
New 'Agent Baiting' Attack Technique Targets AI Agents Through Malicious GitHub Repositories
Researchers from Island have discovered a new attack technique called 'agent baiting' that targets AI agents such as Claude Code, Codex, and Gemini. The research identified almost 8,000 malicious public GitHub repositories that deceive AI agents by masquerading as legitimate software packages while actually containing info-stealer malware and other threats. These malicious repositories specifically target AI skills and MCP (Model Context Protocol) servers, fooling AI agents into recommending or using compromised code that can infect users' computers. Researchers Oleg Zaytsev and Chris Gong conducted the investigation with the goal of finding as many malicious MCPs and AI skills as possible. The video creator John Hammond interviewed the research team about their findings and methods for protecting against these AI-targeted threats.