109 Fake GitHub Repos Spread SmartLoader, StealC Malware
ID: 8fcdc4bc-ab11-5ea7-ad20-7e3a083b88ca
STIX ID: report--8fcdc4bc-ab11-5ea7-ad20-7e3a083b88ca
Feed Name: GBHackers
**Executive summary:** A large-scale campaign is using fake, trojanized GitHub repositories to distribute a LuaJIT-based loader (SmartLoader) and a subsequent StealC infostealer; the operator embeds ZIP archives in cloned projects, ships an obfuscated Lua payload and renamed LuaJIT binaries, and resolves C2 dynamically via a Polygon smart contract to rotate infrastructure. Observed behaviors include in-memory PE loading, anti-analysis checks, screenshot and metadata exfiltration via multipart HTTP POSTs to bare-IP endpoints, scheduled-task persistence, and at least 109 malicious repositories across 103 GitHub accounts active through April 2026.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
