cd /news/ai-safety/ai-agents-tricked-into-recommending-… · home topics ai-safety article
[ARTICLE · art-67096] src=helpnetsecurity.com ↗ pub= topic=ai-safety verified=true sentiment=↓ negative

AI agents tricked into recommending malicious GitHub repositories

Island uncovered roughly 7,600 malicious GitHub repositories, more than 800 of them posing as AI Skills or Model Context Protocol (MCP) servers, in a wave that peaked in April 2026, with the fake repositories tied to about 6,600 accounts, around 1,400 of which were built around AI tools, agents, or workflows.

read1 min views1 publishedJul 21, 2026

Roughly 7,600 malicious GitHub repositories were uncovered, more than 800 of them posing as AI Skills or Model Context Protocol (MCP) servers, in a wave that peaked in April 2026, according to Island. The scale of the FakeGit operation (Source: Island) The fake repositories are tied to about 6,600 accounts, around 1,400 of which were built around AI tools, agents, or workflows, and span individual and enterprise use, ranging from Gmail and WhatsApp integrations to … More

The post AI agents tricked into recommending malicious GitHub repositories appeared first on Help Net Security.

── more in #ai-safety 4 stories · sorted by recency
── more on @island 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
Live at https://your-agent.zahid.host
Get free account → Pricing
from €0/mo · no card required
LIVE [news/ai-agents-tricked-in…] indexed:0 read:1min 2026-07-21 ·