Malicious AI Skills Reach Public Registries and Accumulate 14 Million Downloads

Security researchers have uncovered a large FakeGit malware operation that used malicious GitHub repositories, public AI registries, and AI-agent-readable installation instructions to distribute the SmartLoader malware loader.

Island researchers identified about 7,6007{,}6007,600 malicious GitHub repositories linked to the operation.

More than 800800800 of these repositories impersonated AI Skills or Model Context Protocol (MCP) servers. The campaign peaked in April 202620262026, when attackers created nearly 300300300 AI-related repositories.

The operation has recorded more than 141414 million downloads from GitHub Release assets across roughly 200200200 repositories.

The real exposure may be higher because thousands of other repositories hosted malicious ZIP files directly in source projects, where download totals are not publicly visible.

The scale of the FakeGit operation, including its AI-related repositories, Skills and MCP servers, and appearances across public AI registries (Source: island)
The scale of the FakeGit operation, including its AI-related repositories, Skills and MCP servers, and appearances across public AI registries (Source: island)

Researchers said the campaign represents a growing software supply-chain risk. Attackers are no longer only targeting developers searching GitHub manually.

They are also targeting AI assistants and agents that discover, assess, and recommend tools on behalf of users.

Malicious AI Skills Surge

FakeGit relies on copied open-source projects, lookalike GitHub profiles, realistic README files, and fake download packages.

The repositories often claim to offer useful AI integrations, including Skills and MCP servers for Gmail, WhatsApp, Databricks, Docker, Jenkins, Walmart, and enterprise systems.

In one example, the repository Mann1988/awesome-claude-skills copied the branding of the legitimate ComposioHQ/awesome-claude-skills project.

The fake repository accumulated stars and forks, helping it look trustworthy. Its README promoted a ZIP archive named awesome-skills-claude-3.3.zip, which researchers identified as a SmartLoader package.

Another repository, 45d5r/databricks-mcp-server, claimed to provide an MCP server with 263263263 Databricks tools.

Instead of legitimate server files, its download package contained a command launcher, a renamed LuaJIT-style runtime, and a heavily obfuscated Lua payload disguised as a text file.

The fake Mann1988/awesome-claude-skills repository imitates the original ComposioHQ/awesome-claude-skills project while directing visitors to a SmartLoader download (Source: island)
The fake Mann1988/awesome-claude-skills repository imitates the original ComposioHQ/awesome-claude-skills project while directing visitors to a SmartLoader download (Source: island)

The launcher executed the payload, which could establish persistence and fetch additional encrypted malware stages. These stages ultimately deployed StealC, a known information-stealing malware family.

StealC can steal browser passwords, cookies, active login sessions, browser-extension data, screenshots, email credentials, remote-access credentials, and system information.

Because it steals active sessions, changing passwords alone may not stop account takeover after an infection. Island calls the technique AgentBaiting.

It occurs when an AI agent independently finds a malicious repository during a normal capability search, trusts the attacker-controlled README, and provides the installation steps to its user.

Researchers tested this behavior with Claude Code, Gemini, and ChatGPT. In one test, Claude Code searched for a free cinematic prompt Skill.

It found both a legitimate project and a malicious FakeGit repository. In some runs, it repeated the malicious repository’s instructions to download an executable and bypass Windows security prompts.

Indicators of Compromise

TypeIndicatorNotes
GitHub repositoryhfgwygey/yu-ai-agentAI agent lure, 909090 stars
Malicious fileyu-ai-agent-1.0-beta.3.zipSmartLoader package

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Prevent critical incidents and financial loss with stronger proactive defense. Integrate a live threat feed from 15K SOCs

Varshini
Varshini
Varshini is a Cyber Security expert in Threat Analysis, Vulnerability Assessment, and Research. Passionate about staying ahead of emerging Threats and Technologies..

Trending News

Related Stories