VMTech
Discuss a project

FakeGit: Thousands of GitHub repositories masquerade as AI and MCP to spread SmartLoader

FakeGit: Thousands of GitHub repositories masquerade as AI and MCP to spread SmartLoader

A cybersecurity and AI story worth noting.

Researchers uncovered nearly 7,600 malicious GitHub repositories. More than 800 were disguised as AI Skills and MCP servers to deliver SmartLoader.

The scheme relies on copies of real projects, fake profiles, credible READMEs and ZIP archives. The loader then helps establish persistence and deliver a second-stage payload, including StealC.

A key concern is AgentBaiting: an AI agent may find such a repository, treat it as legitimate, and execute the attack chain without human involvement.

The takeaway: trust not only the code, but also the source — especially in the AI tools ecosystem.

How do you verify Skills and MCP servers before using them? #cybersecurity #AI #SupplyChain #ThreatIntel

Open analytics
On the site 15 views
min read 1 20.07.2026
On Instagram 3 views
On Instagram 1 reach
Instagram

FakeGit: Thousands of GitHub repositories masquerade as AI and MCP to spread SmartLoader

Open the post on Instagram ↗