Mark RadarMARK RADAR
EN
Event File AI

FakeGit Seeds 7,600 GitHub Repositories With SmartLoader

1 reports · First detected 2026-07-24 · Last active 2026-07-24

AI coding agents increasingly search public repositories and interpret README files to install new capabilities, turning software discovery into a supply-chain risk. FakeGit exploits that trust with copied projects, lookalike developer profiles and malicious ZIP files presented as AI Skills or Model Context Protocol servers. Once launched, SmartLoader establishes persistence and can deploy StealC, an information stealer that targets credentials and other sensitive data.

Cybersecurity firm Island disclosed the campaign on July 20, 2026, saying nearly 7,600 malicious repositories were created by roughly 6,600 profiles, with more than 800 impersonating AI Skills or MCP servers. By July, GitHub Release assets tied to about 200 campaign repositories had logged more than 14 million downloads. In Island's tests, Anthropic's Claude Code, Google Gemini and OpenAI's ChatGPT each surfaced malicious repositories without receiving a direct link, showing how FakeGit's AgentBaiting technique can turn an AI assistant into an unwitting distribution channel.

All Coverage

1 original reports

The Backstory

The history behind this event

No historical echoes for this signal

Mark Radar|MARK RADAR
All times are in Taipei time (GMT+8)