Application security, Third-party code

FakeGit campaign reactivates, distributing SmartLoader malware via GitHub

(Credit: Robert – stock.adobe.com)

More than 17,000 fake repositories on GitHub are currently distributing the SmartLoader malware, a reactivation of the FakeGit campaign that began earlier this month to push the StealC infostealer, with further coverage provided by Bleeping Computer.

The FakeGit campaign, first identified in July, has resurfaced with over 17,610 malicious repositories on GitHub. Researchers observed a significant surge in activity, with over 13,000 repositories created in just 34 hours. The campaign primarily uses convincing README files with "download" buttons that link to ZIP archives containing the SmartLoader malware. This initial payload is then used to distribute other malware, including the StealC infostealer. The operation's persistence is attributed to GitHub's repository removal policies, which often miss a large portion of malicious content. Attackers can easily re-point existing repositories to new malicious payloads, making traditional blocklisting ineffective. The repositories often masquerade as AI skills or MCP servers, targeting developers and users seeking legitimate tools. Apiiro researchers recommend verifying repository owners and obtaining software from official sources to mitigate risks. If SmartLoader execution is suspected, users should treat it as a potential account compromise, revoke sessions, and consider implementing passkeys.

Source: Bleeping Computer

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds