Gunjo · Business Intelligence for the AI Era
← Sticker Wall SCAM · DETAIL

Fake AI Skill MCP Server Poisoning Scam: Trojan-Embedded Automation Plugins Stealing Corporate Credentials

The primary targets are developers at AI startups, corporate IT operations staff, and independent programmers. Driven by the urgent need to connect AI agents to databases, local files, or third-party services for automation, they often harbor a blind trust in 'open source equals secure.' Coupled with the time pressure of project deadlines, they are easily lured by high-star repositories and promises of 'out-of-the-box' functionality. This leads them to skip code reviews and introduce backdoored pseudo-automation tools directly into production environments, ultimately exposing core corporate assets to theft and ransomware.

SCAM

Key Fields

FIELD STAMPS
IndustryContent / Creator Economy
RegionGlobal
ScaleGray Market
ChannelOther
⚠️ This entry compiles scam tactics and public reporting; it is not investment or legal advice. Content is organized from public reporting and third-party complaint platforms; this site does not make any finding of illegality against the parties involved, who may contact us for correction if they object. If you encounter fraud, report it to the police immediately (110 / anti-fraud hotline 96110 in mainland China; local police overseas).

Who Gets Targeted

The primary targets are developers at AI startups, corporate IT operations staff, and independent programmers. Driven by the urgent need to connect AI agents to databases, local files, or third-party services for automation, they often harbor a blind trust in 'open source equals secure.' Coupled with the time pressure of project deadlines, they are easily lured by high-star repositories and promises of 'out-of-the-box' functionality. This leads them to skip code reviews and introduce backdoored pseudo-automation tools directly into production environments, ultimately exposing core corporate assets to theft and ransomware.

骗局怎么运作

  • Scam syndicates mass-create repositories on open-source hosting platforms disguised as popular AI Agent automation plugins—such as fake MCP servers for mainstream office software—complete with detailed, enticing manuals in Chinese, demo GIFs, and seemingly legitimate emails and open-source licenses to lower developer vigilance.
  • To create the illusion of high community approval, scammers use automated scripts to inflate star counts and fake likes, and even hire 'click farms' to promote the tools on technical forums and social groups, misleading developers into believing these are high-quality, widely-tested AI extensions.
  • Scammers carefully embed highly obfuscated malicious code within the installation scripts or underlying dependency packages of these fake tools. When a developer executes the one-click installation command in their terminal, the malware bypasses standard security scans, runs silently in the background, and uses environment variables to secretly harvest cloud platform keys and database access credentials.
  • The stolen high-risk credentials from development environments are encrypted and uploaded to overseas anonymous servers. Scammers then sell these packages on dark web marketplaces to ransomware gangs or use them directly to infiltrate corporate intranets for lateral movement, deploying ransomware or stealing trade secrets, leading to catastrophic data disasters for the victimized companies.
  • To avoid detection, some fake tools maintain basic functionality for a period after the theft, even pushing fake updates to maintain trust. Once a security incident occurs due to the leaked keys, the scammers delete the repository and quickly rebrand to launch new malicious plugins to continue the scam.

红旗信号(看到这些快跑)

  • 🚩 Repositories created very recently with abnormally high engagement, yet featuring sparse or highly mechanical commit histories.
  • 🚩 Installation scripts requesting unnecessary high-level system permissions, such as direct access to global environment variables or requiring the disabling of security software.
  • 🚩 Key logic in the source code containing unreadable obfuscated characters or decompiled binary files with no corresponding open-source implementation.
  • 🚩 Documentation that aggressively promotes powerful automation capabilities while completely ignoring data security mechanisms, repeatedly urging users to 'run the command now to experience it.'
  • 🚩 A lack of genuine historical interaction in developer communities, or comment sections filled with praise from recently registered, empty accounts.

真实案例

  • In July 2026, security agencies exposed the 'AgentBaiting' supply chain attack, where perpetrators released up to 800 fake AI skills and MCP servers on open-source platforms, tricking developers into installing them to plant malware and steal data (Source: In-depth analysis by Jiayun Tech Blog).
  • Security researchers tracked the 'FakeGit' open-source poisoning campaign, which disguised over 7,600 malicious repositories as popular automation plugins, resulting in the theft of credentials from a large number of unprepared developer servers (Source: CN-SEC tracking report).
  • A forensic investigation into AI cross-agent attack chains revealed that a hacker used a fake vulnerability scanner called 'AgentForger' to trick corporate admins into installing it, subsequently gaining control over the company's internal core LLM interface to launch a ransomware attack (Source: Developer Security Bulletin).

Official Stance

  • In April 2026, the Office of the Central Cyberspace Affairs Commission issued the 'Interim Measures for the Management of AI Anthropomorphic Interactive Services,' explicitly requiring AI service providers to conduct security assessments to prevent supply chain poisoning via automated interfaces.
  • In 2026, the Cyberspace Administration of China reported on the investigation of the website 'www.4stoken.cn' for the illegal operation of AI model interfaces, warning developers to be wary of third-party AI interfaces and tools of unknown origin to avoid becoming a technical springboard for cybercrime.
  • Throughout 2026, various local cyberspace departments and cybersecurity emergency response centers issued multiple risk warnings, cautioning enterprises against malicious programs like 'FakeSvc' that masquerade as AI applications and automation services to conduct large-scale cryptojacking and Trojan distribution.

How to Protect Yourself

  • ✅ Only acquire AI automation plugins from official stores or internal sources subject to strict organizational audits; never blindly download open-source toolkits from suspicious or unauthorized origins.
  • ✅ Before introducing third-party automation tools, enterprises must conduct comprehensive code reviews and runtime testing in a physically isolated sandbox environment; running unaudited installation scripts in production is strictly prohibited.
  • ✅ Strictly follow the principle of least privilege when configuring connection keys for automation tools, granting only the minimum read-only access required for a single task; never provide super-admin or global write permissions.
  • ✅ Implement key isolation and dynamic management tools to perform regular rotation and monitoring of cloud service access keys in development environments, immediately blocking and initiating emergency responses upon detecting abnormal outbound data transmission requests.