Why it matters
Island identified roughly 7,600 malicious GitHub repositories in the FakeGit campaign, including more than 800 posing as AI skills or MCP servers and more than 600 listings in public AI registries. Tests showed coding assistants could independently surface the lures and repeat their installation instructions, which delivered SmartLoader and the StealC information stealer.
My takeaway: Discovery is part of the agent supply chain, and a marketplace listing is not evidence of trust. Maintain an approved capability catalog, verify publishers, commits, and hashes, install new tools in secret-free sandboxes, monitor agent-initiated downloads and configuration changes, and revoke sessions and tokens—not only passwords—after suspected execution.