AI News selected for Professionals and Decision Makers
AI Security And Privacy Updates

FakeGit Campaign Uses 7,600 GitHub Repositories to Spread SmartLoader Malware

20:23 · July 20, 2026 · Hacker News AI Section

FakeGit Campaign Uses 7,600 GitHub Repositories to Spread SmartLoader Malware

Cybersecurity researchers have discovered nearly 7,600 malicious GitHub repositories, out of which more than 800 pose as artificial intelligence (AI) skills or Model Context Protocol (MCP) servers to deliver a malware family known as SmartLoader as part of an ongoing campaign codenamed FakeGit. "FakeGit uses copied projects, lookalike developer profiles, convincing READMEs, and malicious ZIP

Summary

Cybersecurity researchers have identified a large-scale operation, tracked as FakeGit, that has published nearly 7,600 malicious GitHub repositories created by roughly 6,600 accounts. More than 800 of these repositories impersonate AI skills or Model Context Protocol (MCP) servers for tools such as Gmail, WhatsApp, Databricks, Jenkins, and Docker. The repositories deliver SmartLoader, a loader that establishes persistence and deploys secondary payloads, notably the StealC information stealer.

The campaign relies on copied or fabricated projects, lookalike developer profiles, and detailed README files that guide users or agents toward a malicious ZIP archive. That archive triggers a LuaJIT-based loader chain, which executes an obfuscated Lua script to install SmartLoader. The repositories have accumulated more than 14 million downloads from GitHub Release assets, with many listings also appearing on public MCP and skill registries such as LobeHub, Glama, and MCP.so.

A notable development is AgentBaiting, in which AI agents from Anthropic Claude, Google Gemini, and OpenAI ChatGPT independently locate the counterfeit repositories during routine searches for skills or MCP servers. The agents can interpret the attacker-supplied README instructions and relay them to users without any direct human interaction or supplied links. Prompts that request free cinematic prompt skills or enterprise MCP servers have been shown to surface the malicious entries.

Defensive recommendations focus on maintaining curated catalogs of vetted skills and MCP servers, testing new agent capabilities inside sandboxed environments, verifying both publishers and project provenance, and monitoring agent-driven discovery paths to interrupt the chain before execution.

Why it matters

Directly addresses AI-specific security risks and privacy threats via malware in AI tooling ecosystems, with actionable recommendations applicable to Dutch teams using GitHub, MCP servers, or agentic AI. Aligns with EU data protection needs due to data-stealing payloads.

More in this beat
agent-skillsFakeGitgithubmodel-context-protocolopen-source-securitySmartLoaderthreat-and-vulnerability-updates
GitHub Cuts Public Bug Bounty Payouts, Moves Top Rewards to VIP Tier

20:37 · July 22, 2026

GitHub Cuts Public Bug Bounty Payouts, Moves Top Rewards to VIP Tier

This article is highly relevant for security professionals as it highlights how AI is fundamentally altering the economics and operations of vulnerability management and bug bounties. Dutch enterprises running bug bounty programs or utilizing AI for code security must adapt to these shifts to effectively manage AI-generated reports and leverage new AI security models.

Relevance 75 · Audience 90

Hades PyPI Attack: 19 Packages Poisoned to Auto-Run Bun Credential Stealer

11:13 · June 9, 2026

Hades PyPI Attack: 19 Packages Poisoned to Auto-Run Bun Credential Stealer

Python is the foundational programming language for AI development. Security professionals in the Dutch AI market must be aware of PyPI supply chain attacks to secure their AI development environments, protect proprietary models, and prevent credential theft.

Relevance 65 · Audience 85

ThreatsDay: Gogs 10.0 RCE, n8n Workflow-to-RCE, $10M Reward, GLM-5.3 AI Exploit and More

19:23 · August 20, 2026

ThreatsDay: Gogs 10.0 RCE, n8n Workflow-to-RCE, $10M Reward, GLM-5.3 AI Exploit and More

The article provides crucial updates on privacy-enhancing technologies for AI that are vital for GDPR compliance in the Netherlands. It also alerts security professionals to emerging AI-driven threats, such as uncensored LLMs and AI models capable of autonomous vulnerability exploitation, which require immediate defensive consideration.

Relevance 85 · Audience 95

Veeam, Terraform MCP, Django Patch Critical Flaws, Led by CVSS 10.0 Cross-Tenant Bug

16:27 · August 5, 2026

Veeam, Terraform MCP, Django Patch Critical Flaws, Led by CVSS 10.0 Cross-Tenant Bug

This article details critical vulnerabilities in infrastructure tools used to deploy and manage AI systems, specifically the Terraform MCP server which connects AI assistants to infrastructure. Security professionals in the Dutch AI market must urgently assess their exposure to prevent cross-tenant credential reuse and potential remote code execution.

Relevance 85 · Audience 95

How we’re rethinking work at Cloudflare with Cloudflare OS

15:00 · August 5, 2026

How we’re rethinking work at Cloudflare with Cloudflare OS

Directly addresses AI security risks, privacy controls and compliance patterns that Dutch security teams can adapt under GDPR and the EU AI Act. Provides concrete, actionable guidance on Zero Trust integration, permission scoping and auditability for AI agents.

Relevance 85 · Audience 90

Researcher Says AI Helped Develop Linux Traffic-Control Race Into Root Exploit

10:04 · July 28, 2026

Researcher Says AI Helped Develop Linux Traffic-Control Race Into Root Exploit

This article is highly relevant for security professionals as it demonstrates the practical application of AI in offensive cybersecurity and vulnerability research. It highlights a specific Linux kernel vulnerability that Dutch enterprises must patch, while also signaling the evolving threat landscape where AI accelerates exploit development.

Relevance 75 · Audience 90

AI Tool Discovery at Scale: All You Need is DNS

06:00 · July 22, 2026

AI Tool Discovery at Scale: All You Need is DNS

This research is highly relevant for Dutch AI infrastructure developers and researchers building multi-agent systems. Its decentralized governance model aligns well with European data sovereignty and transparent AI goals, offering a scalable alternative to centralized tool registries.

Relevance 85 · Audience 95