logo

FakeGit Campaign Uses 7,600 GitHub Repos to Push SmartLoader Malware

ID: 3402dec8-3ecb-55ea-a31b-c9398d34ff46

STIX ID: report--3402dec8-3ecb-55ea-a31b-c9398d34ff46

Feed Name: CosmicBytez Labs

Threat Score
75/100

Date Published: 2026-07-21

Date Updated: 2026-07-22

...
...

A large-scale campaign called FakeGit abused GitHub to host ~7,600 malicious repositories (14M+ downloads) that distributed SmartLoader, a multi-stage loader which fetched the StealC infostealer to exfiltrate browser credentials, crypto wallets and application secrets; the report details repository lures, behavioral and file indicators, scanning steps, and recommended developer and organizational mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.