The "FakeGit" campaign is a large-scale supply chain and social engineering operation leveraging approximately 7,600 malicious GitHub repositories and 6,600 unique accounts to distribute the SmartLoader malware. By masquerading as legitimate AI skills and Model Context Protocol (MCP) servers, the attackers manipulate AI agents to recommend malicious repositories to developers. The technical payload utilizes Cloud Server-Side Request Forgery (SSRF) to deploy SmartLoader, which subsequently installs the StealC information stealer. This operation specifically targets users integrating AI-driven workflows for platforms like Gmail and WhatsApp, aiming for high-value credential and sensitive data theft through the exploitation of the emerging AI agent ecosystem and the perceived trust of the GitHub platform.
-
Incident Overview: Massive Trust Exploitation
- Utilization of 7,600 malicious repositories and 6,600 distinct accounts.
- Strategic targeting of the emerging AI-driven development ecosystem.
- Primary objective: Credential and sensitive data theft via StealC.
-
Attack Vector: AI Manipulation and SSRF Mechanics
- Use of fake MCP (Model Context Protocol) servers to impersonate legitimate AI integrations.
- Manipulation of AI agents through social engineering or prompt injection to recommend malicious repos.
- Execution of Cloud SSRF to facilitate the deployment of the SmartLoader payload.
- Targeting of specific workflow integrations including Gmail and WhatsApp.
-
Threat Profile: Scale and Impact
- High concentration of AI-specific infrastructure: 800 malicious AI repositories and 1,400 dedicated AI accounts.
- Peak activity observed in April 2026.
- Direct impact on developers and users implementing third-party AI agents/workflows.
-
Defensive Actions: Detection and Mitigation
- Implement strict validation and scrutiny for all MCP server connections and AI-driven tool recommendations.
- Monitor for anomalous Cloud SSRF patterns within cloud-native development environments.
- Enhance endpoint detection for SmartLoader and StealC activity.
- Review and audit third-party AI integrations and permissions for Gmail and WhatsApp.
-
Conclusion: The AI Supply Chain Frontier
- Demonstrates how the rapid adoption of AI agents creates new, high-trust attack surfaces.
- Highlights the necessity of securing the Model Context Protocol and AI-integrated workflows.
Related posts
- gbhackers.com — Attackers Combine MCP Recon With Cloud Metadata SSRF to Steal Service Account Tokens
- cybersecurity.pk — FakeGit Campaign Uses 7,600 GitHub Repositories to Spread SmartLoader Malware
- gbhackers.com — AgentBaiting Uses Fake AI Skills and MCP Servers to Deliver SmartLoader and StealC Malware
- threatlabsnews.xcitium.com — FakeGit Exposed: How 7,600 GitHub Repos Are Spreading SmartLoader Malware
- News
- Fag-consult
- Ourservices
- Kahutek
- Isc2gauteng
- helpnetsecurity.com — AI agents tricked into recommending malicious GitHub repositories
- Daily
- Bleepingcomputer
- Techzine
- Trendmicro