
Malicious AI Skills Reach Public Registries and Accumulate 14 Million Downloads
Security researchers have uncovered a large FakeGit malware operation that used malicious GitHub repositories, public AI registries, and AI-agent-readable installation instructions to distribute the SmartLoader malware loader. Island researchers identified about 7,6007{,}6007,600 malicious GitHub repositories linked to the operation. More than 800800800 of these repositories impersonated AI Skills or Model Context Protocol (MCP) servers. The […]
The post Malicious AI Skills Reach Public Registries and Accumulate 14 Million Downloads appeared first on Cyber Security News.