AgentBaiting Campaign Exploits AI Skills to Distribute Malware

Cybersecurity researchers have uncovered a sophisticated malware campaign, dubbed ‘AgentBaiting,’ that leverages counterfeit AI skills and Model Context Protocol (MCP) servers to disseminate the SmartLoader malware. This operation exploits the trust users place in AI integrations by distributing malicious code through seemingly legitimate GitHub repositories and public capability catalogs.

The campaign employs deceptive tactics to lure victims into downloading ZIP archives presented as useful installers. Once extracted and executed, these files install malware instead of the advertised AI tools. This method capitalizes on the growing reliance on AI extensions, turning routine searches for AI integrations into potential security risks.

Island researchers, while monitoring the broader FakeGit operation, identified approximately 7,600 malicious repositories created by around 6,600 profiles. Notably, over 800 of these repositories posed as AI skills or MCP servers. The AI-focused wave of this campaign intensified in March and peaked in April 2026, with malicious projects appearing more than 600 times across public AI registries and catalogs. Researchers also recorded over 14 million downloads from release assets in about 200 campaign repositories.

FakeGit enhances its credibility by replicating legitimate projects, creating lookalike accounts, providing convincing documentation, and generating modest engagement numbers. For instance, one lure mimicked the name and positioning of a popular Claude Skills collection, offering a confirmed SmartLoader ZIP archive as the download. This approach mirrors earlier fake GitHub malware delivery activities that exploited familiar development workflows to gain trust.

The lures target both personal and business tasks, including email, messaging, analytics, build systems, cloud services, and developer tools. Their names are crafted to make downloads appear relevant to daily work, thereby reducing suspicion. Island researchers found that 62 malicious repositories were positioned for enterprise or developer-internal use, while nearly two-thirds of MCP lures claimed to connect cloud services, databases, or APIs.

One example is a repository named ’45d5r/databricks-mcp-server,’ which advertises an enterprise integration and provides a download button. However, the linked archive contains a command launcher, a renamed LuaJIT-style runtime, and an obfuscated Lua program disguised as a text file. Executing the launcher activates the concealed payload instead of installing an MCP server.

Related variants of this attack can hide their console windows, locate their command server through a value stored in a Polygon smart contract, create scheduled-task persistence, and retrieve encrypted stages from GitHub.

This campaign underscores the evolving tactics of cybercriminals who exploit the trust in AI tools and open-source platforms. As AI integrations become more prevalent, users and organizations must exercise heightened vigilance when downloading and installing such tools. Verifying the authenticity of repositories, scrutinizing documentation, and employing robust security measures are essential steps to mitigate the risks posed by such sophisticated malware campaigns.