{"id":4641,"date":"2026-07-23T23:13:54","date_gmt":"2026-07-23T23:13:54","guid":{"rendered":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/2026\/07\/23\/fakegit-targets-ai-coding-agents-with-malicious-github-repos\/"},"modified":"2026-07-23T23:13:54","modified_gmt":"2026-07-23T23:13:54","slug":"fakegit-targets-ai-coding-agents-with-malicious-github-repos","status":"publish","type":"post","link":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/2026\/07\/23\/fakegit-targets-ai-coding-agents-with-malicious-github-repos\/","title":{"rendered":"FakeGit Targets AI Coding Agents with Malicious GitHub Repos"},"content":{"rendered":"<div><img data-opt-id=1280437455  fetchpriority=\"high\" decoding=\"async\" width=\"770\" height=\"330\" src=\"https:\/\/devops.com\/wp-content\/uploads\/2026\/07\/ghostapproval_ai_coding_agents_770x330.jpg\" class=\"attachment-large size-large wp-post-image\" alt=\"\" \/><\/div>\n<p><img data-opt-id=334085584  fetchpriority=\"high\" decoding=\"async\" width=\"150\" height=\"150\" src=\"https:\/\/devops.com\/wp-content\/uploads\/2026\/07\/ghostapproval_ai_coding_agents_770x330-150x150.jpg\" class=\"attachment-thumbnail size-thumbnail wp-post-image\" alt=\"\" \/><\/p>\n<p>Threat actors continue to find new ways to incorporate AI into schemes aimed at luring developers into downloading malware from fake repositories.<\/p>\n<p>The latest example involves almost 7,600 malicious GitHub repositories that are being used to distribute a loader and an information-stealer. The FakeGit campaign is nothing new, with Oleg Zaytsev, lead security researcher with Island, noting that it and SmartLoader have been haunting developers for years with false GitHub repositories that deliver the malware.<\/p>\n<p>What\u2019s new is that the bad actors behind FakeGit have added AI into the mix, with many of the repositories presenting as AI skills or <a href=\"https:\/\/devops.com\/coralogix-mcp-server-offers-observability-view-into-ai-agents\/\" target=\"_blank\" rel=\"noopener\">Model Context Protocol (MCP) servers<\/a> and driving exposure via AI registries. They\u2019re part of a technique Island calls \u201cAgentBaiting,\u201d which happens when a developer sends out an AI agent to autonomously find something they can use within GitHub repositories.<\/p>\n<p>\u201cThis brought an established malware operation into the workflows people and agents use to discover and install new AI capabilities,\u201d Zaytsev <a href=\"https:\/\/www.island.io\/blog\/agentbaiting-how-800-fake-ai-skills-and-mcp-servers-delivered-malware\" target=\"_blank\" rel=\"noopener\">wrote in a report<\/a>. \u201cAn AI agent searching for a new capability such as a Skill or an MCP server can discover a campaign repository on its own, treat the attacker\u2019s README as legitimate documentation, and hand the installation instructions to the user.\u201d<\/p>\n<h3>Surfacing Malicious Repositories<\/h3>\n<p>Island researchers in tests found that <a href=\"https:\/\/devops.com\/coralogix-mcp-server-offers-observability-view-into-ai-agents\/\" target=\"_blank\" rel=\"noopener\">Anthropic\u2019s Claude Code<\/a>, <a href=\"https:\/\/devops.com\/google-adds-hooks-to-gemini-cli-for-customized-ai-workflows\/\" target=\"_blank\" rel=\"noopener\">Google\u2019s Gemini<\/a>, and <a href=\"https:\/\/devops.com\/chatgpt-developer-mode-full-mcp-access-with-serious-responsibilities\/\" target=\"_blank\" rel=\"noopener\">OpenAI\u2019s ChatGPT<\/a> all pitched malicious campaign repositories to developers without being shown a link, he wrote, adding that \u201ca playbook built to deceive people now deceives the agents acting on their behalf.\u201d<\/p>\n<p>The 7,600 or so malicious GitHub repositories confirmed by Island were created by about 6,600 profiles, with some 1,400 of those tied to AI tools, agents, or workflows, and more than 800 posing as Skills or MCP servers that reach from tools in such environments as Gmail, WhatsApp integrations, Databricks, Jenkins, and Docker, according to Zaytsev.<\/p>\n<p>As of this month, there have been more than 14 million downloads from about 200 of the campaign\u2019s repositories. Tied to the campaign were thousands of other repositories that embedded malicious ZIP files directly in the project, where downloads aren\u2019t publicly counted.<\/p>\n<h3>Fast-Scaling Campaign<\/h3>\n<p>That said, the AI-focused part of the campaign ramped up quickly, he wrote. According to GitHub creation dates, that started to build in March and peaked in April, when almost 300 such AI-related repositories were created.<\/p>\n<p>\u201cThe repositories were designed to meet demand already forming around AI capabilities, borrowing the names and workflows of familiar consumer and enterprise tools,\u201d he wrote. \u201cThat familiarity gave the malicious ZIP files a credible reason to be downloaded, while the README guided users or agents from what appeared to be routine setup into the SmartLoader attack chain.\u201d<\/p>\n<p>According to Island, the fraudulent repositories are made to resemble real projects, and at times are simply copies of them.<\/p>\n<p>If a fake repository is chosen, the \u201cDownload Latest Release\u201d button sends the developer to a malicious ZIP archive inside, which includes instructions for downloading, extracting, and running the application. This kicks off the attack chain, starting with a heavily obfuscated 300 KB Lua payload that is disguised as a text, icon, license, or data file.<\/p>\n<h3>Next Comes SmartLoader, StealC<\/h3>\n<p>From there, SmartLoader is dropped, which then deploys StealC, which can steal a range of information, including browser passwords and extension data, cookies, active sessions, screenshots, host information, and email and remote-access credentials.<\/p>\n<p>\u201cThe malware chain itself is familiar,\u201d Zaytsev wrote. \u201cWhat changes is the route that leads to execution.\u201d<\/p>\n<p>That route is exploiting the autonomous capabilities of AI agents. The agent doesn\u2019t need to be given a malicious link. Instead, it can discover a FakeGit repository itself, treat the README file as legitimate, and then send the bad actor\u2019s instructions to the user. This is AgentBaiting, and the FakeGit operators built the AI-based lures around it.<\/p>\n<h3>Top Coding Agents Fall for It<\/h3>\n<p>The Island researchers tested it using Anthropic\u2019s Claude Code developer assistant, watching the model search the web, follow results through an MCP marketplace and GitHub, and open two repositories. One was benign, the other a FakeGit repository in the malicious skills category. Claude Code recommended the benign repository, but saw the malicious one as a legitimate alternative.<\/p>\n<p>In other tries, the AI model detected the malicious content in the fraudulent repository and didn\u2019t recommend it.<\/p>\n<p>\u201cThat variability is the point: it independently discovered a campaign repository and, in one run, turned its attacker-written README into actionable installation guidance,\u201d he wrote. \u201cAt the scale of this campaign, even an occasional miss creates a path to malware execution.\u201d<\/p>\n<p>Tests on both Gemini and ChatGPT showed similar results.<\/p>\n<h3>No Breach Needed<\/h3>\n<p>Zaytsev stressed that the FakeGit operators didn\u2019t have to breach anything in the campaign.<\/p>\n<p>They \u201cpublished convincing repositories, borrowed real developers\u2019 identities, spread its listings across public registries, and let discovery do the rest,\u201d he wrote. \u201cWith AgentBaiting, that discovery no longer requires a person at all: an agent searching for a Skill or MCP server can find the lure, read the attacker\u2019s README, and carry its instructions forward.\u201d<\/p>\n<p>Organizations need defenses to interrupt the chain before it executes. That includes evaluating each new capability in an isolated environment first, verifying the publisher and the project, and keeping an eye on the paths AI agents go down.<\/p>\n<p>Island researchers aren\u2019t the only ones to detect such activity. Straiker AI in February reported a campaign <a href=\"https:\/\/www.straiker.ai\/blog\/smartloader-clones-oura-ring-mcp-to-deploy-supply-chain-attack\" target=\"_blank\" rel=\"noopener\">using fake GitHub accounts<\/a> to exploit the MCP ecosystem and a cloned Oura Ring server to sneak into developer environments with info-stealing malware. A month later, Derp.ca <a href=\"https:\/\/www.derp.ca\/research\/fakegit-luajit-github-campaign\/\" target=\"_blank\" rel=\"noopener\">wrote about FakeGit<\/a> distributing Lua-based malware through GitHub.<\/p>\n<p><a href=\"https:\/\/devops.com\/fakegit-targets-ai-coding-agents-with-malicious-github-repos\/\" target=\"_blank\" class=\"feedzy-rss-link-icon\">Read More<\/a><\/p>\n<p>\u200b<\/p>","protected":false},"excerpt":{"rendered":"<p>Threat actors continue to find new ways to incorporate AI into schemes aimed at luring developers into downloading malware from [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":4642,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"site-sidebar-layout":"default","site-content-layout":"","ast-site-content-layout":"default","site-content-style":"default","site-sidebar-style":"default","ast-global-header-display":"","ast-banner-title-visibility":"","ast-main-header-display":"","ast-hfb-above-header-display":"","ast-hfb-below-header-display":"","ast-hfb-mobile-header-display":"","site-post-title":"","ast-breadcrumbs-content":"","ast-featured-img":"","footer-sml-layout":"","ast-disable-related-posts":"","theme-transparent-header-meta":"","adv-header-id-meta":"","stick-header-meta":"","header-above-stick-meta":"","header-main-stick-meta":"","header-below-stick-meta":"","astra-migrate-meta-layouts":"default","ast-page-background-enabled":"default","ast-page-background-meta":{"desktop":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"ast-content-background-meta":{"desktop":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"footnotes":""},"categories":[5],"tags":[],"class_list":["post-4641","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-devops"],"_links":{"self":[{"href":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/wp-json\/wp\/v2\/posts\/4641","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/wp-json\/wp\/v2\/comments?post=4641"}],"version-history":[{"count":0,"href":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/wp-json\/wp\/v2\/posts\/4641\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/wp-json\/wp\/v2\/media\/4642"}],"wp:attachment":[{"href":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/wp-json\/wp\/v2\/media?parent=4641"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/wp-json\/wp\/v2\/categories?post=4641"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/wp-json\/wp\/v2\/tags?post=4641"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}