AgentBaiting Malware Campaign Targets AI MCP Servers
Emergence of AgentBaiting Threat Vector
The surging popularity of artificial intelligence tools has transformed skill directories into lucrative initial access points. Attackers target Model Context Protocol (MCP) server repositories to distribute malicious loads. Notably, the FakeGit operation weaponized roughly 7,600 GitHub repositories. This widespread campaign actively disseminated SmartLoader and the StealC infostealer.
According to research from Island, over 800 repositories masqueraded as specialized AI skills and MCP servers. These components connect large language models to external tools. You can read the comprehensive report on the AgentBaiting malware campaign for deeper insights. These malicious projects surfaced over 600 times across public registries. Cybersecurity specialists designated this novel distribution method as “agent baiting.”
Spoofing Infrastructure and Malicious Payloads
The malicious repositories spoofed popular enterprise services to deceive developers and AI systems. They copied descriptions for Gmail, WhatsApp, Databricks, Jenkins, and Docker. Additionally, the attackers utilized genuine developer names, fake star ratings, and convincing documentation.
README files urged visitors to download ZIP archives containing supposed project releases. However, these archives contained an obfuscated Lua payload that executed SmartLoader. Once running, SmartLoader established system persistence using scheduled tasks. It then fetched command-and-control addresses from a Polygon smart contract. Finally, the installer fetched encrypted components from GitHub to deploy the StealC infostealer.
AI Model Testing and Evasion Capabilities
Controlled evaluations revealed that AI platforms could accidentally index these malicious resources. Popular models including ChatGPT, Gemini, and Claude identified several malicious repositories. In some instances, they provided installation instructions directly to users.
During testing, Claude Code cloned a malicious repository onto a test machine. However, the system detected suspicious indicators and stopped execution before running the payload. Researchers noted these tests were not complete audits. Therefore, they do not indicate how reliably AI agents detect threats.
Scale of Impact and Mitigation Guidance
GitHub download metrics revealed over 14 million file requests across 211 repositories. However, this total includes automated requests and duplicate traffic rather than confirmed infections. Security teams must take proactive steps to secure their environments against agent baiting techniques.
Organizations should strictly rely on verified AI skill registries and MCP directories. Furthermore, IT teams must test new components in isolated environments. Developers should independently verify repository authors before integration. If a SmartLoader infection is suspected, security teams must immediately rotate all credentials and secrets.
Support Our Threat Intelligence
If you find our technology report and cybersecurity news helpful, consider supporting our work.