A large-scale operation dubbed ‘FakeGit’ is pushing SmartLoader and StealC malware through 7,600 malicious GitHub repositories that accumulated more than 14 million downloads.

Over 800 repositories pretended to be AI skills or MCP servers and appeared more than 600 times in public AI registries and catalogs. This increased the likelihood of being discovered by AI agents and developers, a technique that researchers call "agentbaiting."

The campaign is considered a continuation of an older operation that used Lumma Stealer and was attributed to a threat actor tracked as “Water Kurita” by researchers at cybersecurity company Trend Micro.

According to researchers at the enterprise browser platform Island, the AI focus was introduced in March and peaked in April, with the creation of 300 GitHub repositories linked to AI tools.

Researchers found that FakeGit grew to more than 1,400 repositories related to AI tools, agents, and workflows, all linking to SmartLoader or StealC  malware downloads.

Malicious GitHub repository
Source: Island

Many of the repositories imitate consumer and enterprise tools such as Gmail, WhatsApp, Databricks, Jenkins, and Docker, and include convincing documentation, fabricated stars and fork counts, copied project descriptions, and real developer account names.

Their README files direct visitors to download ZIP archives that pose as installers or project releases but are disguised Lua payloads that trigger SmartLoader.

Once SmartLoader is active, it establishes persistence through scheduled tasks, retrieves its command-and-control (C2) address through a Polygon smart contract, and downloads additional encrypted stages from GitHub, ultimately delivering the StealCinformation stealer.

The AgentBaiting technique

Researchers at Island say the malicious repositories are part of an emerging technique they call AgentBaiting, which is designed to increase their visibility to AI agents and improve the chances of being used.

In a typical scenario, agents are likely to parse the README contents as legitimate documentation and recommend the repository or ZIP file to the human operator.

Malicious README file
Source: Island

In Island’s tests, ChatGPT, Gemini, and Claude surfaced various malicious repositories when prompted with related tasks, and sometimes relayed the installation instructions.

Island found in public registries and catalogs more than 600 listings for skills and MCP servers that were linked to the FakeGit campaign. Some of them included LobeHub, Glama, MCP.so, and MCP Market, indicating that the operation has already penetrated the ecosystem and poisoned public resources.

The researchers could not determine if listings were submitted manually or indexed automatically, but said their presence made the repositories easier to discover and added to their credibility.

Island researchers told BleepingComputer that in limited, controlled testing, Claude Code cloned malicious repositories and downloaded the malicious files onto the test machine.

However, the agent subsequently detected suspicious indicators and stopped before execution.

The tests were not designed to establish a detection rate, so they cannot provide conclusive results on whether coding agents can consistently recognize the danger during the execution stage.

Attack chain
Source: Island

Concerning the broader impact of the campaign, Island reports that GitHub’s public download counters for 335 unique Release assets across 211 GitFake repositories recorded 14,084,688 cumulative download events.

Oleg Zaytsev, Lead Security Researcher at Island, clarified that this figure included repeated requests and automated activity, so it should not be interpreted as infections.

Island recommends that organizations maintain approved catalogs of skills and MCP servers, test new capabilities in isolated environments, and verify publishers and repositories independently.

Where SmartLoader execution is suspected, all secrets on impacted environments should be rotated immediately.

Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.

The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.

Get the whitepaper