A cybersecurity campaign called **FakeGit** has created nearly 7,600 malicious GitHub repositories — over 800 of which impersonate AI tools or Model Context Protocol (MCP) servers — to distribute **SmartLoader malware**, which then deploys the **StealC** information stealer on victims' systems. The campaign uses copied projects, fake developer profiles, and deceptive README files to trick users into downloading malicious ZIP files. A particularly alarming evolution called **AgentBaiting** allows AI agents (including Claude, Gemini, and ChatGPT) to independently discover and act on these fraudulent repositories without any human involvement, meaning the attack no longer requires a victim to click a link.