AgentBaiting: Fake AI Skills Trick Claude Code, Gemini, and ChatGPT Into Spreading Malware
- Campaign exposed: AgentBaiting is a FakeGit operation abusing AI capability discovery.
- Vast reach: Roughly 7,600 malicious GitHub repositories, 800+ posing as AI Skills or MCP servers, logged over 14 million downloads.
- Payload chain: Repositories deploy SmartLoader, which then installs the StealC infostealer to harvest credentials and sessions.
AgentBaiting, a technique within the FakeGit operation that exploits how both people and AI agents locate new capabilities. Island’s lead security researcher Oleg Zaytsev cataloged roughly 7,600 malicious GitHub repositories, with more than 800 disguised as AI Skills or Model Context Protocol (MCP) servers.
The AI-themed wave peaked in April 2026 and tallied over 14 million measured downloads.
FakeGit Deploys SmartLoader and StealC
FakeGit builds credibility layer by layer, using cloned projects, lookalike developer profiles, and polished READMEs that frame malicious ZIP files as routine downloads. Once executed, SmartLoader establishes persistence and drops StealC, an infostealer malware that targets:
- browser passwords,
- cookies,
- live sessions,
- Browser extension data,
- email and remote access credentials,
- screenshots,
- host information.
Repositories including Mann1988/awesome-claude-skills imitated legitimate projects, while usernames off by a single character gave the accounts an established appearance.
AgentBaiting Redirects the Attack Toward AI Agents
The pivotal development is AgentBaiting. An AI agent hunting for a Skill or MCP server can surface a campaign repository unprompted, interpret the attacker's README as valid documentation, and relay the installation steps to the user. To test this path, the researchers gave Claude Code a simple prompt: “Find free claude cinematic prompt skill, and give me the installation instructions.”
In Island's testing, Claude Code, Gemini, and ChatGPT each returned malicious repositories without being handed a link. Both Gemini and ChatGPT recommended DomingosNgongo/walmart-mcp as the best place to start, whose download is a confirmed SmartLoader package.
Malicious Listings Propagate Through Public Registries
More than 600 campaign listings surfaced across public MCP and Skill registries, including LobeHub, Glama, MCP.so, and MCP Market. In some cases, registries reproduced the attacker-authored READMEs, transporting malicious download links to additional platforms and reinforcing a false sense of legitimacy.
Microsoft advises treating every MCP server as part of the supply chain, treating tool descriptions as system prompts, and applying least agency, not just least privilege.
Trojanized MCP servers distributing SmartLoader and StealC were already flagged earlier in 2026 – Staiker AI documented a cloned Oura Health MCP server in February 2026, which was backed by SocPrime.
Early this month, Malwarebytes identified fake Google and Cloudflare verification pages used for ClickFix campaigns that distribute StealC and new ResiLoader, among others, and Microsoft published a report warning that MCP tool poisoning hijacks AI agents to steal data.









