FakeGit Campaign Uses 7,600 GitHub Repositories to Spread SmartLoader Malware
ID: cb8db5ec-aacf-5529-b374-49340e4a1375
STIX ID: report--cb8db5ec-aacf-5529-b374-49340e4a1375
Feed Name: The Hacker News
Cybersecurity researchers uncovered the FakeGit campaign that created ~7,600 malicious GitHub repositories (≈6,600 profiles) and more than 200 active campaign repositories, some posing as AI Skills or MCP servers to deliver a LuaJIT loader that deploys SmartLoader and then the StealC infostealer; over 14 million downloads across Release assets were observed. The campaign leverages copied projects, forged developer identities, convincing READMEs, and malicious ZIPs to socially engineer both humans and AI agents — a technique called AgentBaiting — into executing the attack chain; defenders are advised to vet and sandbox agent capabilities, verify publishers and projects, and catalog approved Skills/MCPs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
