AI Agents Are Becoming a New Malware Distribution Channel

By Farukh Rakhimov, Head of Compliance, Information Safety and Info Safety at AdTech Holding

Roughly 7,600 faux GitHub repositories, 6,600 fraudulent profiles and greater than 14 million downloads: that’s the scale of FakeGit, a malware marketing campaign documented by Island in July 2026. Over 800 repositories impersonated AI expertise and MCP servers, distributing SmartLoader and the StealC infostealer.

Pretend repositories are nothing new. The shock was who beneficial them.

Gemini and ChatGPT independently prompt the identical malicious walmart-mcp repository. The brokers discovered the attacker’s challenge and handed customers set up directions.

Attackers now not must deceive customers straight. They’ll deceive the assistants customers belief.

Why Brokers Are Susceptible

Two architectural traits make these assaults attainable.

First, brokers course of directions and exterior data as textual content. A malicious instruction hidden in a README, webpage or instrument description could also be interpreted as one thing to obey relatively than analyze. That is oblique immediate injection.

Second, brokers can act on these directions.

Safety researcher Simon Willison calls the mixture of three circumstances the deadly trifecta: entry to beneficial data, publicity to untrusted exterior content material and the flexibility to ship information exterior the system.

Collectively, these circumstances flip malicious textual content into a possible information breach.

Different assaults exploit one thing less complicated: fabricated belief indicators. Stars, downloads, contributor histories and registry listings could make malicious software program seem official.

Listed below are eight methods these weaknesses are being exploited.

1. AgentBaiting: When an Agent Recommends Malware

AgentBaiting targets the assistant relatively than the person.

Within the FakeGit marketing campaign, attackers created convincing repositories with sensible documentation and distributed them by public registries.

Gemini and ChatGPT independently beneficial the identical faux Walmart MCP connector as a result of it appeared related and credible.

The repositories distributed SmartLoader, which downloaded StealC to steal browser credentials, cookies, lively periods and cryptocurrency pockets information.

The brokers weren’t compromised. They merely beneficial software program whose obvious credibility had been manufactured.

2. Software Poisoning: Directions Hidden in Software Descriptions

MCP servers present brokers with textual descriptions of obtainable instruments. Attackers can conceal directions inside these descriptions.

In April 2025, Invariant Labs demonstrated how directions embedded in a malicious calculator instrument may manipulate a separate, trusted electronic mail connector into copying outgoing messages to an attacker.

The person by no means sees the malicious directions.

Software poisoning stays a demonstrated risk mannequin relatively than a publicly confirmed 

real-world incident.

3. When Brokers Conceal Their Actions

Some malicious expertise explicitly instruct brokers to not disclose what they’ve carried out.

A 2026 educational research examined 98,380 expertise from two registries and confirmed 157 as malicious, figuring out 632 vulnerabilities and 13 assault methods.

One recurring instruction gave the analysis its title: “Do Not Point out This to the Person.”

An agent may subsequently report {that a} job was accomplished whereas omitting unauthorized actions, together with the transmission of delicate data.

4. Rug Pull: Trusted Software program Modifications After Set up

A package deal could behave legitimately for months earlier than introducing malicious performance.

In September 2025, Koi Safety uncovered postmark-mcp, a connector impersonating the official Postmark electronic mail service.

Variations by 1.0.15 appeared innocent. Model 1.0.16 launched a hidden BCC recipient that copied outgoing emails to an attacker-controlled area.

The package deal probably uncovered password-reset messages and authentication hyperlinks related to roughly 300 organizations.

Postmark confirmed that the connector was not its product and that its personal service had not been compromised.

The assault exploited belief gathered by earlier variations. Computerized updates allowed malicious performance to reach with out renewed person approval.

5. Malicious Modifications Can Occur Exterior the Package deal

Reviewing supply code can’t detect all the pieces when exterior dependencies change independently.

In August 2025, Test Level disclosed MCPoison, a vulnerability in Cursor that allowed attackers to change beforehand accepted challenge configurations and execute instructions with out renewed approval.

Cursor 1.3 addressed the difficulty.

One other 2026 experiment demonstrated how a talent distributed to roughly 26,000 brokers may initially hyperlink to official documentation earlier than the exterior web page modified to malicious set up directions.

The package deal itself remained unchanged, permitting the risk to flee scanners inspecting solely submitted information.

6. Opening an Untrusted Repository Can Execute Code

AI-enabled growth environments introduce dangers even earlier than customers intentionally set up extra software program.

Test Level discovered that Claude Code may execute repository-controlled configuration instructions earlier than customers accomplished its trust-confirmation course of.

The vulnerabilities included arbitrary command execution (CVE-2025-59536) and API credential publicity by a manipulated server endpoint (CVE-2026-21852).

Anthropic subsequently patched the reported vulnerabilities.

The implication is easy: opening an unfamiliar challenge inside an agent-enabled growth setting could create execution paths that atypical file inspection wouldn’t.

7. ClickFix: Customers Set up Malware Themselves

ClickFix requires no subtle immediate injection.

Attackers disguise malicious instructions as set up conditions inside README or SKILL.md information. Customers comply with the directions and execute the instructions themselves.

Throughout the ClawHavoc marketing campaign in early 2026, researchers found malicious expertise masquerading as cryptocurrency and productiveness instruments within the OpenClaw ecosystem.

Koi Safety recognized 341 malicious expertise amongst 2,857 obtainable throughout its audit.

Antiy CERT subsequently tracked 1,184 malicious expertise related to simply 12 accounts.

The malware focused cryptocurrency wallets, browser credentials, API keys, SSH keys and Telegram periods.

8. When the Agent Turns into the Attacker

Brokers may coordinate offensive operations.

In November 2025, Anthropic reported GTG-1002, a cyberespionage marketing campaign through which attackers linked penetration-testing instruments to Claude Code by MCP.

In accordance with Anthropic, the mannequin independently carried out roughly 80–90% of tactical operations, whereas human operators established aims and made main strategic selections.

Anthropic attributed the marketing campaign to a state-sponsored group. That evaluation has not been independently confirmed in public threat-intelligence repositories.

The case illustrates how current offensive instruments will be assembled into autonomous workflows.

The Economics of Pretend Popularity

Many assaults rely on artificially manufactured credibility.

An April 2026 investigation discovered GitHub stars marketed for $0.03–$0.10 every. Researchers additionally recognized roughly six million suspicious stars throughout 15,835 repositories.

In one other case, attackers cloned an Oura MCP connector and spent three months creating faux contribution histories earlier than distributing the malicious model by official registries.

A separate malicious Solidity extension displayed artificially inflated obtain counts, finally approaching two million. One blockchain developer reportedly misplaced roughly $500,000.

Reputation determines discoverability, not safety.

Code evaluations and scanners even have limitations: malicious performance can conceal in dependencies, instrument descriptions, subsequent updates or exterior webpages.

What This Means for AdTech

The open-source ecosystem has confronted related supply-chain threats earlier than. Necessary two-factor authentication, trusted publishing and verified package deal provenance finally strengthened established registries.

AI talent marketplaces are growing a lot quicker, whereas their safety infrastructure stays comparatively immature.

The implications are additionally broader: an AI talent could function with entry to electronic mail, repositories, databases and credentials.

For AdTech, the identical danger extends on to promoting accounts.

Media consumers and AdOps groups more and more join brokers, reporting assistants and marketing campaign instruments to DSPs, promoting platforms and advertiser information.

A poisoned reporting or creative-generation talent may expose marketing campaign data, compromise account credentials or put promoting budgets in danger.

The underlying deception is acquainted: shopping for faux stars and downloads to make malicious software program seem reliable follows the identical logic as utilizing faux engagement and bot site visitors to make fraudulent promoting stock look official.

As AI brokers achieve extra authority, verifying the software program and indicators they belief turns into as essential as securing the techniques they function.