There has been an extensive malware campaign, dubbed FakeGit, that utilizes thousands of counterfeit GitHub repositories to distribute SmartLoader malware, which is increasingly targeted at exploiting artificial intelligence (AI) tools and Model Context Protocol (MCP) servers in order to distribute the malware.
Researchers at Island have discovered that approximately 7,600 malicious GitHub repositories have been constructed by using approximately 6,600 false developers profiles, creating nearly 7,600 malicious GitHub repositories.
Thousands of repositories are masquerading as AI skills or MCP servers, offering integration with services such as Google Mail, WhatsApp, Docker, Jenkins, and Databricks. It is believed that FakeGit is an evolution of a previous malware operation that was previously associated with Water Kurita and that used Lumma Stealer.
Research by Island researchers indicates that in March 2026, the campaign began focusing on artificial intelligence-based repositories, peaking in April with hundreds of repositories impersonating artificial intelligence tools before expanding into a broader ecosystem of fake AI agents, workflows, and MCP servers. By copying code, creating convincing README files, and impersonating developer identities, the fake repositories are very closely resembling legitimate open-source projects.
A multi-stage infection chain is triggered by the download of malicious ZIP archives. Upon activation, the attack launches a LuaJIT-based loader that launches an obfuscated Lua script to install SmartLoader. SmartLoader establishes persistence on the compromised system and launches StealC, a malicious program capable of harvesting sensitive data from infected devices once it has been activated.
After installation, SmartLoader creates persistence using scheduled tasks, retrieves its C2 server using the Polygon blockchain smart contract, downloads encrypted payloads hosted on GitHub, and ultimately deploys the StealC information stealer by deploying the C2 server. A new advanced tactic, AgentBaiting, has also been identified, which highlights how AI-powered coding assistants and autonomous agents can unintentionally aid hackers in gaining control of a computer.
By optimizing fake repositories, threat actors can provide users with legitimate resources instead of forcing them to visit malicious links. Research conducted by Island researchers demonstrated that Claude Code automatically replicated malicious repositories and downloaded the associated files onto a test system, resulting in the discovery and recommendation of legitimate resources by AI models searching for free AI skills or MCP servers.
In spite of this, the AI assistant detected suspicious indicators before executing the payload, which suggests that even though AI agents can be manipulated into retrieving malicious content, they may still be capable of detecting threats later on during the execution phase.
In spite of the fact that these limited tests were not intended to measure the overall detection capabilities of artificial intelligence coding assistants, Island research demonstrated that AI assistants, such as Anthropic Claude Code, Google Gemini, and OpenAI ChatGPT, could detect malicious repositories during routine searches in response to user requests.
In spite of the fact that these limited tests were not intended to measure the overall detection capabilities of artificial intelligence coding assistants, Island research demonstrated that AI assistants, such as Anthropic Claude Code, Google Gemini, and OpenAI ChatGPT, could detect malicious repositories during routine searches in response to user requests.
Through artificial intelligence-assisted discovery processes, attackers can potentially pass malicious installation
[…]
Content was cut in order to protect the source.Please visit the source for the rest of the article.
[…]
Content was cut in order to protect the source.Please visit the source for the rest of the article.
This article has been indexed from CySecurity News – Latest Information Security and Hacking Incidents
Read the original article:
