logo

FakeGit campaign uses 7,600 GitHub repos to push SmartLoader malware

ID: 18ad7d5f-0327-5a97-a6d9-47ac530cb124

STIX ID: report--18ad7d5f-0327-5a97-a6d9-47ac530cb124

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2026-07-21

Date Updated: 2026-07-21

Author: Bill Toulas

...
...

A large-scale campaign named FakeGit used thousands of malicious GitHub repositories and public AI registries to distribute SmartLoader and the StealC information stealer; the operation employed a technique called "AgentBaiting" to lure AI agents and developers into downloading disguised payloads, established persistence via scheduled tasks, resolved C2 through a Polygon smart contract, and delivered additional encrypted stages — Island researchers observed extensive repository proliferation and recorded millions of download events though not all indicate successful infections.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.