
Fake GitHub Repos and Trojan Apps Steal Data
Researchers described two active social-engineering-driven malware campaigns: one uses trojanized “popular” remote-user apps (e.g., Zoom/WebEx lookalikes) to…
Researchers found thousands of malicious GitHub repositories designed to look like real developer tools, including hundreds posing as AI “Skills” and Model Context Protocol (MCP) servers. In a technique dubbed “AgentBaiting,” attackers rely on AI assistants to discover these repos and pass the installation steps to users, leading them to download and run malware that steals credentials and active sessions.
Researchers identified around 7,600 malicious GitHub repositories, including more than 800 posing as AI Skills or Model Context Protocol (MCP) servers, tied to roughly 6,600 accounts. The campaign, dubbed FakeGit, relied on copied projects, lookalike developer profiles, and convincing READMEs to make the repositories look like legitimate open-source tools. Victims who followed the install steps were led to download ZIP or EXE files that delivered SmartLoader, malware that establishes persistence and then installs StealC to steal credentials and active sessions.
What sets this campaign apart is a technique called AgentBaiting. Instead of relying solely on a human clicking a malicious link, attackers count on AI assistants to find the malicious repos during a routine search for a tool or capability. In testing, AI assistants surfaced these campaign repositories without ever being shown a link, and in one case an assistant recommended a legitimate option while also passing along the malicious repository's installation steps in the same response, including instructions to download an executable and click past a Windows security warning.
The attack exploits trust in two layers at once: trust in GitHub as a platform for open-source tools, and trust in AI assistants as a reliable filter for finding those tools. Public AI registries that listed or mirrored repository READMEs added a third layer, carrying malicious download links onto other platforms under those registries' own credibility. Because the AI agent, not the person, does the searching, the agent effectively becomes the target, standing in for the user it works for.
Organizations can reduce exposure by treating AI assistant recommendations as a starting point rather than a trusted source, and by verifying the publisher and project before installing anything. Building a curated, reviewed catalog of approved Skills and MCP servers, and testing new capabilities in a sandboxed environment first, limits exposure to unvetted repositories. If SmartLoader execution is suspected, isolate the affected endpoint and revoke active browser sessions, OAuth grants, API tokens, and cloud and developer credentials rather than just resetting passwords, since StealC targets live sessions directly.
Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.
AgentBaiting is a technique where AI assistants discover malicious GitHub repositories on their own and relay the attacker's installation steps to the user, even without being given a direct link.
The campaign delivers SmartLoader, which establishes persistence and then installs StealC to steal credentials and active browser sessions.
Researchers identified roughly 7,600 malicious GitHub repositories, including more than 800 posing as AI Skills or MCP servers, tied to about 6,600 accounts.
StealC captures live sessions in addition to passwords, so defenders also need to revoke active browser sessions, OAuth grants, API tokens, and cloud and developer credentials.
You ask your AI assistant for a free “cinematic prompt” Skill, and it confidently hands you a GitHub repo. Looks legit, right? Behind that link might be a FakeGit repo, one of thousands of lookalike projects built to push SmartLoader malware that steals your credentials and active sessions. In tests, AI agents surfaced malicious Walmart MCP server repos as their top pick, then passed along steps telling users to download an .exe from GitHub Releases and click past a Windows security warning. Here’s the move: if any AI-recommended Skill or MCP server tells you to run an .exe or bypass a security warning, stop and report it, don’t install it.

Researchers described two active social-engineering-driven malware campaigns: one uses trojanized “popular” remote-user apps (e.g., Zoom/WebEx lookalikes) to…

Kaspersky reports an active malware campaign (“OkoBot”) that tricks people into running malicious scripts via a ClickFix-style prompt or by downloading a fake…

This threat trend report describes multiple real-world APT campaigns that rely on social engineering (job offers, fake recruiters, code reviews, and…

Researchers linked DigiCert’s April 2026 breach to a GoldenEyeDog sub-group that tricked support staff into running a malicious file delivered through a…

This roundup describes several real-world social-engineering and human-abuse techniques, including trojanized “installer” lures (ClickFix), large-scale…

Researchers demonstrated a new “agent data injection” technique where attackers plant content (like a review or GitHub comment) that an AI agent mistakenly…