FakeGit Floods GitHub With Over 17,000 Malware Repos


FakeGit campaign github
Image credit: Microsoft

The FakeGit campaign has resumed activity, flooding GitHub with more than 17,000 malicious repositories designed to distribute SmartLoader malware and the StealC information stealer.

The campaign became active again on October 4, 2026. Security researchers at Apiiro identified 17,610 repositories associated with the operation.

Most repositories use disposable GitHub accounts, but researchers found that at least 700 accounts appear to belong to legitimate developers, raising concerns about potential account compromises.

Attackers updated over 13,000 repositories in just 34 hours

The attackers create convincing GitHub repositories with README files containing download buttons. These buttons direct users to malicious ZIP archives that install SmartLoader, which then delivers additional malware, including the StealC information stealer.

The operation has expanded rapidly. Within just 34 hours, the attackers updated more than 13,000 repositories, reaching a peak of 2,999 repository updates per hour.

The campaign also exploits GitHub’s infrastructure to make malicious downloads appear legitimate, increasing the likelihood that developers and other users will trust the files.

Why removing malicious repositories is not enough

FakeGit has proven difficult to stop because attackers maintain multiple copies of their malicious payloads across GitHub.

Researchers discovered that 71% of the malicious repository network was absent from the URLhaus threat intelligence database before their report.

Attackers distribute backup payloads through repository forks, older files, release assets, issue attachments, and separate download-hosting repositories. When security teams remove or block one malicious link, the attackers can redirect victims to another existing copy.

Domain-level DNS blocking also presents a challenge because GitHub hosts legitimate projects alongside malicious files. Blocking individual malicious downloads through DNS without affecting the broader platform is not possible.

GitHub users should verify downloads and secure their accounts

Researchers recommend verifying repository ownership before downloading or executing files, particularly when projects direct users to ZIP archives through README download buttons.

Developers should also install AI skills and Model Context Protocol (MCP) servers only from trusted official registries or vendor repositories.

Anyone who suspects they executed SmartLoader should consider their GitHub account potentially compromised, revoke active sessions and access tokens, and switch to passkeys to strengthen account security.

The campaign adds to recent security concerns involving trusted online services. Other incidents include hackers hijacking Google domains and obtaining valid HTTPS certificates, fake ChatGPT and Gemini websites stealing MFA codes, and account breaches affecting Microsoft 365 and Google Workspace environments.

Via BleepingComputer

More about the topics: Cybersecurity, Github

Readers help support Windows Report. We may get a commission if you buy through our links. Tooltip Icon

Read our disclosure page to find out how can you help Windows Report sustain the editorial team. Read more

User forum

0 messages