AI agents tricked into recommending malicious GitHub repositories Island uncovered roughly 7,600 malicious GitHub repositories, more than 800 of them posing as AI Skills or Model Context Protocol (MCP) servers, in a wave that peaked in April 2026, with the fake repositories tied to about 6,600 accounts, around 1,400 of which were built around AI tools, agents, or workflows. Roughly 7,600 malicious GitHub repositories were uncovered, more than 800 of them posing as AI Skills or Model Context Protocol MCP servers, in a wave that peaked in April 2026, according to Island. The scale of the FakeGit operation Source: Island The fake repositories are tied to about 6,600 accounts, around 1,400 of which were built around AI tools, agents, or workflows, and span individual and enterprise use, ranging from Gmail and WhatsApp integrations to … More https://www.helpnetsecurity.com/2026/07/21/github-repos-malware-campaign-fakegit-ai-agents/ The post AI agents tricked into recommending malicious GitHub repositories https://www.helpnetsecurity.com/2026/07/21/github-repos-malware-campaign-fakegit-ai-agents/ appeared first on Help Net Security https://www.helpnetsecurity.com .