Security researchers have uncovered a large FakeGit malware operation that used malicious GitHub repositories, public AI registries, and AI-agent-readable installation instructions to distribute the SmartLoader malware loader.
Island researchers identified about 7,6007{,}6007,600 malicious GitHub repositories linked to the operation.
More than 800800800 of these repositories impersonated AI Skills or Model Context Protocol (MCP) servers. The campaign peaked in April 202620262026, when attackers created nearly 300300300 AI-related repositories.
The operation has recorded more than 141414 million downloads from GitHub Release assets across roughly 200200200 repositories.
The real exposure may be higher because thousands of other repositories hosted malicious ZIP files directly in source projects, where download totals are not publicly visible.

Researchers said the campaign represents a growing software supply-chain risk. Attackers are no longer only targeting developers searching GitHub manually.
They are also targeting AI assistants and agents that discover, assess, and recommend tools on behalf of users.
Malicious AI Skills Surge
FakeGit relies on copied open-source projects, lookalike GitHub profiles, realistic README files, and fake download packages.
The repositories often claim to offer useful AI integrations, including Skills and MCP servers for Gmail, WhatsApp, Databricks, Docker, Jenkins, Walmart, and enterprise systems.
In one example, the repository Mann1988/awesome-claude-skills copied the branding of the legitimate ComposioHQ/awesome-claude-skills project.
The fake repository accumulated stars and forks, helping it look trustworthy. Its README promoted a ZIP archive named awesome-skills-claude-3.3.zip, which researchers identified as a SmartLoader package.
Another repository, 45d5r/databricks-mcp-server, claimed to provide an MCP server with 263263263 Databricks tools.
Instead of legitimate server files, its download package contained a command launcher, a renamed LuaJIT-style runtime, and a heavily obfuscated Lua payload disguised as a text file.

The launcher executed the payload, which could establish persistence and fetch additional encrypted malware stages. These stages ultimately deployed StealC, a known information-stealing malware family.
StealC can steal browser passwords, cookies, active login sessions, browser-extension data, screenshots, email credentials, remote-access credentials, and system information.
Because it steals active sessions, changing passwords alone may not stop account takeover after an infection. Island calls the technique AgentBaiting.
It occurs when an AI agent independently finds a malicious repository during a normal capability search, trusts the attacker-controlled README, and provides the installation steps to its user.
Researchers tested this behavior with Claude Code, Gemini, and ChatGPT. In one test, Claude Code searched for a free cinematic prompt Skill.
It found both a legitimate project and a malicious FakeGit repository. In some runs, it repeated the malicious repository’s instructions to download an executable and bypass Windows security prompts.
Indicators of Compromise
| Type | Indicator | Notes |
|---|---|---|
| GitHub repository | hfgwygey/yu-ai-agent | AI agent lure, 90 stars |
| Malicious file | yu-ai-agent-1.0-beta.3.zip | SmartLoader package |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Prevent critical incidents and financial loss with stronger proactive defense. Integrate a live threat feed from 15K SOCs