AI agents tricked into recommending malicious GitHub repositories

2026-07-21T14:51:49Z7933a6b3ca8d80f725e52d7984a4bb6b8f959047cf0e0c2290e0a253867d735a
AI agentsAI resilienceENCFORGEFBI impersonation scamsFakeGitGuardDutyJadePufferOracle EBS breachSonicWall SMAagent securitybackup & recoverydata breachidentity fraudmalicious GitHub repositoriesransomwaresupply chain compromisevulnerability localizationzero-day exploitation

What happened

This collection highlights multiple active threats and AI-era risks: a large FakeGit campaign (≈7,600 malicious GitHub repos across ~6,600 accounts) that tricks AI agents into recommending malicious code or services, increasing supply-chain risk for agentic workflows; JadePuffer resurfacing with ENCFORGE ransomware specifically designed to target AI/ML models and infrastructure; and active exploitation of two SonicWall SMA zero-days (CVE-2026-15409, CVE-2026-15410) that enabled stealthy, long-term access and custom malware on VPN appliances. Also noted: an Estée Lauder data breach tied to an (

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
helpnetsecurity
Record identifier
7933a6b3ca8d80f725e52d7984a4bb6b8f959047cf0e0c2290e0a253867d735a
Enrichment time
2026-07-21T14:51:49Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · AI agents tricked into recommending malicious GitHub repositories · Baitaphish