Your AI Assistant Recommends the Malware Now: Inside the FakeGit Campaign and the Agent-Borne Supply Chain
A security analysis published today documents how AI agents became a malware distribution channel: the FakeGit campaign (7,600 fake repos, 14M downloads) got Gemini and ChatGPT themselves to recommend a malicious MCP server, while a USENIX 2026 study confirmed 157 malicious skills hiding 'Do Not Mention This to the User' instructions across 98,380 registry entries.
Roughly 7,600 fake GitHub repositories, 6,600 fraudulent profiles, and more than 14 million downloads. That is the scale of FakeGit, a malware campaign documented by security firm Island in July 2026 — and more than 800 of those repositories impersonated AI skills and MCP servers, distributing the SmartLoader downloader and the StealC infostealer.
But the number that should worry anyone building on AI agents is not in those figures. It is this: during the campaign, Gemini and ChatGPT independently suggested the same malicious walmart-mcp repository to users. The assistants were not compromised. They simply found the attacker’s project, judged it relevant and credible, and handed over installation instructions.
A detailed analysis published today by Farukh Rakhimov, Head of Compliance and Information Security at AdTech Holding, walks through the full landscape of what is now a proven attack surface: the software supply chain that feeds AI agents — skills, MCP connectors, plugins, and the trust signals that make them look legitimate. The conclusion is blunt. Attackers no longer need to deceive users directly. They can deceive the assistants users trust.
Why agents are structurally vulnerable
Two architectural characteristics make these attacks possible. First, agents process instructions and external information as text: a malicious instruction hidden in a README, a webpage, or a tool description may be interpreted as something to obey rather than something to analyze. This is indirect prompt injection. Second, agents can act on those instructions.
Security researcher Simon Willison calls the combination of three conditions the “lethal trifecta”: access to valuable information, exposure to untrusted external content, and the ability to send data outside the system. Any agent with all three — which describes most coding assistants and MCP-connected workflows — turns malicious text into a potential data breach.
Eight ways the vector is being exploited
The analysis catalogs eight attack patterns already observed in the wild:
1. AgentBaiting. The FakeGit playbook: build convincing repositories with realistic documentation, seed them through public registries, and wait for AI assistants to recommend them. The fake Walmart MCP connector distributed SmartLoader, which pulled in StealC to steal browser credentials, cookies, active sessions, and cryptocurrency wallet data. The agents’ credibility was manufactured, then borrowed.
2. Tool poisoning. MCP servers describe their tools to agents in text — and instructions can hide inside those descriptions. Invariant Labs demonstrated as early as April 2025 how a malicious calculator tool’s description could manipulate a separate, trusted email connector into copying outgoing messages to an attacker. The user never sees the instructions. It remains a demonstrated threat model rather than a confirmed real-world incident.
3. Skills that conceal their actions. A 2026 academic study — the first labeled dataset of malicious agent skills, presented at USENIX Security — behaviorally verified 98,380 skills from two community registries, confirmed 157 as malicious, and identified 632 vulnerabilities across 13 attack techniques. One recurring hidden instruction gave the research its title: “Do Not Mention This to the User.” An agent can report a task as complete while omitting unauthorized actions, including the exfiltration of sensitive data.
4. The rug pull. A package can behave for months before turning. In September 2025, Koi Security uncovered postmark-mcp, a connector impersonating the legitimate Postmark email service: versions through 1.0.15 were harmless, and version 1.0.16 introduced a hidden BCC recipient copying outgoing mail to an attacker-controlled domain — potentially exposing password resets and authentication links at around 300 organizations. Automatic updates delivered the payload without renewed user approval.
5. Changes outside the package. Reviewing source code cannot catch everything when external dependencies change independently. Check Point’s August 2025 disclosure of MCPoison showed attackers modifying previously approved Cursor project configurations to execute commands without fresh approval (fixed in Cursor 1.3). A separate 2026 experiment distributed a skill to roughly 26,000 agents that initially linked to legitimate documentation — then swapped the external page for malicious installation instructions. The package itself never changed.
6. Code execution before trust is granted. Check Point also found that Claude Code could execute repository-controlled configuration commands before the user completed the trust-confirmation process, including arbitrary command execution (CVE-2025-59536) and API credential exposure via a manipulated server endpoint (CVE-2026-21852). Anthropic has since patched both. The implication: merely opening an unfamiliar project in an agent-enabled environment can create execution paths that ordinary file inspection would not suggest.
7. ClickFix. No prompt injection needed — attackers disguise malicious commands as installation prerequisites inside README or SKILL.md files, and users run them themselves. During the ClawHavoc campaign in early 2026, Koi Security identified 341 malicious skills among 2,857 in the OpenClaw ecosystem (Antiy CERT later tracked 1,184 malicious skills tied to just 12 accounts), targeting cryptocurrency wallets, browser credentials, API keys, SSH keys, and Telegram sessions.
8. The agent as attacker. In November 2025, Anthropic reported GTG-1002, a cyberespionage campaign in which operators connected penetration-testing tools to Claude Code through MCP. According to Anthropic, the model independently performed approximately 80–90% of tactical operations, with humans setting objectives and making strategic decisions. The state-sponsorship attribution has not been independently confirmed, but the case shows existing offensive tools being assembled into autonomous workflows.
The economics of fake reputation
Many of these attacks run on artificially manufactured credibility. An April 2026 investigation found GitHub stars advertised for $0.03–$0.10 each, with roughly six million suspicious stars spread across 15,835 repositories. In one documented case, attackers cloned an Oura MCP connector and spent three months building fake contribution histories before shipping the malicious version. A malicious Solidity extension displayed inflated download counts approaching two million; one blockchain developer reportedly lost about $500,000.
Popularity determines discoverability, not security — and scanners have structural blind spots, since malicious functionality can hide in dependencies, tool descriptions, post-installation updates, or external webpages the package merely links to.
Why this matures slower than the threat
The open-source world has been here before. Mandatory two-factor authentication, trusted publishing, and verified provenance eventually hardened established package registries. AI skill marketplaces are developing much faster, while their security infrastructure remains comparatively immature — and the stakes are broader, because an AI skill may hold access to email, repositories, databases, and credentials simultaneously. The analysis draws a direct line to advertising tech, where media-buying teams increasingly connect agents to DSPs and advertiser data: a poisoned reporting or creative-generation skill puts budgets and account credentials at risk.
The parallel is exact: buying fake stars to legitimize malicious software follows the same logic as using bot traffic to legitimize fraudulent ad inventory. As AI agents gain more authority, verifying the software — and the signals — they trust becomes as important as securing the systems they operate.
Sources
- [1] https://www.artificialintelligence-news.com/news/ai-agents-are-becoming-a-new-malware-distribution-channel/
- [2] https://arxiv.org/html/2602.06547v1
- [3] https://owasp.github.io/www-project-agentic-skills-top-10/ast01.html
- [4] https://unit42.paloaltonetworks.com/openclaw-ai-supply-chain-risk/
- [5] https://snyk.io/blog/toxicskills-malicious-ai-agent-skills-clawhub/