real developers’ identities to spread its malicious code. With AgentBaiting, the campaign no longer requires human discovery, as AI agents can independently locate and execute the attacker’s instructions.
Looking Forward
The FakeGit campaign underscores the importance of robust cybersecurity measures in the face of evolving threats. As AI systems become more integrated into technological ecosystems, the potential for AI manipulation by malicious actors grows. Organizations must remain vigilant and proactive in safeguarding their digital assets against such innovative cyber threats.
