FakeGit malware campaign returns with 17,610 malicious GitHub repos
FakeGit returned with 17,610 GitHub repositories distributing SmartLoader and the StealC infostealer.
Apiiro says the FakeGit campaign resumed on October 4 and is using 17,610 GitHub repositories to distribute SmartLoader, which then delivers the StealC infostealer. In 34 hours the operator pushed more than 13,000 repositories, peaking at 2,999 an hour. In sampled commits, 97% changed only the README and 88% pointed a Download button at a ZIP that installs SmartLoader. Island previously tied the operation to 7,600 fake repositories in July, including about 800 posing as AI skills or MCP servers.
- Apiiro says FakeGit resumed on October 4 with 17,610 malicious GitHub repositories.
- More than 13,000 repositories were pushed in 34 hours, peaking at 2,999 an hour.
- About 88% of sampled README download buttons pointed to SmartLoader ZIP archives.
- SmartLoader delivers StealC; some repositories posed as AI skills or MCP servers.
- Forks, releases, and attachments let operators replace deleted payload links.
Full article466 words · extracted from bleepingcomputer.com · click to collapse

More than 17,000 fake repositories on GitHub are distributing the SmartLoader malware after the FakeGit campaign reactivated earlier this month to push the StealC infostealer.
The operator uses mostly throwaway accounts, but researchers identified at least 700 accounts that appear to belong to legitimate developers.
The malicious repositories use convincing README instructions with a download button pointing to a ZIP archive containing the initial payload, SmartLoader, that is used to distribute other malware.
While similar activity with various payloads has been observed since at least January, the FakeGit term was associated with this operation in July, when researchers at enterprise browser platform Island published a report on 7,600 fake GitHub repositories pushing the SmartLoader malware.
Island noted at the time that 800 of the malicious repositories masqueraded as AI skills or MCP servers that appeared in public AI registries and catalogs.
A new report from researchers at software supply-chain security platform Apiiro says that FakeGit resumed its activity on October 4 and now uses 17,610 repositories on GitHub.
In just 34 hours, FakeGit pushed more than 13,000 repos, peaking at 2,999 an hour.
"In the commits we sampled, 97% touched only the README, and 88% pointed its “Download” button at a ZIP that installs SmartLoader," Apiiro says.
"Nobody had to create a single new repo. The fleet was already there. It just got re-aimed," the researchers added.

Source: Apiiro
How FakeGit survived
According to the researchers, the reason behind FakeGit's survival is that removing repositories is based on lists that cover only a fraction of the malicious repos.
Also, blocklisted payloads and backup copies remain accessible, so attackers can simply change the download links while keeping the same repositories active.
“71% of the fleet was missing from URLhaus before our report, and a domain-level DNS blocklist can’t block one file on GitHub without blocking GitHub,” Apiiro explains.
The researchers found malicious archives in forks, older files, release assets, issue attachments, and separate download-hosting repositories, which makes deleting one link at a time ineffective.
“Delete one file and the operator can point the lure at a spare copy: a fork, an older ZIP, a release asset or an issue attachment,” the researchers said.
Apiiro researchers recommend that users verify the repository’s owner. Furthermore, the source for installing AI skills and MCP servers should be official registries or vendor repositories.
If SmartLoader execution is suspected, users should treat the incident as a potential GitHub account compromise, revoke active sessions and access tokens, and move to passkeys.
Build your security blueprint for AI-powered attacks
Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.