// PC GAMER — GAMING
Welcome to the internet in 2026, where AI agents are both victim and attacker in malware wars
Let's hope safeguards develop in-line with AI agent capabilities.
When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works.
It might feel like an eternity that we've been living in this AI era, but really we're only at its advent. As such, many of the risks associated with it have until now been merely hypothetical. However, we're now seeing research filter out from security and software research teams that show some genuinely concerning behaviour, in particular when it comes to AI agents.
On the one hand, we have Island Technology explaining how it's uncovered thousands of malicious GitHub repos disguised as AI agent skills and Model Context Protocol (MCP) servers that the agents are at risk of downloading of their own discretion. On the other hand, we have the AI Security Institute (AISI) showing how the (unrestricted) AI agents it was using for cybersecurity attempted to dupe real people, using fake identities and pressuring people into accepting malicious code.
I remember when OpenClaw ('Moltbot', back then) first entered public consciousness with promises of actual agential behaviour to help solopreneurs and the likes do, umm, stuff and things. Without said solopreneurs having to do said stuff and things themselves—just hook your bot up to your different apps and services, tell it what to do, and let it cook. That wasn't too long ago, either; I reported on it in January.
How time flies. Now, talking about autonomous, agential AI seems pretty normal. And we're starting to see what this actually means in terms of security risks. We'd seen cases of AI agents running amok before, of course, but these newly identified risks seem a little more concrete.
In the first case, Island Technologies has discovered that fake GitHub repos pose a real threat for AI agents. These kinds of attacks existed previously, of course, but they attempted to dupe real humans who could personally assess them and take responsibility for vetting things thoroughly before downloading. The difference is these repos are now dressing up as AI agent skills and MCP servers to specifically target AI agents, which could download these repositories of their own 'volition'.
The Enterprise Browser creator explains: "The most significant shift is a technique we call AgentBaiting. An AI agent searching for a new capability such as a Skill or an MCP server can discover a campaign repository on its own, treat the attacker's Readme as legitimate documentation, and hand the installation instructions to the user.
In our testing, Claude Code, Gemini, and ChatGPT all surfaced malicious campaign repositories without ever being shown a link. A playbook built to deceive people now deceives the agents acting on their behalf."
Keep up to date with the most important stories and the best deals, as picked by the PC Gamer team.