FakeGit Campaign: Malicious GitHub Repos Impersonating AI Skills/MCP Servers Distributing SmartLoader
highAgentSupply ChainResearchers identified roughly 7,600 malicious GitHub repositories, with over 800 masquerading as AI 'skills' or Model Context Protocol (MCP) servers, used to distribute the SmartLoader malware family in a campaign dubbed FakeGit. The attackers use copied projects, lookalike developer profiles, convincing READMEs, and malicious ZIP downloads to trick developers into executing malware, exploiting growing trust in AI/MCP tooling as a lure.
Updated Jul 21, 2026