AI Agents Are Becoming a New Malware Distribution Channel
A new malware campaign, FakeGit, leveraged AI assistants like Gemini and ChatGPT to recommend malicious GitHub repositories, turning the agents themselves into distribution channels. Researchers warn that agents’ reliance on textual instructions and ability to act on them creates a “lethal trifecta” that attackers can exploit through tactics such as AgentBaiting and tool poisoning, posing a significant emerging security threat.