FakeGit: 7.600 repository GitHub malevoli ingannano gli agenti AI e diffondono SmartLoader

FakeGit: 7,600 malicious GitHub repositories trick AI agents and spread SmartLoader

A campaign called FakeGit set up around 7,600 malicious GitHub repositories, with over 800 projects pretending to be AI Skills or MCP servers. According to researchers, the operation exploited the trust of AI agents and automatic recommendation flows to make infected repositories appear to be legitimate installation options. The scale is notable because the repos were tied to about 6,600 accounts, with a strong focus on integrations and automations used in personal and business contexts. The associated payload is SmartLoader, a malware that can pave the way for further attack stages. The case shows that online reputation and social engineering no longer affect only people: now they can manipulate the agents that choose what to install.

Sources

Leave a Reply

Your email address will not be published. Required fields are marked *


Post Comment