Researchers uncovered nearly 7,600 malicious GitHub repositories in the FakeGit campaign, including more than 800 fake AI Skills and MCP servers used to distribute SmartLoader and later StealC. The new AgentBaiting technique can trick AI agents like Claude Code, Gemini, and ChatGPT into discovering and following malicious repositories on their own. #FakeGit #SmartLoader #StealC #AgentBaiting #AnthropicClaudeCode #GoogleGemini #OpenAIChatGPT
Keypoints
- FakeGit used fake GitHub repositories and lookalike profiles to spread SmartLoader.
- More than 800 repositories impersonated AI Skills or MCP servers.
- SmartLoader was used to install StealC for data theft.
- AgentBaiting can lure AI agents into finding malicious repositories without human help.
- Public registries like LobeHub and Glama helped fake listings appear legitimate.
Read More: https://thehackernews.com/2026/07/fakegit-campaign-uses-7600-github.html