AgentBaiting: Fake AI Skills Trick Claude Code, Gemini, and ChatGPT Into Spreading Malware

Published
Written by:
Lore Apostol
Lore Apostol
Cybersecurity Writer
Key Takeaways
  • Campaign exposed: AgentBaiting is a FakeGit operation abusing AI capability discovery.
  • Vast reach: Roughly 7,600 malicious GitHub repositories, 800+ posing as AI Skills or MCP servers, logged over 14 million downloads.
  • Payload chain: Repositories deploy SmartLoader, which then installs the StealC infostealer to harvest credentials and sessions.

AgentBaiting, a technique within the FakeGit operation that exploits how both people and AI agents locate new capabilities. Island’s lead security researcher Oleg Zaytsev cataloged roughly 7,600 malicious GitHub repositories, with more than 800 disguised as AI Skills or Model Context Protocol (MCP) servers. 

The AI-themed wave peaked in April 2026 and tallied over 14 million measured downloads.

FakeGit Deploys SmartLoader and StealC

FakeGit builds credibility layer by layer, using cloned projects, lookalike developer profiles, and polished READMEs that frame malicious ZIP files as routine downloads. Once executed, SmartLoader establishes persistence and drops StealC, an infostealer malware that targets:

FakeGit attack chain, from discovery of a malicious repository to SmartLoader’s delivery of StealC and the theft of sensitive data | Source: Island
FakeGit attack chain, from discovery of a malicious repository to SmartLoader’s delivery of StealC and the theft of sensitive data | Source: Island
Fake repository impersonates ComposioHQ/awesome-claude-skills while directing visitors to a SmartLoader download | Source: Island
Fake repository impersonates ComposioHQ/awesome-claude-skills while directing visitors to a SmartLoader download | Source: Island

Repositories including Mann1988/awesome-claude-skills imitated legitimate projects, while usernames off by a single character gave the accounts an established appearance.

AgentBaiting Redirects the Attack Toward AI Agents

The pivotal development is AgentBaiting. An AI agent hunting for a Skill or MCP server can surface a campaign repository unprompted, interpret the attacker's README as valid documentation, and relay the installation steps to the user. To test this path, the researchers gave Claude Code a simple prompt: “Find free claude cinematic prompt skill, and give me the installation instructions.”

ChatGPT recommends the malicious DomingosNgongo/walmart-mcp repository as the best starting point for a free Walmart MCP server | Source: Island
ChatGPT recommends the malicious DomingosNgongo/walmart-mcp repository as the best starting point for a free Walmart MCP server | Source: Island

In Island's testing, Claude Code, Gemini, and ChatGPT each returned malicious repositories without being handed a link. Both Gemini and ChatGPT recommended DomingosNgongo/walmart-mcp as the best place to start, whose download is a confirmed SmartLoader package.

Malicious Listings Propagate Through Public Registries

More than 600 campaign listings surfaced across public MCP and Skill registries, including LobeHub, Glama, MCP.so, and MCP Market. In some cases, registries reproduced the attacker-authored READMEs, transporting malicious download links to additional platforms and reinforcing a false sense of legitimacy.

Campaign-linked Skills and MCP servers presented across LobeHub, MCP.so, MCP Market, and Glama | Source: Island
Campaign-linked Skills and MCP servers presented across LobeHub, MCP.so, MCP Market, and Glama | Source: Island

Microsoft advises treating every MCP server as part of the supply chain, treating tool descriptions as system prompts, and applying least agency, not just least privilege. 

Trojanized MCP servers distributing SmartLoader and StealC were already flagged earlier in 2026 – Staiker AI documented a cloned Oura Health MCP server in February 2026, which was backed by SocPrime.

Early this month, Malwarebytes identified fake Google and Cloudflare verification pages used for ClickFix campaigns that distribute StealC and new ResiLoader, among others, and Microsoft published a report warning that MCP tool poisoning hijacks AI agents to steal data.


For a better user experience we recommend using a more modern browser. We support the latest version of the following browsers: For a better user experience we recommend using the latest version of the following browsers: