Science & Tech · Cybersecurity · 2 days ago

FakeGit campaign spreads SmartLoader through 17,610 GitHub repositories

FakeGit campaign spreads SmartLoader through 17,610 GitHub repositories

The FakeGit campaign has resumed on GitHub, where researchers found 17,610 repositories distributing SmartLoader.

The campaign uses repository pages with convincing instructions and a download button that leads to a ZIP file containing the malware.

SmartLoader can then deliver other malware, including StealC, which steals information.

Many repositories present themselves as AI skills or MCP servers, making them look like tools developers may want to use.

Researchers say the campaign resumed on October 4 and added more than 13,000 repositories in 34 hours.

The operation is hard to stop because attackers can change download links or use backup files while keeping repositories active.

Users are advised to check who owns a repository and get AI tools from official registries or vendor repositories.

If SmartLoader may have run, users should treat it as a possible account compromise, revoke active sessions and access tokens, and consider using passkeys.

Sources

Related news