AI Agents Are Becoming a New Malware Distribution Channel
800+ fake repos. 14M downloads. AI agents are now a malware vector — and most teams don't know to look.

Why it matters
Agent ecosystems (GitHub, MCP servers, skill marketplaces) are becoming attack surfaces. Security and procurement teams need to treat agent dependencies with the same rigor as container images — this is a new class of supply-chain risk.
The key facts
6 to knowFakeGit campaign: 7,600 fake GitHub repos, 6,600 fraudulent profiles
14+ million downloads of malware-laced agent components
800+ repos impersonated AI skills and MCP (Model Context Protocol) servers
SmartLoader malware distributed via agent ecosystems
Campaign documented by Island, July 2026
Author: Farukh Rakhimov, Head of Compliance/Security at AdTech Holding
Go to the source
AI Newsartificialintelligence-news.com
Publisher excerpt: By Farukh Rakhimov, Head of Compliance, Data Protection and Information Security at AdTech Holding Roughly 7,600 fake GitHub repositories, 6,600 fraudulent profiles and more than 14 million downloads: that is the scale of FakeGit, a malware campaign documented by Island in July 2026. Over 800…