h.sHamid Samir
All stories

AI agents are becoming a new malware distribution channel

The FakeGit campaign shows how AI agents can recommend convincing but malicious repositories, exploiting fabricated trust signals, indirect prompt injection, and broad tool permissions.

AI agents do more than generate text. Some search the web and software repositories, recommend tools, and execute commands. Those capabilities create a new supply-chain attack path: instead of deceiving a user directly, an attacker can manipulate the information an agent relies on when deciding what to recommend or run.

FakeGit and AgentBaiting

According to security company Island, the FakeGit operation created roughly 7,600 malicious GitHub repositories through about 6,600 profiles. More than 800 posed as AI skills or MCP servers, while measured downloads of release assets in part of the wider campaign exceeded 14 million. The repositories distributed SmartLoader, which then installed the StealC information stealer.

Island says its tests found assistants including ChatGPT, Gemini, and Claude Code surfacing malicious campaign repositories when asked to find capabilities, without being given direct links. That does not mean the models themselves were compromised. The agents treated manufactured credibility, convincing documentation, and registry exposure as signs of legitimacy.

Why agents are exposed

First, an agent often receives both instructions and external content as text. A malicious instruction hidden in a README, webpage, or tool description may be interpreted as something to follow rather than data to analyse—an indirect prompt-injection problem. Second, an agent may be able to act on that text by installing packages, running code, or accessing email and organisational data.

Risk is greatest when three conditions coincide: access to valuable information, exposure to untrusted content, and the ability to send data outside the system. Attackers can also fabricate stars, download counts, contributor histories, and registry listings. Popularity is a discovery signal, not proof of security.

Recurring attack patterns

  • Tool poisoning: instructions hidden in an MCP tool description can influence how an agent uses another connector. This has been demonstrated in research, but not every proof of concept represents a confirmed real-world breach.
  • Malicious updates: software may behave normally for several versions and add harmful code later. A counterfeit package called postmark-mcp added a hidden BCC recipient that copied outgoing email; Postmark stated that the package was not its product.
  • Changing external resources: a package can remain unchanged while a linked webpage or dependency later begins serving malicious installation instructions.
  • Untrusted repository execution: documented Claude Code vulnerabilities showed that older versions could execute project-controlled commands or expose API credentials before the user confirmed trust. The reported flaws were fixed in later releases.
  • ClickFix: malicious commands are presented as ordinary prerequisites in README or SKILL.md files, persuading users to run the malware themselves.

Reducing the risk

Agents should run with least privilege, and software installation or sensitive execution should require human approval. Teams can also restrict tools to trusted publishers and registries, pin versions, review update diffs, isolate execution environments, limit outbound network access, and monitor what agents send.

The lesson is not that every AI recommendation is unsafe. It is that an agent's recommendation cannot replace verification of provenance, code, permissions, and runtime behaviour. The more authority an agent receives, the more important it becomes to validate the sources it reads and the tools it executes.

تصویر اصلی گزارش درباره توزیع بدافزار از طریق عامل‌های هوش مصنوعی
تصویر اصلی گزارش درباره توزیع بدافزار از طریق عامل‌های هوش مصنوعی

Source: AI News