AgentBaiting is a strategic environmental poisoning campaign, part of the larger "FakeGit" operation, targeting agentic AI frameworks including Claude Code, Gemini, and ChatGPT. Attackers leverage malicious Model Context Protocol (MCP) servers and fraudulent AI "skills" to deceive agents into installing malware or executing unauthorized remote commands. The attack surface is expanded via "Hallusquatting"—registering domains that match AI-generated hallucinations—and "Agent Data Injection," utilizing poisoned GitHub comments and product reviews to manipulate agent decision-making. Researchers have identified approximately 7,600 malicious GitHub repositories, with over 800 specifically masquerading as AI tools to facilitate remote code execution (RCE) and unauthorized system access.
-
Threat Model: Environmental Poisoning
- Shift from traditional prompt injection to "environmental poisoning," targeting the external tools and extensions AI agents rely on.
- Exploits the inherent trust agentic LLMs place in Model Context Protocol (MCP) servers and "skill" definitions.
- Aims to trick AI agents into performing unauthorized actions, such as running malicious shells or making unauthorized purchases.
-
Attack Mechanics: MCP and Skillgate
- Deployment of fake MCP servers that mimic legitimate capabilities to deceive agentic AI into executing remote commands.
- "Skillgate" methodology utilizes poisoned AI instruction files to trick models into installing malicious third-party tools.
- Attackers weaponize the AI extension ecosystem to bypass traditional prompt-level safeguards.
-
Secondary Vectors: Hallusquatting & Data Injection
- Hallusquatting involves registering domains that align with common AI hallucinations to capture traffic from incorrect tool calls.
- Agent Data Injection poisons external data sources, such as GitHub comments and product reviews, to manipulate agent logic.
- These vectors allow attackers to redirect AI agents toward malicious payloads without direct interaction with the user.
-
Scale of Impact: FakeGit Operation
- Cataloged approximately 7,600 malicious GitHub repositories as part of the broader FakeGit operation.
- Over 800 repositories were specifically designed as fraudulent AI Skills or MCP servers.
- Campaign activity reached its peak in April 2026, signaling a surge in AI-centric supply chain attacks.
-
Countermeasures & Mitigation
- Implementation of strict validation and allow-listing for MCP servers and AI skill installations.
- Deployment of isolated sandboxes for AI agent execution to prevent local system compromise.
- Integration of "Human-in-the-loop" (HITL) verification for all high-risk tool calls and external network requests.
Related posts
- TechNadu — AgentBaiting: Fake AI Skills Trick Claude Code, Gemini, and ChatGPT Into Spreading Malware
- rhisac.org — New AgentBaiting Campaign Delivers SmartLoader Via Fake AI Skills and MCP Servers
- Infosecurity-magazine
- tomshardware.com — New hack exploits AI hallucinations to trick agents into running malicious code — 'HalluSquatting' attack exploits a fundamental weakness in every available model
- feeds.feedburner.com — New Agent Data Injection Attack Can Make AI Agents Misclick or Run Attacker Commands
- Island
- Cybersecuritynews
- Lenet
- Techradar
- Mitiga