AI agents become malware distribution channel through fake GitHub repositories
A campaign dubbed FakeGit, documented by Island in July 2026, operated roughly 7,600 fake GitHub repositories, 6,600 fraudulent profiles and more than 14 million downloads. Over 800 of those repos impersonated AI skills and MCP servers, distributing the SmartLoader loader and the StealC infostealer. In a striking development, both Gemini and ChatGPT independently recommended the same malicious…
Key points
- FakeGit campaign used ~7,600 fake GitHub repos, 6,600 fraudulent profiles, and over 14 million downloads.
- Gemini and ChatGPT each recommended the same malicious walmart‑mcp repository, spreading SmartLoader and the StealC infostealer.
- Researchers outlined eight attack patterns, including AgentBaiting, Tool Poisoning, Rug Pulls, and agents acting as attackers.
Security researchers describe eight ways the vulnerabilities are exploited, from AgentBaiting – where agents recommend malware – to Tool Poisoning, Rug Pulls, and agents acting as attackers. Some techniques, such as tool poisoning, remain demonstrated threat models rather than confirmed real‑world incidents, while others, like the GTG‑1002 cyber‑espionage operation reported by Anthropic, have not been independently verified. The report highlights the ease with which malicious text can be turned into data breaches when agents process untrusted external content and can send data outside the system.
The findings underscore that as AI agents gain more authority, verifying the software and signals they trust is as critical as securing the underlying systems, especially for sectors like advertising where compromised agents could expose campaign data and budgets.
The story so far
7 episodes →- AI agents become malware distribution channel through fake GitHub repositoriesthis story
AI Agents Are Becoming a New Malware Distribution Channel
AI News · 23 September 2026
Loading the full article…
This text was published by AI News and written by Farukh Rakhimov, Head of Compliance, Data Protection and Information Security at AdTech Holding. It is reproduced here with attribution so you can read it in full; the rights remain with the publisher. Read it at the source ↗
The headline, key points and digest above were generated by Digest AI's editorial model from the linked sources. Automated summaries can contain errors: the sources are the record. Spotted a mistake? Tell us. Published by Martin K., who runs Digest AI and handles corrections.
More in Agents & Tools
All →- Amazon blocks Meta's Muse AI agent from shopping on its platform · 11 src
- Nokia open-sources AnyJev library to turn open LLMs into calibrated decision models · 1 src
- Opinion: Claude adds Docs and Slides, sparking debate over office integration · 1 src
- Delinea tests Anthropic Claude Mythos 5.1 on its own privileged‑access code · 1 src
- Google launches CC family AI agent for up to six members · 1 src
Comments
via GitHub Discussions