B
今週中
攻撃者がGitHub上に約7,600個の悪意あるリポジトリを作成し、AIツールやMCPサーバーを装ってSmartLoaderおよびStealCという情報窃取マル…
📌 一言でいうと
攻撃者がGitHub上に約7,600個の悪意あるリポジトリを作成し、AIツールやMCPサーバーを装ってSmartLoaderおよびStealCという情報窃取マルウェアを配布する「FakeGit」キャンペーンが確認されました。攻撃者は「AgentBaiting」と呼ばれる手法を用い、AIエージェントの検索結果を通じてユーザーを誘導し、偽のREADMEから悪意あるZIPファイルをダウンロードさせます。感染すると、ブラウザのパスワード、Cookie、セッション情報などの機密情報が窃取されます。
🔍該当判定
- GitHubからAIツールやMCPサーバーなどのZIPファイルをダウンロードし、社内PCで実行した
- LobeHub, Glama, MCP.so, MCP MarketなどのAI能力ディレクトリ経由でソフトを導入した
- ChatGPTやClaude CodeなどのAIが推奨したGitHubリポジトリから、インストールファイルをダウンロードした
上記いずれにも該当しない → 静観でOK
✅該当時の対応
信頼できないGitHubリポジトリからZIPファイルをダウンロードして実行しないこと。特にAIエージェントやLLMの推奨リポジトリであっても、公式の検証済みソースであるかを確認し、実行前にコードの内容を精査することを推奨します。
📧 メール案を見る (社員向け)
⚠️ これは AI が生成した参考例です。配信前に必ず内容をご確認のうえ、貴社の状況に合わせて編集してご利用ください。実際の被害状況や自社の利用環境を踏まえた判断は、貴社のセキュリティ責任者にご確認ください。
件名: 【注意喚起】GitHub上の偽AIツールによるウイルス感染について
お疲れさまです。情報システム担当です。
GitHub上で、AIツールや便利な設定ファイルを装った偽のプログラムが大量に配布されており、実行するとパスワードや個人情報が盗まれる被害が報告されています。
ご協力をお願いしたいこと:
1. AIツールやMCPサーバーなどの導入を検討する際、出所不明なGitHubリポジトリからZIPファイルをダウンロードして実行しないでください。
2. AIチャットボット(ChatGPT, Claude, Gemini等)が推奨したリポジトリであっても、必ず公式なものであるかを確認してください。
対応期限: 本日中(周知確認)
お疲れさまです。情報システム担当です。
GitHub上で、AIツールや便利な設定ファイルを装った偽のプログラムが大量に配布されており、実行するとパスワードや個人情報が盗まれる被害が報告されています。
ご協力をお願いしたいこと:
1. AIツールやMCPサーバーなどの導入を検討する際、出所不明なGitHubリポジトリからZIPファイルをダウンロードして実行しないでください。
2. AIチャットボット(ChatGPT, Claude, Gemini等)が推奨したリポジトリであっても、必ず公式なものであるかを確認してください。
対応期限: 本日中(周知確認)
Subject: [Security Alert] Malware Distribution via Fake AI Tools on GitHub
Dear employees,
We have received reports of a large-scale campaign where attackers are distributing malware by disguising it as AI tools or configuration files on GitHub. Executing these files can lead to the theft of your passwords and sensitive information.
Requested Actions:
1. Do not download and execute ZIP files from untrusted GitHub repositories, especially those claiming to be AI tools or MCP servers.
2. Be cautious even if a repository is recommended by AI chatbots (e.g., ChatGPT, Claude, Gemini); always verify the source is official and trusted.
Deadline: Immediate
Dear employees,
We have received reports of a large-scale campaign where attackers are distributing malware by disguising it as AI tools or configuration files on GitHub. Executing these files can lead to the theft of your passwords and sensitive information.
Requested Actions:
1. Do not download and execute ZIP files from untrusted GitHub repositories, especially those claiming to be AI tools or MCP servers.
2. Be cautious even if a repository is recommended by AI chatbots (e.g., ChatGPT, Claude, Gemini); always verify the source is official and trusted.
Deadline: Immediate