HomeIntelligenceBrief
BREACH BRIEF🟠 High ThreatIntel

AI Agents Served Malicious GitHub Repos in FakeGit Campaign, Delivering SmartLoader Malware

Researchers uncovered a FakeGit operation that created thousands of malicious GitHub repositories, tricking AI agents like Claude, Gemini, and ChatGPT into recommending them. The repos deliver SmartLoader malware, highlighting the need for robust third‑party code vetting in SOC 2 vendor‑risk programs.

LiveThreat™ Intelligence · 📅 July 22, 2026· 📰 helpnetsecurity.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
3 sector(s)
Actions
3 recommended
📰
Source
helpnetsecurity.com

AI Agents Tricked into Recommending Malicious GitHub Repositories

What Happened — Researchers identified a campaign, dubbed FakeGit, that created ~7,600 malicious GitHub repositories. The repos masquerade as AI Skills or Model Context Protocol (MCP) servers and have been used to deliver the SmartLoader malware family, which installs the StealC information‑stealer. In testing, leading AI agents (Claude, Gemini, ChatGPT) surfaced these malicious repos when asked for code or services, effectively “baiting” the agents themselves.

Why It Matters for Compliance & Audit Readiness

  • The attack exploits third‑party code and open‑source supply‑chain controls—exactly the scenario SOC 2 vendor‑management criteria (CC6.1, CC6.2) are designed to monitor.
  • Continuous evidence of third‑party risk assessments (e.g., repository provenance, SBOM validation) becomes critical audit evidence.
  • Demonstrating a documented process for vetting AI‑generated recommendations aligns with the “monitoring” and “risk mitigation” principles of SOC 2.

Who Is Affected – SaaS platforms, AI‑tool providers, DevOps toolchains, and any organization that integrates third‑party code from public repositories (tech, finance, healthcare, etc.).

Recommended Actions

  • Map the FakeGit technique to your vendor‑risk controls (SOC 2 CC6.x) and update your third‑party assessment checklist.
  • Implement automated SBOM generation and repository provenance checks for any code pulled from public sources.
  • Add AI‑agent interaction logs to your continuous monitoring pipeline as audit evidence of safe code sourcing.

Source: Help Net Security

Technical Notes – The campaign uses look‑alike developer profiles, copied READMEs, and malicious ZIP assets. SmartLoader establishes persistence and drops StealC, which harvests credentials and active sessions. No specific CVE is cited; the vector is malicious repository distribution (AgentBaiting). Source: same as above

📰 Original Source
https://www.helpnetsecurity.com/2026/07/21/github-repos-malware-campaign-fakegit-ai-agents/

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Vendor Risk Hub

This is the scenario continuous vendor monitoring is built to catch.

When a vendor is compromised, your SOC 2 vendor-management controls are what produce the audit trail showing you knew, assessed, and acted. The Verisq AI Trust Operations platform tracks that continuously.

Explore the Verisq AI Trust Operations platform →