AI Agents Compromised: FakeGit Breach Exposes Vulnerabilities in Trust-Through-Defaults Model
A recent security breach has exposed vulnerabilities in AI agents' trust-through-defaults model. The attack, codenamed FakeGit, exploits the tendency of autonomous coding agents like Claude Code and ChatGPT to discover and recommend external repositories. Over 7,600 malicious GitHub repositories have been identified, with over 800 posing as AI Skills or MCP servers.
The operation involves roughly 6,600 profiles and has generated over 14 million downloads across approximately 200 repositories. The attack chain is sophisticated: the fake repositories deliver a malicious ZIP file containing a LuaJIT loader, which then executes SmartLoader. This loader utilizes a Polygon smart contract for command-and-control communication, ultimately deploying the StealC info stealer.
The attack is not limited to GitHub, with over 600 listings identified across public registries such as LobeHub, Glama, MCP.so, and MCP Market. These registries inadvertently amplify the threat by mirroring the malicious READMEs, thereby carrying the harmful download links onto additional platforms.