A big-scale operation dubbed “FakeGit” pushed SmartLoader and StealC malware by way of 7,600 malicious GitHub repositories, leading to greater than 14 million cumulative downloads.
Over 800 repositories masquerading as AI expertise or MCP servers appeared over 600 instances in public AI registries and catalogs. This will increase the probabilities of being found by AI brokers and builders. It is a method researchers name “agent baiting.”
The marketing campaign is believed to be a continuation of an older marketing campaign utilizing Lumma Stealer and is believed to be the work of a menace actor tracked by researchers at cybersecurity agency Development Micro as “Water Kurata.”
In keeping with researchers at enterprise browser platform Island, the give attention to AI was launched in March and peaked in April, with the creation of 300 GitHub repositories linked to AI instruments.
Researchers discovered that FakeGit has grown to greater than 1,400 repositories associated to AI instruments, brokers, and workflows, all of which hyperlink to downloads of SmartLoader or StealC malware.

Supply: Island
Most of the repositories mimic client and enterprise instruments reminiscent of Gmail, WhatsApp, Databricks, Jenkins, and Docker, and embody convincing documentation, fabricated star and fork counts, copied undertaking descriptions, and actual developer account names.
Their README file instructs guests to obtain a ZIP archive that pretends to be an installer or undertaking launch, however is a disguised Lua payload that triggers the SmartLoader.
As soon as activated, the SmartLoader establishes persistence by way of a scheduled job, obtains a command and management (C2) tackle by way of a Polygon good contract, downloads extra encryption levels from GitHub, and at last delivers the StealC info stealer.
Agent baiting methodology
Island researchers say the malicious repository is a part of a brand new method referred to as AgentBaiting, which goals to extend visibility into AI brokers and improve their probability of use.
In a standard state of affairs, the agent may parse the contents of the README as legit documentation and advocate a repository or ZIP file to a human operator.

Supply: Island
In Island’s assessments, ChatGPT, Gemini, and Claude surfaced varied malicious repositories when prompted for associated duties, and in some instances relayed set up directions.
Island found greater than 600 listings of expertise and MCP servers linked to FakeGit campaigns in public registries and catalogs. A few of them embody LobeHub, Glama, MCP.so, and MCP Market, indicating that this operation has already penetrated the ecosystem and polluted public assets.
The researchers couldn’t decide whether or not the lists had been submitted manually or listed routinely, however stated the presence of the lists made the repositories simpler to find and elevated belief.
Island researchers advised BleepingComputer that in restricted, managed testing, Claude Code cloned a malicious repository and downloaded malicious information onto take a look at machines.
Nonetheless, the agent then detected a suspicious indicator and stopped earlier than operating.
This take a look at just isn’t designed to ascertain a detection fee, so it can’t give a definitive outcome on whether or not coding brokers can constantly acknowledge hazards in the course of the execution part.
.jpg)
Supply: Island
Concerning the broader impression of the marketing campaign, Island studies that GitHub’s public obtain counter recorded a cumulative complete of 14,084,688 obtain occasions for 335 distinctive launch property throughout 211 GitFake repositories.
Oleg Zaytsev, lead safety researcher at Island, clarified that this quantity shouldn’t be interpreted as an an infection, because it contains repeated requests and automatic exercise.
Island recommends that organizations preserve an authorised catalog of expertise and MCP servers, take a look at new options in an remoted setting, and independently confirm publishers and repositories.
In case you suspect SmartLoader execution, you need to instantly rotate all secrets and techniques on the affected setting.
Safety groups doc 54% of profitable assaults and problem a warning on solely 14%. The remaining strikes invisibly by way of the setting.
Picus’ whitepaper reveals take a look at your SIEM and EDR guidelines in breach and assault simulations to make sure threats go undetected.
Get the white paper
