FakeGit Seeds 7,600 GitHub Repositories With SmartLoader
AI coding agents increasingly search public repositories and interpret README files to install new capabilities, turning software discovery into a supply-chain risk. FakeGit exploits that trust with copied projects, lookalike developer profiles and malicious ZIP files presented as AI Skills or Model Context Protocol servers. Once launched, SmartLoader establishes persistence and can deploy StealC, an information stealer that targets credentials and other sensitive data.
Cybersecurity firm Island disclosed the campaign on July 20, 2026, saying nearly 7,600 malicious repositories were created by roughly 6,600 profiles, with more than 800 impersonating AI Skills or MCP servers. By July, GitHub Release assets tied to about 200 campaign repositories had logged more than 14 million downloads. In Island's tests, Anthropic's Claude Code, Google Gemini and OpenAI's ChatGPT each surfaced malicious repositories without receiving a direct link, showing how FakeGit's AgentBaiting technique can turn an AI assistant into an unwitting distribution channel.
All Coverage
1 original reportsThe Backstory
The history behind this eventNo historical echoes for this signal
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.