Back to all lessons
Awareness Lessons
3 months ago

FakeGit Campaign Weaponizes 7,600 GitHub Repos to Hijack AI Agents

The FakeGit campaign exploits the rapidly growing AI tool ecosystem by flooding public registries with nearly 7,600 malicious GitHub repositories masquerading as legitimate AI skills and MCP servers. A novel 'AgentBaiting' technique manipulates AI agents such as Claude, Gemini, and ChatGPT into autonomously discovering and executing malicious code without any human interaction, fundamentally bypassing traditional user-awareness defenses. With over 14 million downloads recorded, this attack demonstrates how supply chain poisoning scales exponentially when AI agents become unwitting distribution vectors. The campaign highlights a critical trust gap in public AI tool registries, where provenance and integrity verification mechanisms remain immature, enabling attackers to establish false credibility at scale.

Tactical Insight

Immediate actions

  • Audit any AI skills, MCP servers, or third-party repositories currently integrated into your AI pipelines for signs of compromise or suspicious provenance.
  • Block or sandbox AI agent access to public registries until repositories can be verified against known-good sources.
  • Report and flag suspicious MCP/Skill registry listings to platform maintainers to accelerate takedowns.

Long-term improvements

  • Implement a verified allow-list policy for all AI tools and repositories permitted to execute within your environment.
  • Enforce cryptographic signing and provenance checks (e.g., Sigstore/SLSA) for all third-party AI components before integration.
  • Establish a formal AI supply chain risk management process that reviews new tool adoptions through a security approval workflow.

Detection measures

  • Monitor AI agent activity logs for unexpected outbound connections or execution of newly discovered, unvetted repositories.
  • Deploy SIEM rules to alert on mass repository cloning patterns or execution of payloads originating from public code-hosting platforms.
  • Integrate threat intelligence feeds that track malicious GitHub repositories and MCP registry abuse into your security tooling.