Cybersecurity researchers at Island have identified 7,600 malicious GitHub repositories using "AgentBaiting" tactics to trick AI coding assistants into recommending malware-laden software to unsuspecting software developers.
Key Points
- Attackers are using 7,600 fake GitHub repositories to distribute the SmartLoader and StealC malware, which exfiltrates passwords, cookies, and sensitive session data.
- The "AgentBaiting" technique exploits AI coding assistants like Claude Code, Gemini, and ChatGPT, causing them to autonomously recommend malicious repositories as legitimate tools.
- Malicious repositories are disguised as AI skills or Model Context Protocol (MCP) servers, targeting integrations for platforms like Docker, Jenkins, and Gmail.
- Researchers confirmed over 14 million downloads from approximately 200 of the identified repositories, with the campaign activity peaking in April.
- The attack chain begins with an obfuscated Lua payload that executes once a developer follows instructions found in the repository's README file.