AI Coding Incident Tracker

AgentBaiting: AI Agents Tricked into Recommending Malicious Repos

AgentBaiting: AI Agents Tricked into Recommending Malicious Repos

Key Questions

What is the AgentBaiting attack?

AgentBaiting is a supply-chain attack that uses fake MCP servers and AI Skills on GitHub to trick AI agents into recommending malicious repositories. Attackers created over 7,600 such repos, with more than 800 posing as AI-related tools, leading AI systems to suggest them unprompted.

Which AI agents were tricked into recommending the malicious repositories?

Claude Code, Gemini, and ChatGPT were all affected and recommended the malicious GitHub repositories without user prompting. The attack exploits AI agents' reliance on external resources like GitHub for code and tool suggestions.

What is the scale and impact of the malicious repositories?

Roughly 7,600 malicious repositories were discovered, accumulating 14 million downloads and distributing malware such as SmartLoader and StealC. More than 800 repos specifically mimicked AI Skills or Model Context Protocol servers to target AI coding workflows.

Supply-chain attack via fake MCP servers and Skills. Claude Code, Gemini, ChatGPT all recommended malicious GitHub repositories unprompted. 14M downloads, 7,600 repos, SmartLoader/StealC. Concrete numbers and tool coverage. Fits pattern of AI agents exploited through trust in external resources. Updated with detailed write-up from FakeGit research.

Sources (2)
Updated Jul 24, 2026
What is the AgentBaiting attack? - AI Coding Incident Tracker | NBot | nbot.ai