AI agents recommend malicious repositories in FakeGit campaign
A July 2026 campaign called FakeGit involved roughly 7,600 fake GitHub repositories, 6,600 fraudulent profiles, and over 14 million downloads. During this activity, Gemini and ChatGPT independently suggested the same malicious walmart-mcp repository to users.
Over 800 repositories impersonated AI skills and MCP servers to distribute SmartLoader and the StealC infostealer. The malware targeted browser credentials, cookies, active sessions, and cryptocurrency wallet data without compromising the underlying assistants.