← Back to Daily Briefing

AgentBaiting is a strategic environmental poisoning campaign, part of the larger "FakeGit" operation, targeting agentic AI frameworks including Claude Code, Gemini, and ChatGPT. Attackers leverage malicious Model Context Protocol (MCP) servers and fraudulent AI "skills" to deceive agents into installing malware or executing unauthorized remote commands. The attack surface is expanded via "Hallusquatting"—registering domains that match AI-generated hallucinations—and "Agent Data Injection," utilizing poisoned GitHub comments and product reviews to manipulate agent decision-making. Researchers have identified approximately 7,600 malicious GitHub repositories, with over 800 specifically masquerading as AI tools to facilitate remote code execution (RCE) and unauthorized system access.

  • Threat Model: Environmental Poisoning

    • Shift from traditional prompt injection to "environmental poisoning," targeting the external tools and extensions AI agents rely on.
    • Exploits the inherent trust agentic LLMs place in Model Context Protocol (MCP) servers and "skill" definitions.
    • Aims to trick AI agents into performing unauthorized actions, such as running malicious shells or making unauthorized purchases.
  • Attack Mechanics: MCP and Skillgate

    • Deployment of fake MCP servers that mimic legitimate capabilities to deceive agentic AI into executing remote commands.
    • "Skillgate" methodology utilizes poisoned AI instruction files to trick models into installing malicious third-party tools.
    • Attackers weaponize the AI extension ecosystem to bypass traditional prompt-level safeguards.
  • Secondary Vectors: Hallusquatting & Data Injection

    • Hallusquatting involves registering domains that align with common AI hallucinations to capture traffic from incorrect tool calls.
    • Agent Data Injection poisons external data sources, such as GitHub comments and product reviews, to manipulate agent logic.
    • These vectors allow attackers to redirect AI agents toward malicious payloads without direct interaction with the user.
  • Scale of Impact: FakeGit Operation

    • Cataloged approximately 7,600 malicious GitHub repositories as part of the broader FakeGit operation.
    • Over 800 repositories were specifically designed as fraudulent AI Skills or MCP servers.
    • Campaign activity reached its peak in April 2026, signaling a surge in AI-centric supply chain attacks.
  • Countermeasures & Mitigation

    • Implementation of strict validation and allow-listing for MCP servers and AI skill installations.
    • Deployment of isolated sandboxes for AI agent execution to prevent local system compromise.
    • Integration of "Human-in-the-loop" (HITL) verification for all high-risk tool calls and external network requests.

Related posts

  1. TechNadu — AgentBaiting: Fake AI Skills Trick Claude Code, Gemini, and ChatGPT Into Spreading Malware
  2. rhisac.org — New AgentBaiting Campaign Delivers SmartLoader Via Fake AI Skills and MCP Servers
  3. gbhackers.com — Claude Opus 5 Finds Software Vulnerabilities While Blocking Exploit Generation
  4. vibegraveyard.ai — Malicious issue requests bypassed coding-agent guardrails in 66.5% of tests
  5. www.newser.com — Anthropic AI Test Models Go Rogue, Breach 3 Companies
  6. simplysecuregroup.com — Anthropic’s Claude breached 3 orgs, uploaded PyPI malware during tests
  7. bleepingcomputer.com — Anthropic's Claude breached 3 orgs, uploaded PyPI malware during tests
  8. Cybersecurity News — Anthropic Confirms Claude Hacked 3 Organizations by Breaking Test Environment
  9. TechNadu — Anthropic Says Claude Models Opus 4.7, Mythos 5, and a Research Model Broke Out of Test Environments and Hacked Real Companies
  10. itpro.com — Anthropic joins OpenAI in admitting loss of control in cybersecurity tests
  11. adversa.ai — Top Agentic AI security resources — August 2026
  12. Infosecurity-magazine
  13. tomshardware.com — New hack exploits AI hallucinations to trick agents into running malicious code — 'HalluSquatting' attack exploits a fundamental weakness in every available model
  14. feeds.feedburner.com — New Agent Data Injection Attack Can Make AI Agents Misclick or Run Attacker Commands
  15. Island
  16. Cybersecuritynews
  17. Lenet
  18. Techradar
  19. Mitiga
  20. Researchgate
  21. Cryptopolitan
  22. Github
  23. Arxiv
  24. Futurice
  25. Themoonlight
  26. Asanify
  27. Tomshardware
  28. hackernews.com — Investigating three real-world incidents in our cybersecurity evaluations
  29. cyberscoop.com — Anthropic says its AI accidentally hacked three companies during safety tests
  30. Businessinsider
  31. Reddit
  32. Straitstimes
  33. Ft
  34. Community
  35. Mashable
  36. Economictimes
  37. Foxbusiness
  38. Venturebeat
  39. Cryptobriefing
  40. Eu
  41. Japantimes
  42. Kfgo
  43. Dobetter
  44. Cbc
  45. Hiddenlayer
  46. Forbes
  47. Aijourn
  48. Linx
  49. Zenity
  50. Nhimg
  51. Cltc
  52. Labs
  53. Genai
  54. Simbian

LINK COPIED TO CLIPBOARD