AgentBaiting Campaign Uses 800 Fake AI Skills and MCP Servers to Deliver SmartLoader Malware

In Cybersecurity News - Original News Source is cybersecuritynews.com by Blog Writer

Spread the love

Malware operators are increasingly using tools built to extend artificial intelligence as a delivery route.

A newly documented campaign called AgentBaiting uses fraudulent AI Skills and Model Context Protocol, or MCP, servers to distribute SmartLoader malware through trusted-looking GitHub projects and public capability catalogs.

The operation turns a routine search for an AI integration into a malware risk. Victims can be steered to ZIP archives presented as useful installers, then encouraged to extract and run files that have no connection to the advertised tool.

Island researchers identified the campaign while tracking the wider FakeGit operation.

Island said in a report shared with Cyber Security News (CSN) that it found about 7,600 malicious repositories created by roughly 6,600 profiles, including more than 800 posing as AI Skills or MCP servers.

The campaign’s reach makes it more than a typical developer scam. The AI-focused wave built through March and peaked in April 2026, while malicious projects appeared more than 600 times across public AI registries and catalogs.

The scale of the FakeGit operation (Source – Island.io)

Researchers also measured more than 14 million downloads from release assets in approximately 200 campaign repositories.

AgentBaiting Campaign Uses 800 Fake AI Skills and MCP Servers

FakeGit builds credibility through copied projects, lookalike accounts, convincing documentation, and modest engagement numbers.

One lure copied the name and positioning of a popular Claude Skills collection, then offered a confirmed SmartLoader ZIP archive as the download.

The approach echoes earlier fake GitHub malware delivery activity that exploited familiar development workflows to gain trust.

The fake Mann1988 – awesome-claude-skills repository imitates the original ComposioHQ – awesome-claude-skills project (Source – Island.io)

The lures target both personal and business tasks, including email, messaging, analytics, build systems, cloud services, and developer tools.

Their names make downloads appear relevant to daily work instead of suspicious.

Island found that 62 malicious repositories were positioned for enterprise or developer-internal use, while nearly two-thirds of MCP lures claimed to connect cloud services, databases, or APIs.

A repository named 45d5r/databricks-mcp-server shows how the infection begins. Its documentation advertises an enterprise integration and provides a download button, but the linked archive contains a command launcher, a renamed LuaJIT-style runtime, and an obfuscated Lua program disguised as a text file.

Running the launcher activates the concealed payload rather than installing an MCP server.

Related variants can hide their console windows, locate their command server through a value stored in a Polygon smart contract, create scheduled-task persistence, and retrieve encrypted stages from GitHub.

The FakeGit attack chain (Source – Island.io)

The stages eventually inject StealC into another process, continuing the credential-theft threat covered in reporting on the StealC infrastructure disruption.

AI Discovery Becomes Risk

AgentBaiting changes the threat because an AI agent can discover the malicious project without a victim receiving a direct link.

During testing, researchers found that Claude Code, Gemini, and ChatGPT could independently surface campaign repositories when asked to find a Skill or MCP server.

The results varied, but still exposed a dangerous gap. One tested agent recommended a benign option while also repeating malicious installation instructions as an alternative.

In another test, Gemini returned a malicious Walmart MCP repository as its first result, while ChatGPT listed the same repository among public options and highlighted it as a starting point.

Public registries can further expand that exposure. Island found more than 600 campaign listings across LobeHub, Glama, MCP.so, and MCP Market, with some reproducing attacker-written documentation and download instructions.

That gives malicious repositories another layer of credibility, particularly as MCP server security concerns grow around AI integrations that can access business resources.

Organizations should rely on a curated and reviewed catalog for Skills, MCP servers, and agent plug-ins instead of unrestricted discovery.

Campaign-linked Skills and MCP servers (Source – Island.io)

New capabilities should be tested in an isolated environment without browser sessions, cloud credentials, SSH keys, or production data. A supposed AI capability distributed as a Windows ZIP containing a launcher and hidden payload should be rejected.

Teams should verify publishers as carefully as projects, since star counts, copied profiles, and registry listings do not establish legitimacy.

They should monitor downloads, Git clones, shell commands, and changes to MCP or Skill configurations initiated by agents. Maintaining an inventory of each capability’s repository, commit, version, and package hash can speed investigation.

If SmartLoader execution is suspected, security teams should isolate the endpoint and revoke active browser sessions, OAuth grants, API tokens, cloud credentials, and developer credentials.

Password resets alone may not be enough because StealC can steal live sessions, browser data, email and remote-access credentials, screenshots, and host details.

Indicators of Compromise (IoCs):-

Type Indicator Description
GitHub repository hfgwyge/yu-ai-agent Fake AI agent repository
File name yu-ai-agent-1.0-beta.3.zip SmartLoader package
SHA-256 216a2c99fd42c00f9323d8b16dd19f622f7f4778b2b1d7cf07a3de5621f2 Package hash
GitHub repository Mann1988/awesome-claude-skills Fake Claude Skills repository
File name awesome-skills-claude-3.3.zip SmartLoader package
SHA-256 91e5dbfaf45edf25fbc2168f92083e05dfa427afa7633e991392e33cc743 Package hash
GitHub repository h4vzz/awesome-ai-agent-skills Fake AI agent Skills repository
File name agentaiawesomeskills2.0.zip SmartLoader package
SHA-256 498fe8fb806cd0e6685f97fc7d74de769dae5a28cdc821557b7585ad5ad Package hash
GitHub repository StanLeyJ03/mcp-for-security Fake security MCP repository
File name for-security-mcp-3.3.zip SmartLoader package
SHA-256 62744baa8077bb8be237647fd78e3bea2ca0932bf4be3d5618600f971185 Package hash
GitHub repository xbim08/awesome-claude-code-plugins Fake Claude Code plug-ins repository
File name pluginsclaudeawesomecode2.4.zip SmartLoader package
SHA-256 1da8df487d30b988f3c350c065206726aaa13f079a07151cd42ab557999 Package hash
GitHub repository DomingosNgongo/walmart-mcp Fake Walmart MCP repository
File name mcp-walmart-2.2.zip SmartLoader package
SHA-256 c15693106682f2ddb26649cab6e1962a64537627cde4c5d3c79d5a0be8c7 Package hash
GitHub repository 45d5r/databricks-mcp-server Fake Databricks MCP repository
File name serverdatabricksmcp1.6.zip SmartLoader package
SHA-256 66afc7d87d10dbe392898c4e5c613e0442fabb396415c2bef3a5ef2ac758 Package hash
GitHub repository MauManto/jenkins-mcp-server Fake Jenkins MCP repository
File name mcp-server-jenkins-3.2.zip SmartLoader package
SHA-256 a33f40cab1ab7f971d3464af3e7595918107332b9e83342007571842b9e Package hash
GitHub repository waynestimulative605/docker-mcp-gateway Fake Docker MCP gateway repository
File name gateway-docker-mcp-v1.6-alpha.5.zip SmartLoader package
SHA-256 3c858facbad66f5479e2c4add171421dc1b6488b36f33e7cff073aba585 Package hash
GitHub repository lucaducapuca/alibabacloud-bigdata-skills Fake Alibaba Cloud Skills repository
File name alibabacloud-skills-bigdata-v1.7.zip SmartLoader package
SHA-256 fc1278f419e611bf40ca414099bfd9ad98a31ffb054371e8cb65a84849b Package hash

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Strengthen Your SOC by Accelerating Threat Detection & Rapid Investigations. -> Integrate ANY.RUN With Your SOC Now.