Skip to content
AgentBaiting Campaign Exploits AI Skills to Distribute SmartLoader Malware

AgentBaiting Campaign Exploits AI Skills to Distribute SmartLoader Malware

First seen 21 Jul 2026, 19:22 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster July 22, 2026 at 18:56 UTC
  • AgentBaiting uses 800 fake AI Skills to deliver SmartLoader malware.
  • The operation exploits trusted GitHub projects and public AI registries.
  • 7,600 repositories are implicated in the malware distribution campaign.

The AgentBaiting campaign has emerged as a significant threat, utilizing 800 fake AI Skills and Model Context Protocol (MCP) servers to deliver SmartLoader malware. This operation leverages trusted GitHub projects and public capability catalogs to disguise malicious activities. The malware delivery method exploits the growing trust in AI integrations, turning them into vectors for cyberattacks. The campaign is notable for its scale, with 7,600 repositories involved in the operation. Affected systems include those relying on AI capabilities and MCP workflows. The current status of the campaign indicates ongoing exploitation, with no immediate resolution reported. Security professionals are advised to remain vigilant against this evolving threat.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 51d ago How this analysis works

Timeline

2026-07-21
AgentBaiting campaign identified
Malware operators are using fake AI Skills and MCP servers to distribute SmartLoader malware through trusted platforms.
Gbhackers
2026-07-21
Malware delivery method detailed
The campaign turns trusted AI integrations into vectors for cyberattacks, affecting numerous systems relying on AI capabilities.
Cybersecuritynews

More articles in this cluster (3)

Following this threat?

Track StealC in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed