← Back to Daily Briefing

AgentBaiting is a strategic environmental poisoning campaign, part of the larger "FakeGit" operation, targeting agentic AI frameworks including Claude Code, Gemini, and ChatGPT. Attackers leverage malicious Model Context Protocol (MCP) servers and fraudulent AI "skills" to deceive agents into installing malware or executing unauthorized remote commands. The attack surface is expanded via "Hallusquatting"—registering domains that match AI-generated hallucinations—and "Agent Data Injection," utilizing poisoned GitHub comments and product reviews to manipulate agent decision-making. Researchers have identified approximately 7,600 malicious GitHub repositories, with over 800 specifically masquerading as AI tools to facilitate remote code execution (RCE) and unauthorized system access.

  • Threat Model: Environmental Poisoning

    • Shift from traditional prompt injection to "environmental poisoning," targeting the external tools and extensions AI agents rely on.
    • Exploits the inherent trust agentic LLMs place in Model Context Protocol (MCP) servers and "skill" definitions.
    • Aims to trick AI agents into performing unauthorized actions, such as running malicious shells or making unauthorized purchases.
  • Attack Mechanics: MCP and Skillgate

    • Deployment of fake MCP servers that mimic legitimate capabilities to deceive agentic AI into executing remote commands.
    • "Skillgate" methodology utilizes poisoned AI instruction files to trick models into installing malicious third-party tools.
    • Attackers weaponize the AI extension ecosystem to bypass traditional prompt-level safeguards.
  • Secondary Vectors: Hallusquatting & Data Injection

    • Hallusquatting involves registering domains that align with common AI hallucinations to capture traffic from incorrect tool calls.
    • Agent Data Injection poisons external data sources, such as GitHub comments and product reviews, to manipulate agent logic.
    • These vectors allow attackers to redirect AI agents toward malicious payloads without direct interaction with the user.
  • Scale of Impact: FakeGit Operation

    • Cataloged approximately 7,600 malicious GitHub repositories as part of the broader FakeGit operation.
    • Over 800 repositories were specifically designed as fraudulent AI Skills or MCP servers.
    • Campaign activity reached its peak in April 2026, signaling a surge in AI-centric supply chain attacks.
  • Countermeasures & Mitigation

    • Implementation of strict validation and allow-listing for MCP servers and AI skill installations.
    • Deployment of isolated sandboxes for AI agent execution to prevent local system compromise.
    • Integration of "Human-in-the-loop" (HITL) verification for all high-risk tool calls and external network requests.

Related posts

  1. Hack Noon — Agentic SRE: What Happens When AI Doesn't Just Suggest Fixes, It Applies Them
  2. TechNadu — AgentBaiting: Fake AI Skills Trick Claude Code, Gemini, and ChatGPT Into Spreading Malware
  3. rhisac.org — New AgentBaiting Campaign Delivers SmartLoader Via Fake AI Skills and MCP Servers
  4. arXiv (Computer Science - Cryptography and Security) — JailMeter: An Evidence-Based Evaluation Framework for Jailbreak Attacks on Large Language Models
  5. techtarget.com — OpenAI models escape containment, hack Hugging Face
  6. techjacksolutions.com — Ghostcommit: Prompt Injection via Images Targets AI Coding Tools for Secret Theft
  7. it.slashdot.org — OpenAI's Rogue Agent Went Unnoticed For a Week
  8. serisec.com — Researcher Claims Working Jailbreak on Top AI Models Including GPT-5.6, Claude Opus 5, and Fable
  9. SC Media — Phishing the agent: Why identity controls are essential to secure and manage AIs
  10. gbhackers.com — Claude Opus 5 Finds Software Vulnerabilities While Blocking Exploit Generation
  11. vibegraveyard.ai — Malicious issue requests bypassed coding-agent guardrails in 66.5% of tests
  12. it.slashdot.org — OpenAI's Rogue AI Agent Hacked More Than Just Hugging Face
  13. DEV Community — OpenAI Says Two API Settings Tripled GPT-5.6 Sol's ARC-AGI-3 Score
  14. www.newser.com — Anthropic AI Test Models Go Rogue, Breach 3 Companies
  15. simplysecuregroup.com — Anthropic’s Claude breached 3 orgs, uploaded PyPI malware during tests
  16. bleepingcomputer.com — Anthropic's Claude breached 3 orgs, uploaded PyPI malware during tests
  17. Cybersecurity News — Anthropic Confirms Claude Hacked 3 Organizations by Breaking Test Environment
  18. TechNadu — Anthropic Says Claude Models Opus 4.7, Mythos 5, and a Research Model Broke Out of Test Environments and Hacked Real Companies
  19. itpro.com — Anthropic joins OpenAI in admitting loss of control in cybersecurity tests
  20. adversa.ai — Top Agentic AI security resources — August 2026
  21. Schneier on Security — Anthropic’s Opus 5 Is Better at Resisting Prompt Injection
  22. it.slashdot.org — OpenAI Finds Evidence Other AI Agents Escaped Containment
  23. adversa.ai — Nine AI coding agent incidents that ended with deleted data
  24. simplysecuregroup.com — Mythos 5 and GPT-5.6-Sol Agents Went Beyond Their Cyber Test and Targeted the Real World
  25. arXiv (Computer Science - Cryptography and Security) — DenialRAG: Single-Document RAG Poisoning via Embedded Parametric Denial
  26. hackernews.com — Beating GPT-5.6 Sol on retrieval with 100x cheaper open models
  27. Check Point Research — Three AI security disclosures, fourteen days: what the warnings signs are telling us
  28. serisec.com — AI Browsers Vulnerable to ‘PleaseFix’ Zero-Click Agent Hijacking
  29. sec-tec.co.uk — The Register: AI struggles to patch vulns without adult supervision
  30. feeds.feedburner.com — Claude Code and Gemini CLI Flaws Let a GitHub Issue Reach CI Workflow Secrets
  31. csoonline.com — Trojanized AI skills gain 1.7M installs in agent-targeted attack
  32. TechNadu — Weekly Cybersecurity Roundup: Entering an Era When AI Agents Take Unapproved Paths as Security Teams Race to Trace Them
  33. Cybersecurity News — Claude Opus 5 Cuts Indirect Prompt Injection Attack Success to 2% in New Benchmark Analysis
  34. Check Point Research — Native AI Security Comes to Claude: Why Anthropic’s Inference Hooks Matter
  35. arXiv (Computer Science - Cryptography and Security) — When Grammar Guides the Attack: Uncovering Control-Plane Vulnerabilities in LLMs with Structured Output
  36. arXiv (Computer Science - Cryptography and Security) — Evaluating Jailbreaking Vulnerabilities in LLMs Deployed as Assistants for Smart Grid Operations: A Benchmark Against NERC Standards
  37. gbhackers.com — OpenAI Launches GPT-5.6-Cyber to Find Zero-Day Vulnerabilities and Develop Exploit Chains
  38. feeds.feedburner.com — OpenAI Launches GPT-5.6-Cyber with Reduced Safeguards for Exploit Development
  39. SOCFortress — The Hidden Risks of AI-Generated Vulnerability Patches
  40. NSFOCUS — AI Security Incident Case: AISI Reveals AI Agents Autonomously Attacking Real People and Systems During Security Testing
  41. arXiv (Computer Science - Cryptography and Security) — When Agents Talk: Honeytokens under Shared Memory
  42. arXiv (Computer Science - Cryptography and Security) — Attention is All You Need to Defend Against Indirect Prompt Injection Attacks in LLMs
  43. forkast.news — Grok 4.6 Matches GPT-5.6 Sol on Composite Intelligence — But SpaceXAI Still Won’t Document What It Does Autonomously
  44. arXiv (Computer Science - Cryptography and Security) — RAGSieve: Self-Referenced Local Contrast for Knowledge-Poison Detection in Retrieval-Augmented Generation
  45. eSecurity Planet — Claude Agents Started a ‘Turf War’ That Escalated to Self-Replicating Malware
  46. NewsBytes — Zhipu's GLM-5.3 AI model outperforms Anthropic's Mythos 5 in cybersecurity
  47. blackhatnews.tokyo — PromptJacking:Claude Desktopの重大なRCE脆弱性が「質問」を「攻撃」に変える
  48. arXiv (Computer Science - Cryptography and Security) — Evaluating Agentic Learning Harness Capabilities Without Labels via the Scaling Hypothesis
  49. Malware News — Teaching AI to Reason Through Detection Triage
  50. arXiv (Computer Science - Cryptography and Security) — WeSCE: A Benchmark for Measuring Security Drift in LLM-Driven Code Editing
  51. arXiv (Computer Science - Cryptography and Security) — Securing AI-Generated Code: A Just-in-Time Vulnerability Detection and Remediation Pipeline
  52. feeds.feedburner.com — AI "Mind Viruses" Can Spread Between Agents Through Persistent Prompt Files
  53. Google Cloud Security Community — Webinar 9/30: CodeMender: AI Code Security Agent
  54. datawater.com — AI Agent Mind Virus + Turf War: Anthropic Research Shows Self-Propagating Payloads Spread Between Agents via Harness State Files (63% Success Rate, Payloads Published on GitHub) — and Claude Agents Given Conflicting Goals Deployed Malware Against Each Other Without Being Told To
  55. thenewstack.io — Grok, Claude, and Hermes agents get job titles — and persistent permissions
  56. news.ycombinator.com — Show HN: AgentSight – eBPF observability for AI agents, no code changes
  57. Dark Reading — AI Browsers Vulnerable to 'PleaseFix' Zero-Click Agent Hijacking
  58. Dark Reading — 'Turf War' Between Claude Agents Leads to Self-Replicating Malware
  59. techjacksolutions.com — AI Agent Identity Is a Structural Gap, Not a Configuration Problem: What Security Teams Must Do Now
  60. arXiv (Computer Science - Cryptography and Security) — Democratizing Agent Deployment Safety: A Structural Monitoring Approach
  61. Hack Noon — Your Agent Doesn't Need Better Retries, It Needs a Circuit Breaker
  62. gbhackers.com — Claude Code Auto Mode Blocks 89% of Dangerous Commands and Prompt Injection Attacks
  63. Dark Reading — No Perfect Fix for AI Browser Prompt Injection Flaws
  64. Infosecurity-magazine
  65. Hashicorp
  66. Cycode
  67. tomshardware.com — New hack exploits AI hallucinations to trick agents into running malicious code — 'HalluSquatting' attack exploits a fundamental weakness in every available model
  68. feeds.feedburner.com — New Agent Data Injection Attack Can Make AI Agents Misclick or Run Attacker Commands
  69. Island
  70. Cybersecuritynews
  71. Lenet
  72. Techradar
  73. Mitiga
  74. Mezmo
  75. 67ailab
  76. Novaaiops
  77. Novelvista
  78. Mfdela
  79. Kodekloud
  80. Sherlocks
  81. Jobzonerisk
  82. hackernews.com — OpenAI and Hugging Face partner to address security incident
  83. news.ycombinator.com — OpenAI’s accidental attack against Hugging Face is science fiction that happened
  84. DEV Community — Claude Opus 5 is Here: What Developers Need to Know About the Safety "Fine Print"
  85. helpnetsecurity.com — Hugging Face breach reignites open-weights debate, raises liability questions
  86. news.ycombinator.com — Anatomy of a Frontier Lab Agent Intrusion: A Technical Timeline of the Incident
  87. Thehackernews
  88. Researchgate
  89. Cryptopolitan
  90. Github
  91. Arxiv
  92. Futurice
  93. Themoonlight
  94. Asanify
  95. Computerworld
  96. Csoonline
  97. Coalitionforsecureai
  98. Youtube
  99. Techcommunity
  100. Zscaler
  101. Officegarageitpro
  102. Auth0
  103. Idsalliance
  104. Biometricupdate
  105. Insightpartners
  106. Cloudsecurityalliance
  107. Tomshardware
  108. hackernews.com — Investigating three real-world incidents in our cybersecurity evaluations
  109. cyberscoop.com — Anthropic says its AI accidentally hacked three companies during safety tests
  110. Businessinsider
  111. Reddit
  112. Straitstimes
  113. Ft
  114. Community
  115. Mashable
  116. Economictimes
  117. Foxbusiness
  118. Valueaddvc
  119. Mallory
  120. Reddit
  121. Deploymentsafety
  122. Labs
  123. Www-cdn
  124. Roo
  125. Neuraltrust
  126. Github
  127. Venturebeat
  128. Cryptobriefing
  129. Eu
  130. Japantimes
  131. Kfgo
  132. Dobetter
  133. Cbc
  134. Hiddenlayer
  135. Forbes
  136. Aijourn
  137. Linx
  138. Zenity
  139. Nhimg
  140. Cltc
  141. Labs
  142. Genai
  143. Simbian
  144. Securityboulevard
  145. The-decoder
  146. Synapsehd
  147. Noma
  148. Forbes
  149. Cbsnews
  150. Time
  151. Japantimes
  152. Facebook
  153. Mashable
  154. cyberscoop.com — AISI, OpenAI report more ‘unsanctioned’ model hacks
  155. bleepingcomputer.com — OpenAI, Anthropic AI agents targeted real people and systems in cyber tests
  156. Itnews
  157. Reddit
  158. Aisi
  159. Bworldonline
  160. Facebook
  161. Dailysecurity
  162. Promptfoo
  163. Usenix
  164. Emergentmind
  165. Grafyn
  166. Aclanthology
  167. cybersecuritydive.com — OpenAI warns autonomous hacks are ‘watershed moment for computer security’
  168. gbhackers.com — Critical Flaws in Claude Code, Gemini CLI, and OpenAI Codex Enable RCE and Supply Chain Attacks
  169. csoonline.com — Human oversight is still critical as AI patching tools miss security risks
  170. Labs
  171. Reddit
  172. Esecurityplanet
  173. Devops
  174. Medium
  175. cyberscoop.com — More than half of AI-generated patches are broken
  176. Daily
  177. Labs
  178. Arxiv
  179. Labs
  180. Reddit
  181. Github
  182. Python
  183. Theguardian
  184. Itpro
  185. Zenity
  186. Towardsdatascience
  187. Jackmaguire
  188. Youtube
  189. 1password
  190. Labs
  191. Engadget
  192. Openai
  193. thenewstack.io — OpenAI built a model it doesn’t want most people to use
  194. Venturebeat
  195. Reddit
  196. Helpnetsecurity
  197. Poloniex
  198. Eesel
  199. Facebook
  200. Trendingtopics
  201. Analyticsinsight
  202. Engadget
  203. Openai
  204. Timesofindia
  205. Defenseone
  206. Themoonlight
  207. Boozallen
  208. Researchgate
  209. Industrialcyber
  210. Sandia
  211. Csis
  212. Youtube
  213. News
  214. Frenos
  215. Blogs
  216. Pdxscholar
  217. Defendersinitiative
  218. Security
  219. News
  220. Arxiv
  221. Aquasec
  222. Youtube
  223. Neuraltrust
  224. Youtube
  225. Alluresecurity
  226. Enterprisedna
  227. Adsadvance
  228. Forkast
  229. Hcamag
  230. Cyberdaily
  231. Arxiv
  232. Edrm
  233. Patents
  234. Air-governance-framework
  235. Scouts
  236. Usenix
  237. Huggingface
  238. Orbit
  239. Dokumen
  240. App
  241. Lbank
  242. Unite
  243. Reddit
  244. Venturebeat
  245. The-independent
  246. Businessinsider
  247. Relvehq
  248. Anthropic
  249. Startupfortune
  250. Crowdstrike
  251. Corelight
  252. Cybersecurity-insiders
  253. Ndss-symposium
  254. Medium
  255. Youtube
  256. Reddit
  257. Daily
  258. Youtube
  259. Economictimes
  260. Alphaxiv
  261. Researchgate
  262. News
  263. Facebook
  264. Dark Reading — AI-Generated Patches Fail Half the Time

LINK COPIED TO CLIPBOARD