FakeGit malware campaign returns with 17,610 malicious GitHub repos

The FakeGit malware campaign has made a comeback, with over 17,610 malicious repositories on GitHub distributing the SmartLoader malware. This resurgence marks a significant increase in activity, with the operators pushing out nearly 13,000 new repos in just 34 hours.

Researchers at Apiiro, a software supply-chain security platform, have been tracking this operation and report that it is using convincing README instructions to lure victims into downloading malicious ZIP archives. Once executed, these payloads can distribute other malware, including infostealers like StealC. What’s concerning is that the attackers are using legitimate-looking repositories, with at least 700 accounts belonging to what appear to be real developers.

The operators’ tactics have evolved since our previous reports on this campaign in July, when researchers identified around 7,600 fake GitHub repositories pushing the SmartLoader malware. Back then, we noted that some of these repositories masqueraded as AI skills or MCP servers that were listed in public AI registries and catalogs. Now, it seems the attackers have found ways to evade removal by the platform. According to Apiiro, removing repositories is based on lists that cover only a fraction of the malicious repos, leaving many still active.

This campaign’s persistence can be attributed, in part, to the fact that blocklisted payloads and backup copies remain accessible. Attackers can simply change the download links while keeping the same repositories active. In other words, deleting one link at a time is ineffective against this type of operation. The researchers found malicious archives hidden in forks, older files, release assets, issue attachments, and separate download-hosting repositories.

Apiiro’s findings highlight the need for users to be vigilant when interacting with GitHub repositories. To avoid falling victim to these attacks, it’s essential to verify the repository owner and source before installing AI skills or MCP servers. Official registries or vendor repositories should always be the preferred choice. If SmartLoader execution is suspected, treat the incident as a potential compromise of your GitHub account and take immediate action: revoke active sessions and access tokens, and consider switching to passkeys.

As we continue to navigate the complex landscape of cybersecurity threats, it’s essential to stay informed about emerging tactics and technologies used by attackers. By understanding these risks, we can better prepare ourselves for potential attacks and protect our digital assets.


Source: Bleeping Computer — 2026-10-08