AI hacks have evolved into a new form of malware that poses a significant threat to users. The FakeGit campaign, which was discovered in July 2023 by Island, has been found to distribute malware that disguises itself as fake GitHub repositories and profiles, all while spreading malicious software.
According to the data provided by Island, roughly 7,600 fake GitHub repositories and 6,600 fraudulent profiles have been created, with over 14 million downloads reported. This makes FakeGit one of the largest known malware campaigns in recent history. The malware is particularly insidious, as it impersonates AI skills and MCP servers, which suggests that its capabilities extend beyond mere hacking.
Experts warn that this new form of malware has the potential to spread mind-control capabilities through a vulnerability exploited by the infected users. As such, users are advised to exercise extreme caution when interacting with unfamiliar repositories or profiles online. This is a clear example of how AI hacks can evolve into more sophisticated and insidious threats, highlighting the need for vigilance and robust security measures in the digital age.