FakeGit malware campaign returns with 17,610 malicious GitHub repos

A massive malware campaign has resurfaced on GitHub, with over 17,610 fake repositories spreading the SmartLoader malware. This is a significant threat that highlights the ongoing challenges in securing online development platforms and the importance of vigilance for developers.

The FakeGit campaign, which first came to light in July when researchers at Island published a report on 7,600 fake GitHub repositories pushing the SmartLoader malware, has been reactivated with renewed vigor. According to Apiiro, a software supply-chain security platform, the campaign resumed its activity on October 4 and has since created a staggering number of malicious repositories. In just 34 hours, FakeGit pushed over 13,000 repos, peaking at an astonishing 2,999 per hour.

The malicious repositories use convincing README instructions with a download button pointing to a ZIP archive containing the initial payload, SmartLoader. This malware is used to distribute other malicious software, and its operators have been clever in using throwaway accounts to evade detection. However, researchers identified at least 700 accounts that appear to belong to legitimate developers, suggesting that FakeGit’s tactics are becoming increasingly sophisticated.

The reason behind FakeGit’s survival lies in the limitations of current security measures. Removing repositories is based on lists that cover only a fraction of the malicious repos, leaving many gaps for attackers to exploit. Moreover, blocklisted payloads and backup copies remain accessible, allowing attackers to simply change download links while keeping the same repositories active.

The researchers found that deleting one link at a time is ineffective due to the presence of malicious archives in forks, older files, release assets, issue attachments, and separate download-hosting repositories. This means that even if one file is deleted, the operator can easily point the lure at a spare copy, rendering efforts to remove malware from GitHub repositories futile.

To protect themselves, developers should verify the repository’s owner and ensure that they are installing AI skills and MCP servers from official registries or vendor repositories. If SmartLoader execution is suspected, users should treat the incident as a potential GitHub account compromise, revoke active sessions and access tokens, and move to passkeys.

The FakeGit campaign serves as a stark reminder of the importance of security awareness in online development platforms. As the threat landscape continues to evolve, it is crucial for developers to stay vigilant and adopt best practices to prevent such attacks from succeeding.


Source: Bleeping Computer — 2026-10-08