AgentBaiting uses 600 fake MCP and Skills listings to lure AI assistants
TechNadu · x · 2026-07-21
Researchers say a new attack called AgentBaiting can trick AI assistants such as Claude Code, Gemini, and ChatGPT into recommending malicious Skills and MCP servers. The campaign reportedly seeds more than 600 fake listings in public registries to spread malware, showing how easily agent toolchains can be weaponized.
More from coding & agent
- GPT-6 Astra beats Factorio with enemies in 44 in-game hours at ~$4,500 API cost — liminal_bardo · 2026-09-11
- Investment Analyst Asks How to Build a Claude-Based Diligence Agent Stack — Careless_Tie2286 · 2026-09-11
- How Do You Catch Behavioral Regressions in LLM Agents Between Releases? — Beautiful_Belt_601 · 2026-09-11
- Treating agents like 50 First Dates: a 3-layer context system so every conversation doesn't start from zero — evielync · 2026-09-11
- Running the Firefox MCP on Android via Termux, ngrok, and mcp-proxy — Nervous-Strain7544 · 2026-09-11
- Run Firefox MCP on Android: Termux + ngrok tunnel tutorial — Nervous-Strain7544 · 2026-09-11