#FakeGit
Gemini i ChatGPT niezależnie poleciły użytkownikom ten sam złośliwy konektor z kampanii FakeGit. Asystenci nie zostali przejęci — oszukano sygnały zaufania, którymi się kierują.
FakeGit: Gemini i ChatGPT poleciły to samo złośliwe repozytorium. Asystentów nie trzeba było łamać — wystarczyło ich oszukać
Gemini i ChatGPT niezależnie poleciły użytkownikom ten sam złośliwy konektor z kampanii FakeGit. Asystenci nie zostali przejęci — oszukano sygnały zaufania, którymi się kierują.
aisight.pl
September 23, 2026 at 9:50 AM
FakeGit campaign uses 7,600 GitHub repos to push SmartLoader malware
FakeGit campaign uses 7,600 GitHub repos to push SmartLoader malware
A large-scale operation dubbed 'FakeGit' is pushing SmartLoader and StealC malware through 7,600 malicious GitHub repositories that accumulated more than 14 million downloads. [...]
www.bleepingcomputer.com
July 21, 2026 at 11:22 PM
A large-scale operation dubbed 'FakeGit' is pushing SmartLoader and StealC malware through 7,600 malicious GitHub repositories that accumulated more than 14 million downloads.
FakeGit campaign uses 7,600 GitHub repos to push SmartLoader malware
A large-scale operation dubbed 'FakeGit' is pushing SmartLoader and StealC malware through 7,600 malicious GitHub repositories that accumulated more than 14 million downloads.
www.bleepingcomputer.com
July 21, 2026 at 10:34 PM
Gemini et ChatGPT ont recommandé, chacun de leur côté, le même dépôt GitHub piégé. Avec les instructions d'installation en prime.

Le dépôt s'appelle walmart-mcp. Il fait partie de FakeGit, une campagne documentée par Island en juillet : environ 7 600 faux… https://www.lefilia.fr/article/6213036
September 25, 2026 at 12:02 PM
Gemini et ChatGPT ont recommandé, chacun de leur côté, le même dépôt GitHub piégé. Avec les instructions d'installation fournies gentiment à l'utilisateur.

La campagne s'appelle FakeGit, documentée par Island en juillet : environ 7 600 faux dépôts, 6 600… https://www.lefilia.fr/article/6213036
September 24, 2026 at 10:01 AM
FakeGit is using 7,600 GitHub repos and 14M download events to spread SmartLoader and StealC, with fake AI tools and MCP servers luring developers and AI agents. #FakeGit #SmartLoader #StealC
FakeGit campaign uses 7,600 GitHub repos to push SmartLoader malware
A large-scale campaign called FakeGit is using 7,600 malicious GitHub repositories to distribute SmartLoader and StealC, with more than 14 million recorded download events across public release assets. Researchers say the operation uses “agentbaiting” to lure AI agents and developers into trusting fake AI tools, while its roots appear tied to an earlier Lumma Stealer campaign linked to Water Kurita. #FakeGit #SmartLoader #StealC #LummaStealer #WaterKurita
www.hendryadrian.com
July 22, 2026 at 3:45 AM
FakeGit: 14 milioni di download, gli hacker avvelenano GitHub con falsi server MCP e skill AI

📌 Link all'articolo : www.redhotcyber.com/post/fakegit...

A cura di Luigi Zullo

#redhotcyber #news #cybersecurity #sviluppoSoftware #malware #repository #github #hacking #sviluppatori
July 24, 2026 at 11:52 AM
FakeGit: 800 AI Repositories on GitHub Turn Agents Into Malware Vectors
FakeGit: 800 AI Repositories on GitHub Turn Agents Into Malware Vectors
Island uncovered 800 malicious GitHub repositories masquerading as AI Skills and MCP servers. AI agents autonomously recommended the malware to users.
deafnews.it
July 23, 2026 at 12:06 PM
Lua-based FakeGit trojan loader masquerading as an “n8n CyberSecurity Workflows” package Alert: GitHub Repo n8n-CyberSecurity-Workflows Is a FakeGit Lua Loader, Full Technical Breakdown Continu...

#technology #cybersecurity #malware-analysis #github #n8n

Origin | Interest | Match
Awakari App
awakari.com
April 21, 2026 at 3:34 PM
FakeGit uses trojanized GitHub Skills and MCP servers to deliver SmartLoader malware and StealC, with AI agents tricked into discovering and executing attacks automatically.
Save What Matters
Curate Feeds | Make Collections | Customize Email Briefs
briefly.co
July 20, 2026 at 7:55 PM
FakeGit campaign uses 7,600 GitHub repos to push SmartLoader malware

A large-scale operation dubbed 'FakeGit' is pushing SmartLoader and StealC malware through 7,600 malicious GitHub repositories that accumulated more than 14 million downloads. [...]
#hackernews #news
FakeGit campaign uses 7,600 GitHub repos to push SmartLoader malware
A large-scale operation dubbed 'FakeGit' is pushing SmartLoader and StealC malware through 7,600 malicious GitHub repositories that accumulated more than 14 million downloads. [...]
www.bleepingcomputer.com
July 22, 2026 at 9:16 PM
July 23, 2026 at 11:24 PM
Gefälschte KI-Tools machen ChatGPT, Claude und Gemini zu unfreiwilligen Helfern von Cyberkriminellen

#AgentBaiting #ChatGPT #ClaudeCode #Cybersecurity #Cybersicherheit #FakeGit #GitHub #Google-Gemini island #KIAgent #KIAssistent #KISkill #SupplyChain island_io

netzpalaver.de/2026/...
July 22, 2026 at 12:17 PM
AI agents can now autonomously find and execute malicious repos without any human click. 7,600 fake GitHub repos are targeting MCP developers, with 14M+ downloads logged. This is a new attack surface. https://thehackernews.com/2026/07/fakegit-campaign-uses-7600-github.html
July 21, 2026 at 6:04 AM
Fake AI Skills and MCP servers trick Claude, Gemini and ChatGPT into recommending malware installs. https://intel.threadlinqs.com/threat/TL-2026-1595 #ThreatIntel #SmartLoader #Stealc #Lumma
July 21, 2026 at 10:57 PM
AIエージェントを騙して悪意あるGitHubリポジトリを推薦させる手口

Islandによると、約7,600件の悪意あるGitHubリポジトリが発見され、そのうち800件以上がAI SkillやModel Context Protocol(MCP)サーバーを装っていました。この動きは2026年4月にピークを迎えています。 FakeGit作戦の規模(出典: Island)...
AIエージェントを騙して悪意あるGitHubリポジトリを推薦させる手口
Islandによると、約7,600件の悪意あるGitHubリポジトリが発見され、そのうち800件以上がAI SkillやModel Context Protocol(MCP)サーバーを装っていました。この動きは2026年4月にピークを迎えています。 FakeGit作戦の規模(出典: Island)
blackhatnews.tokyo
July 21, 2026 at 2:40 PM
AI agents tricked into recommending malicious GitHub repositories

Roughly 7,600 malicious GitHub repositories were uncovered, more than 800 of them posing as AI Skills or Model Context Protocol (MCP) servers, in a wave that peaked in April 2026, according to Island. The scale of …
#hackernews #news
AI agents tricked into recommending malicious GitHub repositories
Roughly 7,600 malicious GitHub repositories were uncovered, more than 800 of them posing as AI Skills or Model Context Protocol (MCP) servers, in a wave that peaked in April 2026, according to Island. The scale of the FakeGit operation (Source: Island) The fake repositories are tied to about 6,600 accounts, around 1,400 of which were built around AI tools, agents, or workflows, and span individual and enterprise use, ranging from Gmail and WhatsApp integrations to …
www.helpnetsecurity.com
July 22, 2026 at 2:14 PM
AI指示でマルウェア感染?AIを騙す「AgentBaiting」が登場。

・偽MCP等7600件(1400万DL)
・Claude/ChatGPTが偽コード推奨
・攻撃標的が「人間→AI」へシフト

AI選定コードの鵜呑みは厳禁。開発自動化時代の新たな構造的リスクです。

#セキュリティ #AIエージェント
FakeGitキャンペーン、7,600のGitHubリポジトリでSmartLoaderを拡散-AIエージェントを餌食にする新手口「AgentBaiting」の脅威|セキュリティニュースのセキュリティ対策Lab
エンタープライズブラウザ企業のIslandは2026年7月21日、GitHub上に約7,600もの悪意あるリポジトリを設置し、SmartLoaderおよびStealCといったマルウェアを拡散する大規模キャンペーンFakeGitの調査結果を公表しました。これらのリポジトリの累計ダウンロード数は1,400万回を超えています。特に注目すべきは、7,600のうち800以上がAIのスキルやMCP(Model Context Protocol)サーバーを装っており、AIエージェントに自ら悪意あるリポジトリを発見・推奨させることを狙った、AgentBaiting(エージェント・ベイティング)と呼ばれる新しい
rocket-boys.co.jp
July 28, 2026 at 1:28 AM
FakeGit Campaign Uses 7,600 GitHub Repositories to Spread SmartLoader Malware
FakeGit Campaign Uses 7,600 GitHub Repositories to Spread SmartLoader Malware
thehackernews.com
August 1, 2026 at 10:30 AM
FakeGit campaign uses 7,600 GitHub repos to push SmartLoader malware
FakeGit campaign uses 7,600 GitHub repos to push SmartLoader malware
A large-scale operation dubbed 'FakeGit' is pushing SmartLoader and StealC malware through 7,600 malicious GitHub repositories that accumulated more than 14 million downloads.
www.bleepingcomputer.com
July 29, 2026 at 1:42 AM
GitHub悪用の「FakeGit」、AIエージェントもだます新手口 マルウェア1400万回ダウンロード
マイナビニュース

Islandは2026年7月20日(米国時間)、GitHub上でAIツールやMCPサーバーを装った偽リポジトリを使い、マルウェアを配布する大規模キャンペーン「FakeGit」の ...
news.mynavi.jp/techplus/art...
GitHub悪用の「FakeGit」、AIエージェントもだます新手口 マルウェア1400万回ダウンロード
Islandは2026年7月20日(米国時間)、GitHub上でAIツールやMCPサーバーを装った偽リポジトリを使い、マルウェアを配布する大規模キャンペーン「FakeGit」の調査結果を公開した。攻撃ではAIエージェントが偽リポジトリを正規の情報として推薦するケースも確認され、マルウェアを含むアーカイブは1400万回以上ダウンロードされたという。
news.mynavi.jp
July 24, 2026 at 12:14 PM