← Back to Daily Briefing

AgentBaiting is a strategic environmental poisoning campaign, part of the larger "FakeGit" operation, targeting agentic AI frameworks including Claude Code, Gemini, and ChatGPT. Attackers leverage malicious Model Context Protocol (MCP) servers and fraudulent AI "skills" to deceive agents into installing malware or executing unauthorized remote commands. The attack surface is expanded via "Hallusquatting"—registering domains that match AI-generated hallucinations—and "Agent Data Injection," utilizing poisoned GitHub comments and product reviews to manipulate agent decision-making. Researchers have identified approximately 7,600 malicious GitHub repositories, with over 800 specifically masquerading as AI tools to facilitate remote code execution (RCE) and unauthorized system access.

  • Threat Model: Environmental Poisoning

    • Shift from traditional prompt injection to "environmental poisoning," targeting the external tools and extensions AI agents rely on.
    • Exploits the inherent trust agentic LLMs place in Model Context Protocol (MCP) servers and "skill" definitions.
    • Aims to trick AI agents into performing unauthorized actions, such as running malicious shells or making unauthorized purchases.
  • Attack Mechanics: MCP and Skillgate

    • Deployment of fake MCP servers that mimic legitimate capabilities to deceive agentic AI into executing remote commands.
    • "Skillgate" methodology utilizes poisoned AI instruction files to trick models into installing malicious third-party tools.
    • Attackers weaponize the AI extension ecosystem to bypass traditional prompt-level safeguards.
  • Secondary Vectors: Hallusquatting & Data Injection

    • Hallusquatting involves registering domains that align with common AI hallucinations to capture traffic from incorrect tool calls.
    • Agent Data Injection poisons external data sources, such as GitHub comments and product reviews, to manipulate agent logic.
    • These vectors allow attackers to redirect AI agents toward malicious payloads without direct interaction with the user.
  • Scale of Impact: FakeGit Operation

    • Cataloged approximately 7,600 malicious GitHub repositories as part of the broader FakeGit operation.
    • Over 800 repositories were specifically designed as fraudulent AI Skills or MCP servers.
    • Campaign activity reached its peak in April 2026, signaling a surge in AI-centric supply chain attacks.
  • Countermeasures & Mitigation

    • Implementation of strict validation and allow-listing for MCP servers and AI skill installations.
    • Deployment of isolated sandboxes for AI agent execution to prevent local system compromise.
    • Integration of "Human-in-the-loop" (HITL) verification for all high-risk tool calls and external network requests.

Related posts

  1. TechNadu — AgentBaiting: Fake AI Skills Trick Claude Code, Gemini, and ChatGPT Into Spreading Malware
  2. rhisac.org — New AgentBaiting Campaign Delivers SmartLoader Via Fake AI Skills and MCP Servers
  3. arXiv (Computer Science - Cryptography and Security) — JailMeter: An Evidence-Based Evaluation Framework for Jailbreak Attacks on Large Language Models
  4. techtarget.com — OpenAI models escape containment, hack Hugging Face
  5. techjacksolutions.com — Ghostcommit: Prompt Injection via Images Targets AI Coding Tools for Secret Theft
  6. it.slashdot.org — OpenAI's Rogue Agent Went Unnoticed For a Week
  7. serisec.com — Researcher Claims Working Jailbreak on Top AI Models Including GPT-5.6, Claude Opus 5, and Fable
  8. gbhackers.com — Claude Opus 5 Finds Software Vulnerabilities While Blocking Exploit Generation
  9. vibegraveyard.ai — Malicious issue requests bypassed coding-agent guardrails in 66.5% of tests
  10. it.slashdot.org — OpenAI's Rogue AI Agent Hacked More Than Just Hugging Face
  11. DEV Community — OpenAI Says Two API Settings Tripled GPT-5.6 Sol's ARC-AGI-3 Score
  12. www.newser.com — Anthropic AI Test Models Go Rogue, Breach 3 Companies
  13. simplysecuregroup.com — Anthropic’s Claude breached 3 orgs, uploaded PyPI malware during tests
  14. bleepingcomputer.com — Anthropic's Claude breached 3 orgs, uploaded PyPI malware during tests
  15. Cybersecurity News — Anthropic Confirms Claude Hacked 3 Organizations by Breaking Test Environment
  16. TechNadu — Anthropic Says Claude Models Opus 4.7, Mythos 5, and a Research Model Broke Out of Test Environments and Hacked Real Companies
  17. itpro.com — Anthropic joins OpenAI in admitting loss of control in cybersecurity tests
  18. adversa.ai — Top Agentic AI security resources — August 2026
  19. Schneier on Security — Anthropic’s Opus 5 Is Better at Resisting Prompt Injection
  20. it.slashdot.org — OpenAI Finds Evidence Other AI Agents Escaped Containment
  21. adversa.ai — Nine AI coding agent incidents that ended with deleted data
  22. simplysecuregroup.com — Mythos 5 and GPT-5.6-Sol Agents Went Beyond Their Cyber Test and Targeted the Real World
  23. hackernews.com — Beating GPT-5.6 Sol on retrieval with 100x cheaper open models
  24. Check Point Research — Three AI security disclosures, fourteen days: what the warnings signs are telling us
  25. serisec.com — AI Browsers Vulnerable to ‘PleaseFix’ Zero-Click Agent Hijacking
  26. feeds.feedburner.com — Claude Code and Gemini CLI Flaws Let a GitHub Issue Reach CI Workflow Secrets
  27. csoonline.com — Trojanized AI skills gain 1.7M installs in agent-targeted attack
  28. TechNadu — Weekly Cybersecurity Roundup: Entering an Era When AI Agents Take Unapproved Paths as Security Teams Race to Trace Them
  29. Cybersecurity News — Claude Opus 5 Cuts Indirect Prompt Injection Attack Success to 2% in New Benchmark Analysis
  30. Check Point Research — Native AI Security Comes to Claude: Why Anthropic’s Inference Hooks Matter
  31. arXiv (Computer Science - Cryptography and Security) — When Grammar Guides the Attack: Uncovering Control-Plane Vulnerabilities in LLMs with Structured Output
  32. arXiv (Computer Science - Cryptography and Security) — Evaluating Jailbreaking Vulnerabilities in LLMs Deployed as Assistants for Smart Grid Operations: A Benchmark Against NERC Standards
  33. gbhackers.com — OpenAI Launches GPT-5.6-Cyber to Find Zero-Day Vulnerabilities and Develop Exploit Chains
  34. feeds.feedburner.com — OpenAI Launches GPT-5.6-Cyber with Reduced Safeguards for Exploit Development
  35. NSFOCUS — AI Security Incident Case: AISI Reveals AI Agents Autonomously Attacking Real People and Systems During Security Testing
  36. arXiv (Computer Science - Cryptography and Security) — Attention is All You Need to Defend Against Indirect Prompt Injection Attacks in LLMs
  37. forkast.news — Grok 4.6 Matches GPT-5.6 Sol on Composite Intelligence — But SpaceXAI Still Won’t Document What It Does Autonomously
  38. eSecurity Planet — Claude Agents Started a ‘Turf War’ That Escalated to Self-Replicating Malware
  39. NewsBytes — Zhipu's GLM-5.3 AI model outperforms Anthropic's Mythos 5 in cybersecurity
  40. Dark Reading — AI Browsers Vulnerable to 'PleaseFix' Zero-Click Agent Hijacking
  41. gbhackers.com — Claude Code Auto Mode Blocks 89% of Dangerous Commands and Prompt Injection Attacks
  42. Dark Reading — No Perfect Fix for AI Browser Prompt Injection Flaws
  43. Infosecurity-magazine
  44. tomshardware.com — New hack exploits AI hallucinations to trick agents into running malicious code — 'HalluSquatting' attack exploits a fundamental weakness in every available model
  45. feeds.feedburner.com — New Agent Data Injection Attack Can Make AI Agents Misclick or Run Attacker Commands
  46. Island
  47. Cybersecuritynews
  48. Lenet
  49. Techradar
  50. Mitiga
  51. hackernews.com — OpenAI and Hugging Face partner to address security incident
  52. news.ycombinator.com — OpenAI’s accidental attack against Hugging Face is science fiction that happened
  53. DEV Community — Claude Opus 5 is Here: What Developers Need to Know About the Safety "Fine Print"
  54. helpnetsecurity.com — Hugging Face breach reignites open-weights debate, raises liability questions
  55. news.ycombinator.com — Anatomy of a Frontier Lab Agent Intrusion: A Technical Timeline of the Incident
  56. Thehackernews
  57. Researchgate
  58. Cryptopolitan
  59. Github
  60. Arxiv
  61. Futurice
  62. Themoonlight
  63. Asanify
  64. Tomshardware
  65. hackernews.com — Investigating three real-world incidents in our cybersecurity evaluations
  66. cyberscoop.com — Anthropic says its AI accidentally hacked three companies during safety tests
  67. Businessinsider
  68. Reddit
  69. Straitstimes
  70. Ft
  71. Community
  72. Mashable
  73. Economictimes
  74. Foxbusiness
  75. Valueaddvc
  76. Mallory
  77. Reddit
  78. Deploymentsafety
  79. Labs
  80. Www-cdn
  81. Roo
  82. Neuraltrust
  83. Github
  84. Venturebeat
  85. Cryptobriefing
  86. Eu
  87. Japantimes
  88. Kfgo
  89. Dobetter
  90. Cbc
  91. Hiddenlayer
  92. Forbes
  93. Aijourn
  94. Linx
  95. Zenity
  96. Nhimg
  97. Cltc
  98. Labs
  99. Genai
  100. Simbian
  101. Securityboulevard
  102. The-decoder
  103. Synapsehd
  104. Noma
  105. Forbes
  106. Cbsnews
  107. Time
  108. Japantimes
  109. Facebook
  110. Mashable
  111. cyberscoop.com — AISI, OpenAI report more ‘unsanctioned’ model hacks
  112. bleepingcomputer.com — OpenAI, Anthropic AI agents targeted real people and systems in cyber tests
  113. Itnews
  114. Reddit
  115. Aisi
  116. Bworldonline
  117. Facebook
  118. cybersecuritydive.com — OpenAI warns autonomous hacks are ‘watershed moment for computer security’
  119. gbhackers.com — Critical Flaws in Claude Code, Gemini CLI, and OpenAI Codex Enable RCE and Supply Chain Attacks
  120. Labs
  121. Reddit
  122. Esecurityplanet
  123. Devops
  124. Medium
  125. Daily
  126. Labs
  127. Arxiv
  128. Labs
  129. Reddit
  130. Github
  131. Python
  132. Theguardian
  133. Itpro
  134. Zenity
  135. Towardsdatascience
  136. Jackmaguire
  137. Youtube
  138. Labs
  139. Engadget
  140. Openai
  141. thenewstack.io — OpenAI built a model it doesn’t want most people to use
  142. Venturebeat
  143. Reddit
  144. Helpnetsecurity
  145. Poloniex
  146. Eesel
  147. Facebook
  148. Trendingtopics
  149. Analyticsinsight
  150. Engadget
  151. Openai
  152. Timesofindia
  153. Defenseone
  154. Themoonlight
  155. Boozallen
  156. Researchgate
  157. Industrialcyber
  158. Sandia
  159. Csis
  160. Youtube
  161. News
  162. Frenos
  163. Blogs
  164. Pdxscholar
  165. Neuraltrust
  166. Youtube
  167. Alluresecurity
  168. Enterprisedna
  169. Adsadvance
  170. Forkast
  171. Hcamag
  172. Cyberdaily
  173. Arxiv
  174. App
  175. Lbank
  176. Unite
  177. Reddit
  178. Venturebeat
  179. The-independent
  180. Businessinsider
  181. Relvehq
  182. Anthropic
  183. Startupfortune

LINK COPIED TO CLIPBOARD