Threat
FakeGit malware campaign returns with 17,610 malicious GitHub repos
First reported bleepingcomputer.com
Page published · Page updated
Earliest dated coverage: 8 Oct 2026 · First observed: 8 Oct 2026 · Latest dated coverage: 8 Oct 2026
Coverage timeline
Single-source incident — one report is available.
Why it matters
FakeGit weaponizes trust in AI skill and MCP server registries, meaning developers pulling agentic tooling from GitHub catalogs can be lured into installing infostealer malware at scale.
The FakeGit campaign has reactivated with 17,610 malicious GitHub repositories distributing SmartLoader, which installs the StealC infostealer, according to Apiiro and earlier Island research. A notable subset of the fake repos masquerade as AI skills or MCP servers listed in public AI registries and catalogs, using convincing README instructions and a 'Download' button pointing to ZIP payloads; attackers survive takedowns by re-pointing lures to forks, release assets, and backup copies.
Summary
The FakeGit malware campaign has reactivated, using more than 17,610 fake GitHub repositories to distribute the SmartLoader malware loader, which in turn pushes the StealC infostealer. The campaign relies on convincing README instructions and a 'Download' button that points to a ZIP archive containing the initial SmartLoader payload.[0]
According to Apiiro, FakeGit resumed activity on October 4, pushing over 13,000 repos in just 34 hours and peaking at 2,999 repositories an hour. Rather than creating new repos, the operator re-aimed an existing fleet: 97% of sampled commits touched only the README and 88% repointed the download link to a SmartLoader ZIP.[0][2]
The operation has proven resilient because takedown lists cover only a fraction of malicious repos, and blocklisted payloads and backup copies remain accessible so attackers can simply change download links. Apiiro found 71% of the fleet was missing from URLhaus before its report.[0][2]
Attack chain
- Lure / Staging: Attackers maintain a large fleet of fake GitHub repositories, many posing as AI skills or MCP servers appearing in public AI registries and catalogs, with convincing README instructions and a prominent download button.[0]
- Re-pointing / Delivery: The operator re-aims existing repos by editing only the README (97% of sampled commits) to point the 'Download' button at a ZIP archive hosting the initial payload (88% of sampled commits).[0][2]
- Initial payload execution: The downloaded ZIP installs SmartLoader, a loader used to distribute additional malware.[0]
- Secondary payload: SmartLoader deploys the StealC infostealer to the victim system.[0]
- Persistence of infrastructure: Backup copies of malicious archives are kept in forks, older files, release assets, issue attachments, and separate download-hosting repositories, so deleting one link lets the operator point the lure at a spare copy.[0][2]
Disclosure timeline
| Date | Event |
|---|---|
| January (year unspecified) | Similar activity with various payloads observed distributing SmartLoader-style malware via fake GitHub repos.[0] |
| July (year unspecified) | Island published a report naming the operation 'FakeGit', covering 7,600 fake GitHub repositories pushing SmartLoader, 800 of which masqueraded as AI skills or MCP servers.[0] |
| October 4, 2026 | FakeGit resumed activity, pushing more than 13,000 repos in 34 hours.[0][2] |
| October 8, 2026 | BleepingComputer reported Apiiro's findings of 17,610 malicious repositories.[0] |
Actor profile
FakeGit
FakeGit is the name associated with this GitHub-based distribution operation since Island's July report. The operator maintains a large, persistent fleet of fake repositories, mostly using throwaway accounts though at least 700 appear to belong to legitimate developers (suggesting possible account compromise). The operation favors re-pointing existing repos over creating new ones and distributes SmartLoader as a loader for StealC.[0]
How it works
The campaign abuses GitHub's trust and takedown mechanics rather than a software vulnerability. Repository takedowns rely on lists covering only a fraction of malicious repos, and a domain-level DNS blocklist cannot block a single file on GitHub without blocking GitHub entirely, allowing the operator to swap download links while keeping the same repositories active.[0][2]
Key takeaways
- Link-level and list-based takedowns are ineffective against FakeGit because backup payload copies persist across forks, release assets, issue attachments, and separate hosting repos, letting operators re-point lures instead of rebuilding.[0][2]
- The campaign scaled rapidly by re-aiming an existing repository fleet rather than creating new repos, pushing over 13,000 repos in 34 hours with commits that mostly only edited the README's download link.[0][2]
Defensive actions
- Verify the repository owner before downloading, and install AI skills and MCP servers only from official registries or vendor repositories.: The campaign impersonates legitimate projects, including AI skills and MCP servers in public registries, to lure victims into downloading SmartLoader ZIPs.[0]
- If SmartLoader execution is suspected, treat the incident as a potential GitHub account compromise: revoke active sessions and access tokens and migrate to passkeys.: At least 700 malicious repos appear tied to legitimate developer accounts, indicating credential/token compromise risk.[0]