Skip to content
Data Breach

AgentBaiting Campaign Uses 800 Fake AI Skills and MCP Servers to Deliver SmartLoader Malware

Malware operators are increasingly using tools built to extend artificial intelligence as a delivery route. A newly documented campaign called AgentBaiting uses fraudulent AI Skills and Model Context Protocol, or MCP, servers to distribute SmartLoader malware through trusted-looking GitHub projects...

· Jul 21, 2026 · 6 min read · 👁 7 views
AgentBaiting Campaign Uses 800 Fake AI Skills and MCP Servers to Deliver SmartLoader Malware

Malware operators are increasingly using tools built to extend artificial intelligence as a delivery route.

A newly documented campaign called AgentBaiting uses fraudulent AI Skills and Model Context Protocol, or MCP, servers to distribute SmartLoader malware through trusted-looking GitHub projects and public capability catalogs.

The operation turns a routine search for an AI integration into a malware risk. Victims can be steered to ZIP archives presented as useful installers, then encouraged to extract and run files that have no connection to the advertised tool.

Island researchers identified the campaign while tracking the wider FakeGit operation.

Island said in a report shared with Cyber Security News (CSN) that it found about 7,600 malicious repositories created by roughly 6,600 profiles, including more than 800 posing as AI Skills or MCP servers.

The campaign’s reach makes it more than a typical developer scam. The AI-focused wave built through March and peaked in April 2026, while malicious projects appeared more than 600 times across public AI registries and catalogs.

The scale of the FakeGit operation (Source - Island.io)
The scale of the FakeGit operation (Source – Island.io)

Researchers also measured more than 14 million downloads from release assets in approximately 200 campaign repositories.

AgentBaiting Campaign Uses 800 Fake AI Skills and MCP Servers

FakeGit builds credibility through copied projects, lookalike accounts, convincing documentation, and modest engagement numbers.

One lure copied the name and positioning of a popular Claude Skills collection, then offered a confirmed SmartLoader ZIP archive as the download.

The approach echoes earlier fake GitHub malware delivery activity that exploited familiar development workflows to gain trust.

The fake Mann1988 - awesome-claude-skills repository imitates the original ComposioHQ - awesome-claude-skills project (Source - Island.io)
The fake Mann1988 – awesome-claude-skills repository imitates the original ComposioHQ – awesome-claude-skills project (Source – Island.io)

The lures target both personal and business tasks, including email, messaging, analytics, build systems, cloud services, and developer tools.

Their names make downloads appear relevant to daily work instead of suspicious.

Island found that 62 malicious repositories were positioned for enterprise or developer-internal use, while nearly two-thirds of MCP lures claimed to connect cloud services, databases, or APIs.

A repository named 45d5r/databricks-mcp-server shows how the infection begins. Its documentation advertises an enterprise integration and provides a download button, but the linked archive contains a command launcher, a renamed LuaJIT-style runtime, and an obfuscated Lua program disguised as a text file.

Running the launcher activates the concealed payload rather than installing an MCP server.

Related variants can hide their console windows, locate their command server through a value stored in a Polygon smart contract, create scheduled-task persistence, and retrieve encrypted stages from GitHub.

The FakeGit attack chain (Source - Island.io)
The FakeGit attack chain (Source – Island.io)

The stages eventually inject StealC into another process, continuing the credential-theft threat covered in reporting on the StealC infrastructure disruption.

AI Discovery Becomes Risk

AgentBaiting changes the threat because an AI agent can discover the malicious project without a victim receiving a direct link.

During testing, researchers found that Claude Code, Gemini, and ChatGPT could independently surface campaign repositories when asked to find a Skill or MCP server.

The results varied, but still exposed a dangerous gap. One tested agent recommended a benign option while also repeating malicious installation instructions as an alternative.

In another test, Gemini returned a malicious Walmart MCP repository as its first result, while ChatGPT listed the same repository among public options and highlighted it as a starting point.

Public registries can further expand that exposure. Island found more than 600 campaign listings across LobeHub, Glama, MCP.so, and MCP Market, with some reproducing attacker-written documentation and download instructions.

That gives malicious repositories another layer of credibility, particularly as MCP server security concerns grow around AI integrations that can access business resources.

Organizations should rely on a curated and reviewed catalog for Skills, MCP servers, and agent plug-ins instead of unrestricted discovery.

Campaign-linked Skills and MCP servers (Source - Island.io)
Campaign-linked Skills and MCP servers (Source – Island.io)

New capabilities should be tested in an isolated environment without browser sessions, cloud credentials, SSH keys, or production data. A supposed AI capability distributed as a Windows ZIP containing a launcher and hidden payload should be rejected.

Teams should verify publishers as carefully as projects, since star counts, copied profiles, and registry listings do not establish legitimacy.

They should monitor downloads, Git clones, shell commands, and changes to MCP or Skill configurations initiated by agents. Maintaining an inventory of each capability’s repository, commit, version, and package hash can speed investigation.

If SmartLoader execution is suspected, security teams should isolate the endpoint and revoke active browser sessions, OAuth grants, API tokens, cloud credentials, and developer credentials.

Password resets alone may not be enough because StealC can steal live sessions, browser data, email and remote-access credentials, screenshots, and host details.

Indicators of Compromise (IoCs):-

TypeIndicatorDescription
GitHub repositoryhfgwyge/yu-ai-agentFake AI agent repository
File nameyu-ai-agent-1.0-beta.3.zipSmartLoader package
SHA-256216a2c99fd42c00f9323d8b16dd19f622f7f4778b2b1d7cf07a3de5621f2Package hash
GitHub repositoryMann1988/awesome-claude-skillsFake Claude Skills repository
File nameawesome-skills-claude-3.3.zipSmartLoader package
SHA-25691e5dbfaf45edf25fbc2168f92083e05dfa427afa7633e991392e33cc743Package hash
GitHub repositoryh4vzz/awesome-ai-agent-skillsFake AI agent Skills repository
File nameagentaiawesomeskills2.0.zipSmartLoader package
SHA-256498fe8fb806cd0e6685f97fc7d74de769dae5a28cdc821557b7585ad5adPackage hash
GitHub repositoryStanLeyJ03/mcp-for-securityFake security MCP repository
File namefor-security-mcp-3.3.zipSmartLoader package
SHA-25662744baa8077bb8be237647fd78e3bea2ca0932bf4be3d5618600f971185Package hash
GitHub repositoryxbim08/awesome-claude-code-pluginsFake Claude Code plug-ins repository
File namepluginsclaudeawesomecode2.4.zipSmartLoader package
SHA-2561da8df487d30b988f3c350c065206726aaa13f079a07151cd42ab557999Package hash
GitHub repositoryDomingosNgongo/walmart-mcpFake Walmart MCP repository
File namemcp-walmart-2.2.zipSmartLoader package
SHA-256c15693106682f2ddb26649cab6e1962a64537627cde4c5d3c79d5a0be8c7Package hash
GitHub repository45d5r/databricks-mcp-serverFake Databricks MCP repository
File nameserverdatabricksmcp1.6.zipSmartLoader package
SHA-25666afc7d87d10dbe392898c4e5c613e0442fabb396415c2bef3a5ef2ac758Package hash
GitHub repositoryMauManto/jenkins-mcp-serverFake Jenkins MCP repository
File namemcp-server-jenkins-3.2.zipSmartLoader package
SHA-256a33f40cab1ab7f971d3464af3e7595918107332b9e83342007571842b9ePackage hash
GitHub repositorywaynestimulative605/docker-mcp-gatewayFake Docker MCP gateway repository
File namegateway-docker-mcp-v1.6-alpha.5.zipSmartLoader package
SHA-2563c858facbad66f5479e2c4add171421dc1b6488b36f33e7cff073aba585Package hash
GitHub repositorylucaducapuca/alibabacloud-bigdata-skillsFake Alibaba Cloud Skills repository
File namealibabacloud-skills-bigdata-v1.7.zipSmartLoader package
SHA-256fc1278f419e611bf40ca414099bfd9ad98a31ffb054371e8cb65a84849bPackage hash

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Source: CybersecurityNews.com

Follow ShomoySoft for more: Follow on Facebook

💬 Comments (0)

Login to join the discussion.

No comments yet. Be the first!

Recommended for you