logo

FakeGit Campaign Uses 7,600 GitHub Repositories to Spread SmartLoader Malware

ID: cb8db5ec-aacf-5529-b374-49340e4a1375

STIX ID: report--cb8db5ec-aacf-5529-b374-49340e4a1375

Feed Name: The Hacker News

Threat Score
78/100

Date Published: 2026-07-20

Date Updated: 2026-07-21

Author: [email protected] (The Hacker News)

...
...

Cybersecurity researchers uncovered the FakeGit campaign that created ~7,600 malicious GitHub repositories (≈6,600 profiles) and more than 200 active campaign repositories, some posing as AI Skills or MCP servers to deliver a LuaJIT loader that deploys SmartLoader and then the StealC infostealer; over 14 million downloads across Release assets were observed. The campaign leverages copied projects, forged developer identities, convincing READMEs, and malicious ZIPs to socially engineer both humans and AI agents — a technique called AgentBaiting — into executing the attack chain; defenders are advised to vet and sandbox agent capabilities, verify publishers and projects, and catalog approved Skills/MCPs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.