AgentBaiting Malware Campaign Targets AI MCP Servers

AgentBaiting malware campaign diagram showing fake AI skills and MCP server repositories on GitHub

Emergence of AgentBaiting Threat Vector

The surging popularity of artificial intelligence tools has transformed skill directories into lucrative initial access points. Attackers target Model Context Protocol (MCP) server repositories to distribute malicious loads. Notably, the FakeGit operation weaponized roughly 7,600 GitHub repositories. This widespread campaign actively disseminated SmartLoader and the StealC infostealer.

According to research from Island, over 800 repositories masqueraded as specialized AI skills and MCP servers. These components connect large language models to external tools. You can read the comprehensive report on the AgentBaiting malware campaign for deeper insights. These malicious projects surfaced over 600 times across public registries. Cybersecurity specialists designated this novel distribution method as “agent baiting.”

Spoofing Infrastructure and Malicious Payloads

The malicious repositories spoofed popular enterprise services to deceive developers and AI systems. They copied descriptions for Gmail, WhatsApp, Databricks, Jenkins, and Docker. Additionally, the attackers utilized genuine developer names, fake star ratings, and convincing documentation.

README files urged visitors to download ZIP archives containing supposed project releases. However, these archives contained an obfuscated Lua payload that executed SmartLoader. Once running, SmartLoader established system persistence using scheduled tasks. It then fetched command-and-control addresses from a Polygon smart contract. Finally, the installer fetched encrypted components from GitHub to deploy the StealC infostealer.

AI Model Testing and Evasion Capabilities

Controlled evaluations revealed that AI platforms could accidentally index these malicious resources. Popular models including ChatGPT, Gemini, and Claude identified several malicious repositories. In some instances, they provided installation instructions directly to users.

During testing, Claude Code cloned a malicious repository onto a test machine. However, the system detected suspicious indicators and stopped execution before running the payload. Researchers noted these tests were not complete audits. Therefore, they do not indicate how reliably AI agents detect threats.

Scale of Impact and Mitigation Guidance

GitHub download metrics revealed over 14 million file requests across 211 repositories. However, this total includes automated requests and duplicate traffic rather than confirmed infections. Security teams must take proactive steps to secure their environments against agent baiting techniques.

Organizations should strictly rely on verified AI skill registries and MCP directories. Furthermore, IT teams must test new components in isolated environments. Developers should independently verify repository authors before integration. If a SmartLoader infection is suspected, security teams must immediately rotate all credentials and secrets.

Support Our Threat Intelligence

If you find our technology report and cybersecurity news helpful, consider supporting our work.

Crypto QR Code
USDT (TRC20):
TN8BdV8cp4T1Cd28gK9qTAnZknzzuwyUtm
USDT (ERC20):
0x3725e1a7d3bc5765499fa6aaafe307fabcd75bce

Leave a Reply