AgentBaiting: How Fake AI Tools Are Hitting NYC Small Businesses
AgentBaiting: How Fake AI Tools Are Hitting NYC Small Businesses in 2026
Imagine this: your employee searches for a useful AI tool to automate a workflow, finds what looks like a legitimate AI assistant skill or plugin, and installs it. Within hours, malware is exfiltrating credentials, stealing session tokens, and accessing your company’s sensitive data. This isn’t hypothetical — it’s happening right now to businesses across New York, and cybersecurity researchers have named it “AgentBaiting”.
In a landmark investigation published in July 2026, cybersecurity firm Island.io exposed a massive campaign called FakeGit that planted over 7,600 malicious GitHub repositories, including more than 800 posing as AI Skills and MCP (Model Context Protocol) servers. These fake tools were downloaded over 14 million times and appeared across public AI registries. The malware, called SmartLoader, establishes persistence and installs StealC — an information stealer that targets credentials, active sessions, and other sensitive data.
For small business owners in NYC, Staten Island, and throughout the New York tri-state area, this represents a new frontier in cyber threats that most IT teams are still waking up to.
What Is AgentBaiting? The New Attack on AI Supply Chains
AgentBaiting is a technique where attackers create fake AI tools — Skills, plugins, MCP servers, and integrations — that look legitimate in public registries and AI tool directories. When users or AI agents search for capabilities like “Gmail integration” or “WhatsApp automation,” they encounter these counterfeit tools, treat the attacker’s README as legitimate documentation, and install the malware.
What makes this particularly dangerous is the automation factor. AI coding assistants like Claude Code, Gemini, and ChatGPT were observed in testing automatically surfacing these malicious repositories without any human prompting — meaning your AI tools may be recommending malware to your developers and IT staff.
The Scale of the Threat: 7,600 Repos, 14 Million Downloads
The FakeGit operation is one of the largest campaigns of its kind:
- 7,600 malicious GitHub repositories created by approximately 6,600 fake developer profiles
- 800+ repositories posing specifically as AI Skills or MCP servers
- 14+ million downloads across campaign repositories
- 600+ appearances across public AI registries and catalogs
- Peak activity in April 2026, with nearly 300 AI-related repositories created in a single month
The attackers used copied projects, lookalike developer profiles, and convincing README files to make their malicious ZIP files appear credible. The most targeted categories included integrations for Gmail, WhatsApp, Databricks, Jenkins, and Docker — tools that virtually every small business uses daily.
How Small Businesses in NYC Are at Risk
Small businesses across New York City, Staten Island, and New Jersey are particularly vulnerable for several reasons:
- Adoption without vetting: SMBs are increasingly adopting AI tools for productivity but lack the IT resources to vet every plugin or integration before deployment.
- No IT security team: NYC small businesses often operate with one IT person or an outsourced MSP — making it nearly impossible to review every tool before installation.
- Trust in AI recommendations: When an AI assistant recommends a tool, employees naturally trust it. This trust becomes an attack vector when that recommendation is from a compromised AI agent.
- Supply chain exposure: A single malicious MCP server or Skill installed on one employee’s machine can serve as an entry point to your entire network.
Real-World Impact: StealC and SmartLoader in Action
Once installed, SmartLoader malware establishes persistence on the victim’s machine and deploys StealC. The information stealer targets:
- Browser credentials and password vaults
- Active browser sessions and cookies
- Environment variables and API keys
- SSH keys and configuration files
- Communication app sessions (Slack, Teams, Discord)
For a small business, losing access to email credentials or active session tokens can mean client data exposure, financial fraud, and reputational damage that’s often unrecoverable.
How to Protect Your Business: An Actionable Checklist
Here’s what MicroSky recommends for NYC small businesses to defend against AgentBaiting and AI supply chain threats:
1. Audit All AI Tools and Integrations
Review every AI Skill, MCP server, plugin, and integration currently installed across your organization. If it came from a third-party registry or store, verify its source and read reviews from multiple independent sources.
2. Implement an AI Tool Approval Process
Require that all AI tools and integrations be reviewed by IT or your managed service provider before deployment. Don’t let individual employees install tools without oversight.
3. Monitor for Fake Developer Profiles
Be suspicious of repositories with: newly created accounts, generic profile pictures, READMEs that feel too polished, and ZIP files attached to releases. Legitimate tools are typically well-documented with open issue trackers.
4. Use EDR to Detect Malware Behavior
Deploy Endpoint Detection and Response (EDR) solutions that monitor for suspicious behavior like credential dumping, unusual network connections, and unauthorized persistence mechanisms.
5. Rotate Credentials Proactively
If your business has used any AI tools downloaded from public registries or GitHub in the past six months, assume compromise and rotate all credentials, API keys, and session tokens immediately.
6. Restrict AI Agent Permissions
If you use AI coding assistants or automation agents, limit their permissions to what’s strictly necessary. Prevent them from installing packages or accessing sensitive files without human review.
MicroSky’s Approach to AI Security
At MicroSky, we recognize that AI adoption is accelerating faster than security frameworks can keep pace. Our approach combines proactive monitoring, zero-trust architecture, and AI-specific threat detection to protect NYC businesses from these emerging threats.
MicroSky’s managed security services include continuous monitoring for supply chain threats, credential protection, and rapid incident response — ensuring that when the next wave of AI-powered attacks hits, your business is already protected.
The Bottom Line
AgentBaiting represents a fundamental shift in how cybercriminals reach small businesses. The attackers aren’t breaching firewalls — they’re hiding in the tools you willingly install. For NYC small business owners, the time to act is now.
Don’t wait for your business to become the next statistic. Contact MicroSky at (718) 672-2177 or visit microskyms.com to learn how our managed IT and cybersecurity services can protect your business from AgentBaiting and every other emerging threat in 2026.
Your AI tools should make your business more productive — not be the vector that brings it down. Let MicroSky be the partner who makes sure of it.

