A large-scale operation dubbed ‘FakeGit’ has been discovered, where malicious actors have created over 7,600 fake GitHub repositories to push SmartLoader and StealC malware. The campaign’s goal is to manipulate AI agents into downloading and executing the malware, making it a sophisticated example of **agentbaiting**.
These repositories are designed to mimic legitimate projects, including consumer and enterprise tools, with convincing documentation and fabricated credentials. Once downloaded, the malware triggers SmartLoader, which establishes persistence through scheduled tasks and retrieves its command-and-control (C2) address from a Polygon smart contract.
The campaign’s impact is significant, with over 14 million downloads recorded across 211 GitFake repositories. Researchers at Island have identified an emerging technique in this operation, where malicious repositories are created to increase their visibility to AI agents, making it easier for them to be discovered and used.
This highlights the need for organizations to maintain approved catalogs of skills and MCP servers, test new capabilities in isolated environments, and verify publishers and repositories independently. The FakeGit campaign is considered a continuation of an older operation attributed to a threat actor tracked as ‘Water Kurita’ by Trend Micro researchers.
The AI focus was introduced in March and peaked in April, with the creation of 300 GitHub repositories linked to AI tools. Researchers found that FakeGit grew to more than 1,400 repositories related to AI tools, agents, and workflows, all linking to SmartLoader or StealC malware downloads.
In a controlled testing environment, Claude Code was able to clone malicious repositories and download the malicious files, but the agent subsequently detected suspicious indicators and stopped before execution. The tests were not designed to establish a detection rate, so they cannot provide conclusive results on whether coding agents can consistently recognize the danger during the execution stage.
Concerning the broader impact of the campaign, Island reports that GitHub’s public download counters for 335 unique Release assets across 211 GitFake repositories recorded 14,084,688 cumulative download events. Oleg Zaytsev, Lead Security Researcher at Island, clarified that this figure included repeated requests and automated activity, so it should not be interpreted as infections.
**What is the FakeGit Campaign?**
The FakeGit campaign is a large-scale operation where malicious actors have created over 7,600 fake GitHub repositories to push SmartLoader and StealC malware. The goal of this campaign is to manipulate AI agents into downloading and executing the malware.
**How Does the Malware Work?**
Once downloaded, the malware triggers SmartLoader, which establishes persistence through scheduled tasks and retrieves its command-and-control (C2) address from a Polygon smart contract.
**Impact of the Campaign**
The campaign’s impact is significant, with over 14 million downloads recorded across 211 GitFake repositories. Researchers at Island have identified an emerging technique in this operation, where malicious repositories are created to increase their visibility to AI agents, making it easier for them to be discovered and used.
**Recommendations for Organizations**
This highlights the need for organizations to maintain approved catalogs of skills and MCP servers, test new capabilities in isolated environments, and verify publishers and repositories independently. The FakeGit campaign is considered a continuation of an older operation attributed to a threat actor tracked as ‘Water Kurita’ by Trend Micro researchers.
**Conclusion**
The FakeGit campaign is a sophisticated example of **agentbaiting**, where malicious actors are manipulating AI agents into downloading and executing malware. The impact of this campaign is significant, with over 14 million downloads recorded across 211 GitFake repositories. Organizations must take steps to maintain approved catalogs of skills and MCP servers, test new capabilities in isolated environments, and verify publishers and repositories independently.
**Recommendations for Developers**
Developers should be cautious when using AI agents and ensure that they are not being manipulated into downloading and executing malware. This can be achieved by maintaining approved catalogs of skills and MCP servers, testing new capabilities in isolated environments, and verifying publishers and repositories independently.
Source: Original article