ONLINE
LA--:--:--
ATL--:--:--
LDN--:--:--
LIVE WIRE
FACEIN.ID SDK — passwordless login for your app — targeting public launch Friday, July 31, 2026HUGGING FACE confirms a breach exposing internal datasets and credentials — another reminder that stored secrets are the targetDEEPFAKE DETECTION market expands as Deloitte projects up to $40B in US generative-AI fraud losses by 2027FACEIN.ID SDK — passwordless login for your app — targeting public launch Friday, July 31, 2026HUGGING FACE confirms a breach exposing internal datasets and credentials — another reminder that stored secrets are the targetDEEPFAKE DETECTION market expands as Deloitte projects up to $40B in US generative-AI fraud losses by 2027
← THE PASSWORDLESS POST
thePasswordlessPOSTIDENTITY · ACCESS · SECURITY
05

You Starred the Repo, Installed the MCP Server, and Handed Over Every Token You Own

Issue #5 · July 2026 · by Mazy Holiday

FakeGit — 7,600 cloned repos impersonating AI tools, dropping an infostealer.

You googled an MCP server for your AI agent, starred the repo, and installed a credential stealer. Here's how to tell the difference — and why the answer is to stop having credentials worth stealing.

7,600 Repos That Look Exactly Like the Real Ones

The FakeGitcampaign cloned over 7,600 legitimate GitHub repositories, dressed each one up as an AI “skill” or an MCP server, and used them to drop the StealC infostealer onto developer machines. StealC does the boring, brutal thing infostealers do: it sweeps passwords, cookies, and tokens straight off the workstation and ships them out. No zero-day, no clever memory trick — a real-looking repo, a plausible install step, and a developer in a hurry.

This is not a phishing email your parents fall for. This is your exact workflow, weaponized. You need an MCP integration for your agent. You search. You find a repo with a clean README, a sensible name, and a healthy star count. You install it. That is the entire attack. The supply chain is the search bar.

MCP Servers Are the New Risky OAuth

FakeGit connects to a broader, quieter shift: OAuth grants and MCP server connections have become the soft underbelly of SaaS security. Every MCP server you wire into an agent is a standing grant — a connection that can read, act, and pivot on your behalf across the services you've linked. Attackers figured out that they do not need to breach your provider if they can get you to authorize a malicious integration yourself. An OAuth token quietly lets them walk sideways through your SaaS, and an MCP connection hands an AI agent the keys to do it at machine speed.

“How to tell the difference” between a real repo and a poisoned clone is a genuinely hard question — the whole point of the campaign is that you can't, reliably, at a glance. Provenance checks, signed commits, and pinned dependencies help. But they are all bets on catching the fake before it runs. The moment one slips through, the game moves to what it can take.

What StealC Is Really After

Look at the loot list: passwords, cookies, tokens. Every item is a static, replayable secretsitting on your disk or in your browser profile. A saved password works from anywhere. A session cookie is a bearer token — whoever holds it is you. An OAuth refresh token keeps minting access long after you've forgotten the grant exists. Infostealers are lucrative for one reason: developer machines are stuffed with credentials that keep working after they're copied.

FaceIn: Make the Loot List Empty

FaceIn attacks the economics. With zero-knowledge biometric authentication, there is no reusable password to lift, no bearer cookie that grants access from a stranger's machine, no long-lived token that works once copied. Authorization is proven with cryptographic evidence bound to a real person and a specific request — evidence that is worthless the instant it leaves the moment it was created. StealC can still land on the machine. It sweeps the same folders. It finds nothing it can replay.

And FaceIn's account recovery has no backdoor— because “recover my account” is precisely the flow attackers abuse once they have your scraped tokens. There is no support-desk override, no secret reset path, no reusable recovery secret sitting where an infostealer would find it. The recovery system that usually becomes the attacker's on-ramp simply has nothing to hand them.

The Takeaway

You will install a poisoned repo eventually — 7,600 of them are out there wearing your favorite tools' faces, and “be more careful” has never once worked at scale. The durable defense is not a better eye for fakes. It is a machine that has nothing on it worth stealing. Stop storing replayable secrets, and the infostealer's entire business model collapses on your box.

→ Build with FaceIn — no tokens for an infostealer to lift

Get The Passwordless Post

New issues, straight to your inbox. No 2FA required.

Identity, authentication, and the slow death of the password — a few times a month. No spam, ever. Unsubscribe anytime.