By Farukh Rakhimov, Head of Compliance, Data Protection and Information Security at AdTech Holding
Roughly 7,600 fake GitHub repositories, 6,600 fraudulent profiles and more than 14 million downloads: that is the scale of FakeGit, a malware campaign documented by Island in July 2026. Over 800 repositories impersonated AI skills and MCP servers, distributing SmartLoader and the StealC infostealer.
Gemini and ChatGPT independently suggested the same malicious walmart-mcp repository. The agents found the attacker’s project and handed users installation instructions.
Attackers no longer need to deceive users directly. They can deceive the assistants users trust.
First, agents process instructions and external information as text. A malicious instruction hidden in a README, webpage or tool description may be interpreted as something to obey rather than analyze. This is indirect prompt injection.
Security researcher Simon Willison calls the combination of three conditions the lethal trifecta: access to valuable information, exposure to untrusted external content and the ability to send data outside the system.
Other attacks exploit something simpler: fabricated trust signals. Stars, downloads, contributor histories and registry listings can make malicious software appear legitimate.
In the FakeGit campaign, attackers created convincing repositories with realistic documentation and distributed them through public registries.
Gemini and ChatGPT independently recommended the same fake Walmart MCP connector because it appeared relevant and credible.
The repositories distributed SmartLoader, which downloaded StealC to steal browser credentials, cookies, active sessions and cryptocurrency wallet data.
The agents were not compromised. They simply recommended software whose apparent credibility had been manufactured.
Source link







