自 2025 年 3 月起活躍的 FakeGit 行動,建立了約 7,600 個惡意 GitHub 倉庫,其中超過 800 個偽裝成 AI Skills 或 MCP 伺服器,專門誘騙 Claude Code、Gemini CLI 和 ChatGPT 等 AI 程式碼代理自動推薦給開發者。 攻擊者運用名為「AgentBaiting」的新手法,在 AI 代理的搜尋結果與公開的 AI 登錄清單中植入釣餌,讓代理在正常運作過程中主動發現並推薦惡意連結,最終竊取開發者的憑證、API 金鑰與機敏資料。

Create a landscape editorial hero image for this Studio Global article: Search & fact-check with cited sources for What was the FakeGit campaign, how did it use nearly 7,600 fake GitHub repositories to trick AI c. Article summary: Here is a comprehensive, source-cited breakdown of the FakeGit campaign.. Topic tags: general, general web, user generated. Style: premium digital editorial illustration, source-backed research mood, clean composition, high detail, modern web publication hero. Use reference image context only for broad subject, composition, and topical grounding; do not copy the exact image. Avoid: logos, brand marks, copyrighted characters, real person likenesses, fake screenshots, UI text, readable text, watermarks, charts with fake numbers, clickbait thumbnails, icons, and tiny thumbnail layouts. Make it useful as an illustrative visual, not as factual evidence.
2026 年 7 月,Island Security 的研究人員公開揭露了一起名為 FakeGit 的大規模惡意軟體散佈行動。此行動最關鍵的創新在於一種名為 AgentBaiting 的手法——利用 AI 程式碼代理「樂於助人」的特性,讓它們在沒有用戶直接指使的情況下,自主發現並向用戶推薦惡意倉庫
。
該行動至少從 2025 年 3 月 開始活躍,並被追蹤到由一名 越南語的操作者 主導。駭客部署了近 7,600 個惡意 GitHub 倉庫,其中 超過 800 個 偽裝成 AI Skills 或模型上下文協議 (MCP) 伺服器——這正是 Claude Code、Gemini CLI 和 ChatGPT 等 AI 代理會主動搜尋與推薦的元件類型。截至 2026 年 7 月,GitHub 的下載計數器記錄到與這些行動檔案相關的 超過 1,400 萬次下載事件
。
AgentBaiting 是一種針對 AI 代理信任模型的供應鏈攻擊。攻擊者不再依賴受害者自己點擊惡意連結,而是精心設計他們的假倉庫,使其能被 AI 代理自行發現並推廣。攻擊鏈如下所述:
Island Security 的首席研究員 Oleg Zaytsev 描述了這種轉變:「過去用來欺騙人類的手法,現在也開始用來欺騙 AI 代理了。」
FakeGit 行動部署了兩階段的惡意軟體攻擊鏈:
| 指標 | 數據 |
|---|---|
| 惡意 GitHub 倉庫 | 約 7,600 個 |
| 偽裝成 AI Skills / MCP 伺服器的倉庫 | 超過 800 個 |
| 攻擊者控制的 GitHub 帳號 | 約 6,600 個 |
| AI 註冊清單中的惡意條目 | 超過 600 個 |
| 觀察到的 GitHub 總下載事件 | 超過 1,400 萬次 |
| 行動活躍起始時間 | 2025 年 3 月 |
| 攻擊者歸因 | 單一越南語操作者 |
注意:超過 1,400 萬次的下載量是 GitHub 計數器記錄到的所有事件,其中可能包含自動化請求以及真實用戶的下載。
根據 Island Security 的分析以及來自 Mozilla 0din 團隊等其他安全研究單位的交叉比對報告,主要的防禦措施如下:
Studio Global AI
Use this topic as a starting point for a fresh source-backed answer, then compare citations before you share it.
自 2025 年 3 月起活躍的 FakeGit 行動,建立了約 7,600 個惡意 GitHub 倉庫,其中超過 800 個偽裝成 AI Skills 或 MCP 伺服器,專門誘騙 Claude Code、Gemini CLI 和 ChatGPT 等 AI 程式碼代理自動推薦給開發者。
自 2025 年 3 月起活躍的 FakeGit 行動,建立了約 7,600 個惡意 GitHub 倉庫,其中超過 800 個偽裝成 AI Skills 或 MCP 伺服器,專門誘騙 Claude Code、Gemini CLI 和 ChatGPT 等 AI 程式碼代理自動推薦給開發者。 攻擊者運用名為「AgentBaiting」的新手法,在 AI 代理的搜尋結果與公開的 AI 登錄清單中植入釣餌,讓代理在正常運作過程中主動發現並推薦惡意連結,最終竊取開發者的憑證、API 金鑰與機敏資料。
研究人員建議企業建立受核准的 AI 元件白名單、對新代理功能進行沙盒測試,並嚴格限制代理的自主行為,例如要求用戶確認後才能安裝新工具或執行指令。