#agentbaiting
AgentBaiting: How 800+ Fake AI Skills and MCP Servers Delivered Malware www.island.io/blog/agentba...
AgentBaiting: How Fake AI Skills Deliver Malware at Scale
Island researchers uncover 7,600+ malicious GitHub repos, over 800 posing as AI Skills and MCP servers, that trick AI agents into recommending malware.
www.island.io
July 26, 2026 at 6:49 PM
-App Store down in Russia, likely banned
-Canada signs new UN cybercrime convention
-New White House EO covers software supply chains
-NSO owner had diplomatic passport
-New AgentBaiting campaign
-PAN OS bug used to push Qilin ransomware
-DevMan (Funky Mantis) profile
July 22, 2026 at 8:14 AM
AgentBaiting Campaign Uses 800 Fake AI Skills and MCP Servers to Deliver SmartLoader Malware
AgentBaiting Campaign Uses 800 Fake AI Skills and MCP Servers to Deliver SmartLoader Malware
Malware operators are increasingly using tools built to extend artificial intelligence as a delivery route. A newly documented campaign called AgentBaiting uses fraudulent AI Skills and Model Context Protocol, or MCP, servers to distribute SmartLoader malware through trusted-looking GitHub projects and public capability catalogs. The operation turns a routine search for an AI integration into a malware risk. Victims can be steered to ZIP archives presented as useful installers, then encouraged to extract and run files that have no connection to the advertised tool. Island researchers identified the campaign while tracking the wider FakeGit operation. Island said in a report shared with Cyber Security News (CSN) that it found about 7,600 malicious repositories created by roughly 6,600 profiles, including more than 800 posing as AI Skills or MCP servers. The campaign’s reach makes it more than a typical developer scam. The AI-focused wave built through March and peaked in April 2026, while malicious projects appeared more than 600 times across public AI registries and catalogs. The scale of the FakeGit operation (Source – Island.io) Researchers also measured more than 14 million downloads from release assets in approximately 200 campaign repositories. AgentBaiting Campaign Uses 800 Fake AI Skills and MCP Servers FakeGit builds credibility through copied projects, lookalike accounts, convincing documentation, and modest engagement numbers. One lure copied the name and positioning of a popular Claude Skills collection, then offered a confirmed SmartLoader ZIP archive as the download. The approach echoes earlier  fake GitHub malware delivery  activity that exploited familiar development workflows to gain trust. The fake Mann1988 – awesome-claude-skills repository imitates the original ComposioHQ – awesome-claude-skills project (Source – Island.io) The lures target both personal and business tasks, including email, messaging, analytics, build systems, cloud services, and developer tools. Their names make downloads appear relevant to daily work instead of suspicious. Island found that 62 malicious repositories were positioned for enterprise or developer-internal use, while nearly two-thirds of MCP lures claimed to connect cloud services, databases, or APIs. A repository named  45d5r/databricks-mcp-server  shows how the infection begins. Its documentation advertises an enterprise integration and provides a download button, but the linked archive contains a command launcher, a renamed LuaJIT-style runtime, and an obfuscated Lua program disguised as a text file. Running the launcher activates the concealed payload rather than installing an MCP server. Related variants can hide their console windows, locate their command server through a value stored in a Polygon smart contract, create scheduled-task persistence, and retrieve encrypted stages from GitHub. The FakeGit attack chain (Source – Island.io) The stages eventually inject StealC into another process, continuing the credential-theft threat covered in reporting on the  StealC infrastructure disruption . AI Discovery Becomes Risk AgentBaiting changes the threat because an AI agent can discover the malicious project without a victim receiving a direct link. During testing, researchers found that Claude Code, Gemini, and ChatGPT could independently surface campaign repositories when asked to find a Skill or MCP server. The results varied, but still exposed a dangerous gap. One tested agent recommended a benign option while also repeating malicious installation instructions as an alternative. In another test, Gemini returned a malicious Walmart MCP repository as its first result, while ChatGPT listed the same repository among public options and highlighted it as a starting point. Public registries can further expand that exposure. Island found more than 600 campaign listings across LobeHub, Glama, MCP.so, and MCP Market, with some reproducing attacker-written documentation and download instructions. That gives malicious repositories another layer of credibility, particularly as  MCP server security concerns  grow around AI integrations that can access business resources. Organizations should rely on a curated and reviewed catalog for Skills, MCP servers, and agent plug-ins instead of unrestricted discovery. Campaign-linked Skills and MCP servers (Source – Island.io) New capabilities should be tested in an isolated environment without browser sessions, cloud credentials, SSH keys, or production data. A supposed AI capability distributed as a Windows ZIP containing a launcher and hidden payload should be rejected. Teams should verify publishers as carefully as projects, since star counts, copied profiles, and registry listings do not establish legitimacy. They should monitor downloads, Git clones, shell commands, and changes to MCP or Skill configurations initiated by agents. Maintaining an inventory of each capability’s repository, commit, version, and package hash can speed investigation. If SmartLoader execution is suspected, security teams should isolate the endpoint and revoke active browser sessions, OAuth grants, API tokens, cloud credentials, and developer credentials. Password resets alone may not be enough because StealC can steal live sessions, browser data, email and remote-access credentials, screenshots, and host details. Indicators of Compromise (IoCs):- Type Indicator Description GitHub repository hfgwyge/yu-ai-agent Fake AI agent repository File name yu-ai-agent-1.0-beta.3.zip SmartLoader package SHA-256 216a2c99fd42c00f9323d8b16dd19f622f7f4778b2b1d7cf07a3de5621f2 Package hash GitHub repository Mann1988/awesome-claude-skills Fake Claude Skills repository File name awesome-skills-claude-3.3.zip SmartLoader package SHA-256 91e5dbfaf45edf25fbc2168f92083e05dfa427afa7633e991392e33cc743 Package hash GitHub repository h4vzz/awesome-ai-agent-skills Fake AI agent Skills repository File name agentaiawesomeskills2.0.zip SmartLoader package SHA-256 498fe8fb806cd0e6685f97fc7d74de769dae5a28cdc821557b7585ad5ad Package hash GitHub repository StanLeyJ03/mcp-for-security Fake security MCP repository File name for-security-mcp-3.3.zip SmartLoader package SHA-256 62744baa8077bb8be237647fd78e3bea2ca0932bf4be3d5618600f971185 Package hash GitHub repository xbim08/awesome-claude-code-plugins Fake Claude Code plug-ins repository File name pluginsclaudeawesomecode2.4.zip SmartLoader package SHA-256 1da8df487d30b988f3c350c065206726aaa13f079a07151cd42ab557999 Package hash GitHub repository DomingosNgongo/walmart-mcp Fake Walmart MCP repository File name mcp-walmart-2.2.zip SmartLoader package SHA-256 c15693106682f2ddb26649cab6e1962a64537627cde4c5d3c79d5a0be8c7 Package hash GitHub repository 45d5r/databricks-mcp-server Fake Databricks MCP repository File name serverdatabricksmcp1.6.zip SmartLoader package SHA-256 66afc7d87d10dbe392898c4e5c613e0442fabb396415c2bef3a5ef2ac758 Package hash GitHub repository MauManto/jenkins-mcp-server Fake Jenkins MCP repository File name mcp-server-jenkins-3.2.zip SmartLoader package SHA-256 a33f40cab1ab7f971d3464af3e7595918107332b9e83342007571842b9e Package hash GitHub repository waynestimulative605/docker-mcp-gateway Fake Docker MCP gateway repository File name gateway-docker-mcp-v1.6-alpha.5.zip SmartLoader package SHA-256 3c858facbad66f5479e2c4add171421dc1b6488b36f33e7cff073aba585 Package hash GitHub repository lucaducapuca/alibabacloud-bigdata-skills Fake Alibaba Cloud Skills repository File name alibabacloud-skills-bigdata-v1.7.zip SmartLoader package SHA-256 fc1278f419e611bf40ca414099bfd9ad98a31ffb054371e8cb65a84849b Package hash Note:   IP addresses and domains are intentionally defanged (e.g.,  [.] ) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM . Strengthen Your SOC by Accelerating Threat Detection & Rapid Investigations. ->  Integrate ANY.RUN With Your SOC  Now . The post AgentBaiting Campaign Uses 800 Fake AI Skills and MCP Servers to Deliver SmartLoader Malware appeared first on Cyber Security News .
cybersecuritynews.com
July 21, 2026 at 12:42 PM
A novel AI-themed malware distribution campaign (AgentBaiting) has emerged alongside a sustained wave of data breaches and ransomware attacks targeting retail organizations across Europe and North America. rhisac.org/threat-intel...

#cybersecurity
#threatintelligence
#AI
#agentbaiting
New AgentBaiting Campaign Delivers SmartLoader Via Fake AI Skills and MCP Servers - RH-ISAC
On 21 July 2026, Cyber Security News reported a novel AI-themed malware distribution campaign (AgentBaiting) has emerged alongside a sustained wave of data
rhisac.org
July 21, 2026 at 2:17 PM
Gefälschte KI-Tools machen ChatGPT, Claude und Gemini zu unfreiwilligen Helfern von Cyberkriminellen

#AgentBaiting #ChatGPT #ClaudeCode #Cybersecurity #Cybersicherheit #FakeGit #GitHub #Google-Gemini island #KIAgent #KIAssistent #KISkill #SupplyChain island_io

netzpalaver.de/2026/...
July 22, 2026 at 12:17 PM
AgentBaitingマルウェアキャンペーン、AI用MCPサーバーを標的に

新たな脅威ベクター「AgentBaiting」の出現 人工知能ツールの人気急上昇により、スキルディレクトリは初期アクセスの標的として格好の場所になっています。攻撃者はModel Context Protocol(MCP)サーバーのリポジトリを狙い、悪意あるペイロードを配布しています。特筆すべきは、
AgentBaitingマルウェアキャンペーン、AI用MCPサーバーを標的に
新たな脅威ベクター「AgentBaiting」の出現 人工知能ツールの人気急上昇により、スキルディレクトリは初期アクセスの標的として格好の場所になっています。攻撃者はModel Context Protocol(MCP)サーバーのリポジトリを狙い、悪意あるペイロードを配布しています。特筆すべきは、
blackhatnews.tokyo
July 23, 2026 at 2:29 PM
--RansomHouse claims attack on Japanese food giant Nichirei,
--Credential stuffing attack compromised Chick-fil-A customer accounts
--Fake GitHub AI tools spread malware through 'agentbaiting' campaign,
--Maine telecom cyberattack disrupted internet service across 23 towns, 5/6
July 22, 2026 at 1:21 PM
Agents are now a second workforce, often beyond IT approval. Security teams lack full inventory, attribution, and governance across endpoints, browsers, networks, and AI gateways. #AgentOps #MCP #Governance
Agents Work Everywhere Now. Governance Has to See Everywhere Too.
Enterprise teams are discovering that agentic AI has created a second workforce with little to no onboarding, leaving major gaps in inventory, identity, attribution, and governance. The article argues that organizations need real-time, end-to-end controls for agents across endpoints, browsers, networks, and AI gateways to manage risk, cost, and compliance. #Island #AgentBaiting #StealC #MCP
www.hendryadrian.com
August 10, 2026 at 6:15 PM
AI指示でマルウェア感染?AIを騙す「AgentBaiting」が登場。

・偽MCP等7600件(1400万DL)
・Claude/ChatGPTが偽コード推奨
・攻撃標的が「人間→AI」へシフト

AI選定コードの鵜呑みは厳禁。開発自動化時代の新たな構造的リスクです。

#セキュリティ #AIエージェント
FakeGitキャンペーン、7,600のGitHubリポジトリでSmartLoaderを拡散-AIエージェントを餌食にする新手口「AgentBaiting」の脅威|セキュリティニュースのセキュリティ対策Lab
エンタープライズブラウザ企業のIslandは2026年7月21日、GitHub上に約7,600もの悪意あるリポジトリを設置し、SmartLoaderおよびStealCといったマルウェアを拡散する大規模キャンペーンFakeGitの調査結果を公表しました。これらのリポジトリの累計ダウンロード数は1,400万回を超えています。特に注目すべきは、7,600のうち800以上がAIのスキルやMCP(Model Context Protocol)サーバーを装っており、AIエージェントに自ら悪意あるリポジトリを発見・推奨させることを狙った、AgentBaiting(エージェント・ベイティング)と呼ばれる新しい
rocket-boys.co.jp
July 28, 2026 at 1:28 AM
FakeGit is using 7,600 GitHub repos and 14M download events to spread SmartLoader and StealC, with fake AI tools and MCP servers luring developers and AI agents. #FakeGit #SmartLoader #StealC
FakeGit campaign uses 7,600 GitHub repos to push SmartLoader malware
A large-scale campaign called FakeGit is using 7,600 malicious GitHub repositories to distribute SmartLoader and StealC, with more than 14 million recorded download events across public release assets. Researchers say the operation uses “agentbaiting” to lure AI agents and developers into trusting fake AI tools, while its roots appear tied to an earlier Lumma Stealer campaign linked to Water Kurita. #FakeGit #SmartLoader #StealC #LummaStealer #WaterKurita
www.hendryadrian.com
July 22, 2026 at 3:45 AM
🚨 AgentBaiting abuses fake AI tools and MCP servers to spread SmartLoader and StealC malware, making AI supply chain security more critical than ever.

🌐 threatexposure.io/blog/attack-...

#AttackSurfaceManagement #AISecurity #SupplyChainSecurity #StealC #SmartLoader

Try it for FREE. 🆓
Supply Chain Cybersecurity | Online Reports - Threatexposure.io
Reduce cyber supply chain risk with full reports for third-party risk management, continuous vendor monitoring, security ratings, and threat intelligence.
threatexposure.io
July 24, 2026 at 7:17 AM
AgentBaiting : quand c'est votre agent IA qui va chercher le MCP piégé et vous le recommande
blog.gioria.org/fr/ai-securi...
#AIsecurity
August 13, 2026 at 10:42 AM
SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 107

Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter UAC-0145 Primary Compromise Vectors as of July 2026   SleeperGem: Compromised git…
#hackernews #news
SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 107
Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter UAC-0145 Primary Compromise Vectors as of July 2026   SleeperGem: Compromised git_credential_manager, Dendreo, and fastlane RubyGems Drop a Persistent Backdoor   AgentBaiting: How 800+ Fake AI Skills and MCP Servers Delivered Malware   Chaos ransomware’s msaRAT: Living […]
securityaffairs.com
July 27, 2026 at 9:22 AM
AgentBaiting: When AI Goes Rogue and Builds Malware’s www.wangdoo.com/agentbaiting... @hope.net
AgentBaiting: When AI Goes Rogue and Builds Malware's
AgentBaiting exposes how hackers push AI coding assistants into generating malware — and what developers must watch for.
www.wangdoo.com
July 22, 2026 at 8:54 AM
AgentBaiting: Wie gefälschte KI-Skills und MCP-Server zur neuen Angriffsfläche wurden - Sicherheitsforscher haben eine groß angelegte Kampagne aufgedeckt, bei der mehrere Tausend GitHub-Repositories als KI-Skills oder MCP-Server getarnt wurden,....
www.all-about-security.de/agentbaiting...
Gefälschte KI-Skills schleusen Malware ein: Risiken für Entwickler
Informieren Sie sich über die Gefahren gefälschter KI-Skills und deren Rolle bei der Verbreitung von Schadsoftware auf GitHub.
www.all-about-security.de
July 22, 2026 at 6:10 AM
AgentBaiting: How Over 800 Fake AI Skills and MCP Servers Delivered Malware https://packetstorm.news/news/view/42448 #news
July 21, 2026 at 8:32 PM
AgentBaiting campaign uses fake AI skills to spread malware via GitHub. #CyberSecurity #AI #Malware #GitHub #AgentBaiting #SmartLoader thedailytechfeed.com/agentbaiting...
July 21, 2026 at 12:41 PM
Ask Gemini for a "Walmart MCP" and the first result is malware. try it.
AgentBaiting: How Fake AI Skills Deliver Malware at Scale
Island researchers uncover 7,600+ malicious GitHub repos, over 800 posing as AI Skills and MCP servers, that trick AI agents into recommending malware.
www.island.io
July 21, 2026 at 10:28 PM
AgentBaiting Campaign Uses 800 Fake AI Skills and MCP Servers to Deliver SmartLoader Malware

cybersecuritynews.com/agentbaiting...

#Cybersecurity #ThreatIntel #Vulnerability
AgentBaiting Campaign Uses 800 Fake AI Skills and MCP Servers to Deliver SmartLoader Malware
AgentBaiting spreads SmartLoader through fake AI Skills, MCP servers, and GitHub projects, targeting developers with malware.
cybersecuritynews.com
July 21, 2026 at 1:32 PM