AI Assistants Now Walk Into GitHub Lures

AI assistants can now be steered into malicious repos without a human click. FakeGit has shifted from impersonating projects for people to baiting agents that search GitHub for skills or MCP servers and then follow the README on their own. That breaks the old assumption that a user has to choose the bad repo for the campaign to work. Researchers say the campaign now spans about 7,600 malicious GitHub repositories, including more than 800 AI skills and MCP lures. Island found Claude Code, Gemini, and ChatGPT could be tricked into surfacing the bogus repos, and the operation has already racked up more than 14 million downloads across about 200 campaign repositories. The exposure is broader than a phishing click. Any workflow that lets an agent browse GitHub for code or integrations can be pushed into attacker-controlled repos, which then deliver SmartLoader and set up follow-on StealC theft.

Part of the PlainSec briefing for 2026-07-21

Sources