FakeGit Campaign Floods GitHub With 7,600 Malware Repositories
The FakeGit malware campaign is using thousands of malicious GitHub repositories to distribute SmartLoader and the StealC information stealer to developers and AI users.
Researchers identified approximately 7,600 repositories connected to the operation. GitHub download counters showed more than 14 million cumulative downloads, although that figure does not represent confirmed malware infections.
The campaign appears linked to an older operation associated with the Water Kurita threat actor.
FakeGit Targets AI Tools and MCP Servers
A significant part of the campaign focuses on the growing ecosystem surrounding artificial intelligence tools.
Researchers found more than 1,400 repositories claiming to provide AI agents, skills, Model Context Protocol servers, and automated workflows. More than 800 of those repositories specifically posed as AI skills or MCP servers.
FakeGit-linked entries also appeared more than 600 times across public AI registries and software catalogs.
Researchers describe this discovery and distribution technique as “AgentBaiting.” Attackers design malicious projects to attract both developers searching for tools and AI assistants gathering installation recommendations.
Malicious Repositories Imitate Popular Services
FakeGit repositories impersonate widely used products and platforms, including Gmail, WhatsApp, Databricks, Jenkins, and Docker.
The repositories use several tactics to appear legitimate, including copied descriptions, professional-looking documentation, fake star and fork counts, and the names of real developers. They also include detailed installation instructions and README files designed to resemble official project pages.
The README files direct visitors to download ZIP archives presented as software installers, releases, integrations, or development tools.
Instead of legitimate applications, the archives contain disguised payloads that begin the malware infection chain.
SmartLoader Installs the StealC Information Stealer
The downloaded ZIP files contain disguised Lua payloads that launch SmartLoader on the targeted system.
SmartLoader then creates scheduled tasks to maintain persistence after the computer restarts. It retrieves command-and-control information through a smart contract hosted on the Polygon blockchain.
Using a blockchain contract can make infrastructure harder to remove because attackers can update connection details without relying on a traditional command-and-control domain.
SmartLoader downloads additional encrypted payloads from GitHub before installing StealC as the final stage.
StealC can collect sensitive information from compromised systems, including browser data, authentication credentials, session cookies, cryptocurrency wallet information, and other stored secrets.
AgentBaiting Can Influence AI Assistants
FakeGit repositories do not only target people manually searching GitHub. Attackers also structure the repositories so AI assistants may identify, parse, and recommend them.
An AI assistant reviewing a convincing README file may treat its installation commands as legitimate, especially when the repository appears in public catalogs or imitates a trusted service.
During controlled tests, ChatGPT, Gemini, and Claude reportedly surfaced some malicious FakeGit repositories while completing related tasks.
Claude Code reportedly cloned malicious repositories and downloaded files before identifying suspicious activity and stopping execution.
The findings highlight the risks of allowing AI coding agents to search for, download, and execute software without strict approval controls. This is also not the first case involving AI assistants interacting with malicious files hosted in GitHub repositories.
Public AI Registries Increased FakeGit Visibility
FakeGit-linked AI skills and MCP servers appeared in several public catalogs, including LobeHub, Glama, MCP.so, and MCP Market.
Listings in these directories increased the visibility of the malicious projects and made them appear more trustworthy to developers and AI agents.
Researchers could not determine whether attackers submitted the entries manually or whether automated indexing systems collected them directly from GitHub.
Regardless of the method, public directory listings gave the repositories another layer of apparent legitimacy beyond GitHub stars, forks, descriptions, and developer names.
How Organizations Can Reduce the Risk
Organizations using AI agents, MCP servers, or downloadable development tools should maintain an approved internal catalog of trusted software.
Security teams should independently verify repository owners, publishers, commit histories, release files, and external download links before allowing installation.
New AI skills, agents, and MCP servers should run in isolated environments before receiving access to corporate systems, source code, credentials, or production data.
Organizations should also prevent AI assistants from automatically cloning repositories, downloading archives, or executing installation commands without human approval.
If SmartLoader execution is suspected, security teams should isolate the affected system and immediately rotate passwords, API keys, access tokens, browser sessions, cryptocurrency wallet credentials, and other secrets stored on the device.
In other news, BoryptGrab malware is spreading through GitHub repositories, while hackers are exploiting a critical SharePoint flaw to steal machine keys.
Via BleepingComputer
Read our disclosure page to find out how can you help Windows Report sustain the editorial team. Read more
User forum
0 messages