A significant cyber operation known as “FakeGit” has disseminated SmartLoader and StealC malware via over 7,600 malicious GitHub repositories, leading to more than 14 million total downloads.
More than 800 repositories, posing as AI tools or MCP servers, appeared over 600 times in public AI registries and catalogs. This technique, referred to by researchers as “agent baiting,” heightens the likelihood of discoveries by AI agents and developers.
This campaign is a continuation of previous operations. It employs Lumma Stealer and is believed to be orchestrated by the threat actor known as “Water Kurata,” as identified by cybersecurity experts at Trend Micro.
As reported by researchers at enterprise browser platform Island, the surge in AI-related focus began in March, peaking in April with the emergence of 300 GitHub repositories associated with AI tools.
The FakeGit campaign has expanded to encompass over 1,400 repositories concerning AI tools, agents, and workflows, all leading to downloads of SmartLoader or StealC malware.

Source: Island
Many of these repositories simulate legitimate consumer and enterprise tools like Gmail, WhatsApp, Databricks, Jenkins, and Docker, complete with convincing documentation, fabricated star and fork counts, copied project descriptions, and real developer account names.
The README file prompts visitors to download a ZIP archive, masquerading as an installer or project release, but instead containing a concealed Lua payload that activates SmartLoader.
Upon activation, SmartLoader implements persistence via a scheduled task, acquires a command and control (C2) address through a Polygon smart contract, downloads additional encryption stages from GitHub, and ultimately deploys the StealC information stealer.
Understanding Agent Baiting
Researchers from Island assert that the malicious repository is part of a novel technique known as Agent Baiting, designed to enhance visibility into AI agents and elevate their usage probability.
In typical scenarios, the agent may interpret the README contents as authentic documentation, recommending a repository or ZIP file to human operators.

Source: Island
In tests by Island, ChatGPT, Gemini, and Claude highlighted various malicious repositories when requested for related tasks, and at times provided installation instructions.
Island found over 600 listings of skills and MCP servers tied to FakeGit campaigns within public registries and catalogs. Notable mentions include LobeHub, Glama, MCP.so, and MCP Market, indicating that this operation has infiltrated the ecosystem and contaminated public resources.
While researchers could not ascertain whether these lists were submitted manually or indexed automatically, they noted that their existence made repositories more discoverable and fostered trust.
Island researchers informed BleepingComputer that during controlled testing, Claude Code cloned a malicious repository and downloaded infected files onto testing machines.
However, the agent identified a suspicious indicator and halted execution before proceeding.
This test is not intended to measure detection rates but does not provide conclusive evidence regarding whether coding agents can consistently identify hazards during execution phases.
.jpg)
Source: Island
Concerning the broader implications of this campaign, Island noted that GitHub’s public download counter recorded a cumulative total of 14,084,688 download events across 335 unique release assets from 211 GitFake repositories.
Oleg Zaytsev, lead security researcher at Island, emphasized that this figure does not signify actual infections; it incorporates repeated requests and automated activities.
Island advises organizations to maintain an approved catalog of skills and MCP servers, test new features in isolated environments, and independently verify publishers and repositories.
If you suspect any SmartLoader executions, it’s crucial to immediately rotate all sensitive credentials in the affected environment.
Security teams document 54% of successful attacks yet issue warnings for only 14%. The rest remain undetected within the environment.
Picus’ whitepaper explains how to assess your SIEM and EDR rules through breach and attack simulations to ensure threats go unnoticed.
Source: www.bleepingcomputer.com




