ThreatCluster

AgentBaiting Campaign Exploits AI Skills to Distribute SmartLoader Malware

First seen 21 Jul 2026, 19:22 UTC GbhackersCybersecuritynews 85% similarity 65

Article Content

Browse articles
ThreatCluster

The AgentBaiting campaign has emerged as a significant threat, utilizing 800 fake AI Skills and Model Context Protocol (MCP) servers to deliver SmartLoader malware. This operation leverages trusted GitHub projects and public capability catalogs to disguise malicious activities. The malware delivery method exploits the growing trust in AI integrations, turning them into vectors for cyberattacks. The campaign is notable for its scale, with 7,600 repositories involved in the operation. Affected systems include those relying on AI capabilities and MCP workflows. The current status of the campaign indicates ongoing exploitation, with no immediate resolution reported. Security professionals are advised to remain vigilant against this evolving threat.

Key Points: • AgentBaiting uses 800 fake AI Skills to deliver SmartLoader malware. • The operation exploits trusted GitHub projects and public AI registries. • 7,600 repositories are implicated in the malware distribution campaign.

ThreatCluster AI

Timeline

2026-07-21
AgentBaiting campaign identified
Malware operators are using fake AI Skills and MCP servers to distribute SmartLoader malware through trusted platforms.
Gbhackers
2026-07-21
Malware delivery method detailed
The campaign turns trusted AI integrations into vectors for cyberattacks, affecting numerous systems relying on AI capabilities.
Cybersecuritynews

Community

Browse all →