Malware operators are increasingly using tools built to extend artificial intelligence as a delivery route.
A newly documented campaign called AgentBaiting uses fraudulent AI Skills and Model Context Protocol, or MCP, servers to distribute SmartLoader malware through trusted-looking GitHub projects and public capability catalogs.
The operation turns a routine search for an AI integration into a malware risk. Victims can be steered to ZIP archives presented as useful installers, then encouraged to extract and run files that have no connection to the advertised tool.
Island researchers identified the campaign while tracking the wider FakeGit operation.
Island said in a report shared with Cyber Security News (CSN) that it found about 7,600 malicious repositories created by roughly 6,600 profiles, including more than 800 posing as AI Skills or MCP servers.
The campaign’s reach makes it more than a typical developer scam. The AI-focused wave built through March and peaked in April 2026, while malicious projects appeared more than 600 times across public AI registries and catalogs.

Researchers also measured more than 14 million downloads from release assets in approximately 200 campaign repositories.
AgentBaiting Campaign Uses 800 Fake AI Skills and MCP Servers
FakeGit builds credibility through copied projects, lookalike accounts, convincing documentation, and modest engagement numbers.
One lure copied the name and positioning of a popular Claude Skills collection, then offered a confirmed SmartLoader ZIP archive as the download.
The approach echoes earlier fake GitHub malware delivery activity that exploited familiar development workflows to gain trust.

The lures target both personal and business tasks, including email, messaging, analytics, build systems, cloud services, and developer tools.
Their names make downloads appear relevant to daily work instead of suspicious.
Island found that 62 malicious repositories were positioned for enterprise or developer-internal use, while nearly two-thirds of MCP lures claimed to connect cloud services, databases, or APIs.
A repository named 45d5r/databricks-mcp-server shows how the infection begins. Its documentation advertises an enterprise integration and provides a download button, but the linked archive contains a command launcher, a renamed LuaJIT-style runtime, and an obfuscated Lua program disguised as a text file.
Running the launcher activates the concealed payload rather than installing an MCP server.
Related variants can hide their console windows, locate their command server through a value stored in a Polygon smart contract, create scheduled-task persistence, and retrieve encrypted stages from GitHub.

The stages eventually inject StealC into another process, continuing the credential-theft threat covered in reporting on the StealC infrastructure disruption.
AI Discovery Becomes Risk
AgentBaiting changes the threat because an AI agent can discover the malicious project without a victim receiving a direct link.
During testing, researchers found that Claude Code, Gemini, and ChatGPT could independently surface campaign repositories when asked to find a Skill or MCP server.
The results varied, but still exposed a dangerous gap. One tested agent recommended a benign option while also repeating malicious installation instructions as an alternative.
In another test, Gemini returned a malicious Walmart MCP repository as its first result, while ChatGPT listed the same repository among public options and highlighted it as a starting point.
Public registries can further expand that exposure. Island found more than 600 campaign listings across LobeHub, Glama, MCP.so, and MCP Market, with some reproducing attacker-written documentation and download instructions.
That gives malicious repositories another layer of credibility, particularly as MCP server security concerns grow around AI integrations that can access business resources.
Organizations should rely on a curated and reviewed catalog for Skills, MCP servers, and agent plug-ins instead of unrestricted discovery.

New capabilities should be tested in an isolated environment without browser sessions, cloud credentials, SSH keys, or production data. A supposed AI capability distributed as a Windows ZIP containing a launcher and hidden payload should be rejected.
Teams should verify publishers as carefully as projects, since star counts, copied profiles, and registry listings do not establish legitimacy.
They should monitor downloads, Git clones, shell commands, and changes to MCP or Skill configurations initiated by agents. Maintaining an inventory of each capability’s repository, commit, version, and package hash can speed investigation.
If SmartLoader execution is suspected, security teams should isolate the endpoint and revoke active browser sessions, OAuth grants, API tokens, cloud credentials, and developer credentials.
Password resets alone may not be enough because StealC can steal live sessions, browser data, email and remote-access credentials, screenshots, and host details.
Indicators of Compromise (IoCs):-
| Type | Indicator | Description |
|---|---|---|
| GitHub repository | hfgwyge/yu-ai-agent | Fake AI agent repository |
| File name | yu-ai-agent-1.0-beta.3.zip | SmartLoader package |
| SHA-256 | 216a2c99fd42c00f9323d8b16dd19f622f7f4778b2b1d7cf07a3de5621f2 | Package hash |
| GitHub repository | Mann1988/awesome-claude-skills | Fake Claude Skills repository |
| File name | awesome-skills-claude-3.3.zip | SmartLoader package |
| SHA-256 | 91e5dbfaf45edf25fbc2168f92083e05dfa427afa7633e991392e33cc743 | Package hash |
| GitHub repository | h4vzz/awesome-ai-agent-skills | Fake AI agent Skills repository |
| File name | agentaiawesomeskills2.0.zip | SmartLoader package |
| SHA-256 | 498fe8fb806cd0e6685f97fc7d74de769dae5a28cdc821557b7585ad5ad | Package hash |
| GitHub repository | StanLeyJ03/mcp-for-security | Fake security MCP repository |
| File name | for-security-mcp-3.3.zip | SmartLoader package |
| SHA-256 | 62744baa8077bb8be237647fd78e3bea2ca0932bf4be3d5618600f971185 | Package hash |
| GitHub repository | xbim08/awesome-claude-code-plugins | Fake Claude Code plug-ins repository |
| File name | pluginsclaudeawesomecode2.4.zip | SmartLoader package |
| SHA-256 | 1da8df487d30b988f3c350c065206726aaa13f079a07151cd42ab557999 | Package hash |
| GitHub repository | DomingosNgongo/walmart-mcp | Fake Walmart MCP repository |
| File name | mcp-walmart-2.2.zip | SmartLoader package |
| SHA-256 | c15693106682f2ddb26649cab6e1962a64537627cde4c5d3c79d5a0be8c7 | Package hash |
| GitHub repository | 45d5r/databricks-mcp-server | Fake Databricks MCP repository |
| File name | serverdatabricksmcp1.6.zip | SmartLoader package |
| SHA-256 | 66afc7d87d10dbe392898c4e5c613e0442fabb396415c2bef3a5ef2ac758 | Package hash |
| GitHub repository | MauManto/jenkins-mcp-server | Fake Jenkins MCP repository |
| File name | mcp-server-jenkins-3.2.zip | SmartLoader package |
| SHA-256 | a33f40cab1ab7f971d3464af3e7595918107332b9e83342007571842b9e | Package hash |
| GitHub repository | waynestimulative605/docker-mcp-gateway | Fake Docker MCP gateway repository |
| File name | gateway-docker-mcp-v1.6-alpha.5.zip | SmartLoader package |
| SHA-256 | 3c858facbad66f5479e2c4add171421dc1b6488b36f33e7cff073aba585 | Package hash |
| GitHub repository | lucaducapuca/alibabacloud-bigdata-skills | Fake Alibaba Cloud Skills repository |
| File name | alibabacloud-skills-bigdata-v1.7.zip | SmartLoader package |
| SHA-256 | fc1278f419e611bf40ca414099bfd9ad98a31ffb054371e8cb65a84849b | Package hash |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.