As cited
Copy frozen at (site build).
ai security
AI agents tricked into recommending malicious GitHub repositories
Island researchers discovered approximately 7,600 malicious GitHub repositories, with over 800 masquerading as AI Skills or Model Context Protocol servers, peaking in April 2026. The FakeGit operation involved around 6,600 compromised accounts, roughly 1,400 of which targeted AI tools, agents, and workflows. These repositories offered fraudulent integrations spanning consumer and enterprise applications, including services like Gmail and WhatsApp.
Why it matters: Developers and AI practitioners using GitHub for dependencies face supply chain compromise risk if they install malicious AI agent repositories recommended by language models or automation tools, requiring immediate verification of package sources and repository authenticity.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
ai security
AI agents tricked into recommending malicious GitHub repositories
No summary had been written when this copy was frozen.
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
ai security
AI agents tricked into recommending malicious GitHub repositories
Researchers uncovered roughly 7,600 malicious GitHub repositories, with more than 800 masquerading as artificial intelligence (AI) skills or Model Context Protocol (MCP) servers, in a campaign that peaked in April 2026. The fake projects were linked to about 6,600 accounts, around 1,400 of which focused on AI tools, agents, or workflows and spanned uses such as Gmail and WhatsApp integrations.
Why it matters: Developers and security teams that rely on AI agents or GitHub integrations risk pulling malicious code unless they verify repository authenticity before deployment.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
ai security
AI agents tricked into recommending malicious GitHub repositories
Researchers uncovered roughly 7,600 malicious GitHub repositories, with more than 800 masquerading as artificial intelligence (AI) skills or Model Context Protocol (MCP) servers, in a campaign that peaked in April 2026. The fake projects were linked to about 6,600 accounts, around 1,400 of which focused on AI tools, agents, or workflows and spanned uses such as Gmail and WhatsApp integrations.
Why it matters: Developers and security teams that rely on AI agents or GitHub integrations risk pulling malicious code unless they verify repository authenticity before deployment.
- Source published
- First seen by Cybersecurity Tracker