logo

109 Fake GitHub Repositories Used to Deliver SmartLoader and StealC Malware

ID: 73d1d8b0-3b1d-52ab-822b-e50e3a168ad2

STIX ID: report--73d1d8b0-3b1d-52ab-822b-e50e3a168ad2

Feed Name: cybersecurityNews.com

Threat Score
78/100

Date Published: 2026-04-22

Date Updated: 2026-04-22

Author: Tushar Subhra Dutta

...
...

Hexastrike uncovered a large-scale campaign in which an attacker cloned legitimate GitHub projects across 109 repositories to host malicious ZIPs that install a LuaJIT-based loader (SmartLoader) and an in-memory infostealer (StealC); SmartLoader hides execution, performs anti-debug checks, resolves C2 via a Polygon blockchain dead-drop, exfiltrates data to bare-IP servers, and establishes dual scheduled-task persistence while staging additional payloads from attacker-controlled GitHub repositories.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.