SmartLoader is a Windows malware loader implemented in obfuscated Lua and executed through LuaJIT. It deploys additional malicious stages and information stealers, including StealC. Distribution campaigns use counterfeit or cloned GitHub repositories that impersonate legitimate open-source projects, AI tools, developer utilities, AI skills, and Model Context Protocol (MCP) servers. Convincing documentation and download buttons direct users to ZIP archives presented as installers or project releases. Executing an included launcher starts a bundled LuaJIT interpreter and the concealed Lua payload.
SmartLoader uses LuaJIT foreign-function interfaces to invoke Windows APIs. It fingerprints infected systems, collects operating-system and geolocation information, captures desktop screenshots, and transmits collected data to command-and-control infrastructure through encrypted beacons and HTTP requests. Evasion mechanisms include script obfuscation, anti-debugging and anti-tampering checks, suppressed console windows, and separation of the launcher, interpreter, and malicious script into superficially innocuous components. It establishes persistence through scheduled tasks; observed variants support both locally cached stages and recovery paths that retrieve fresh encrypted stages from GitHub.
SmartLoader uses EtherHiding to resolve command-and-control addresses dynamically from a Polygon smart contract through public blockchain RPC services. This allows operators to rotate infrastructure without rebuilding the loader. Multi-stage chains download and execute additional Lua components and final payloads, with observed follow-on stages injecting StealC into another process. Credential and browser-session theft in these chains is performed by the delivered information stealer rather than being an established core SmartLoader function.
SmartLoader is associated with the FakeGit operation and its AgentBaiting tactic, which exposes fraudulent AI integrations through public capability catalogs and AI-assisted discovery. Campaigns have targeted AI users and developers, with affected organizations in financial services, banking, and technology across North America, Asia, and Southern Europe.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Together, the four files make up SmartLoader, a malware loader Netskope has previously seen distributed through GitHub repositories.
There has been an extensive malware campaign, dubbed FakeGit, that utilizes thousands of counterfeit GitHub repositories to distribute SmartLoader malware... Upon activation, the attack launches a LuaJIT-based loader that launches an obfuscated Lua script to install SmartLoader.
A newly documented campaign called AgentBaiting uses fraudulent AI Skills and Model Context Protocol, or MCP, servers to distribute SmartLoader malware through trusted-looking GitHub projects and public capability catalogs.
31 distinct techniques documented for this family, organized by ATT&CK tactic.
Threat actors are actively targeting public GitHub repositories that share tools such as game cheats, Claude code splitters, AI-powered security camera utilities, Amazon validators, coding extensions, and similar software. Attackers fork or clone legitimate repositories, then upload a malicious SmartLoader payload into them.
Scheduled Tasks: The script also creates schedules task under the following names for persistence. These tasks are configured to execute the malicious Lua script daily at a predetermined time.
The Lua script executes and connects to a Polygon RPC endpoint (leveraging the blockchain network for C2 retrieval).
Launcher.cmd – Command shell script file with command to execute the malicious Lua script using Luajit.exe
compiler.exe is a renamed LuaJIT interpreter... causing the interpreter to read and execute the contents of the text file
Scheduled Tasks: The script also creates schedules task under the following names for persistence. These tasks are configured to execute the malicious Lua script daily at a predetermined time.
Scheduled Tasks: The script also creates schedules task under the following names for persistence. These tasks are configured to execute the malicious Lua script daily at a predetermined time.
The Lua script is heavily obfuscated, and was obfuscated using the Prometheus Lua obfuscator.
The script dynamically loads multiple additional DLLs using ldrloaddll.
In this campaign, the attacker-controlled GitHub repository hosts two XOR encoded distinct payloads
The actor changes only the parts that influence user behavior: the README, the repository metadata, and the embedded archive.
The malware creates a mutex with the following long hardcoded name... This mutex prevents multiple instances of the payload from running simultaneously on the same machine.
After successfully deobfuscating the initial script, several sophisticated anti-debugging and anti-tampering mechanisms became clearly visible.
The payload performs connectivity and geolocation checks before proceeding to C2 communication
In the samples we analyzed, that SmartLoader stage hides execution, performs a native anti-debug check... fingerprints the host, captures a screenshot, exfiltrates the collected data...
The script enumerates the following user-specific directories: C:\Users\BBBB\AppData\Local\Temp\ C:\Users\BBBB\AppData\Roaming\ C:\Users\BBBB\Desktop\
After successfully deobfuscating the initial script, several sophisticated anti-debugging and anti-tampering mechanisms became clearly visible.
The payload constructs and sends a POST request to a Polygon blockchain RPC endpoint (polygon-rpc.com).
Once SmartLoader resolves the active server, it sends a POST request to /api/<base64_victim_id> on the bare-IP C2. The request body is multipart/form-data... The server responds with JSON...
EtherHiding is an advanced evasion and delivery technique in which attackers leverage blockchain networks as an intermediary infrastructure to host and retrieve command-and-control (C2) information and payload locations.
When unsuspecting users download and run the software from these compromised repositories, they unknowingly retrieve and execute the malicious Lua payload alongside the intended files.
148 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
35 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Initial malware payload distributed through fake GitHub repositories in the FakeGit campaign. Repositories masquerade as AI skills or MCP servers to lure developers and users seeking legitimate tools. SmartLoader subsequently distributes additional malware, including StealC.
An initial-stage malware loader distributed through ZIP archives linked from fake GitHub repositories. The FakeGit campaign uses it to deliver additional malware, including StealC. Apiiro reported 17,610 repositories in the renewed campaign; 88% of sampled commits pointed their download buttons to ZIP archives that install SmartLoader. Suspected execution should be treated as a potential GitHub account compromise.
A multi-file malware loader delivered via cloned GitHub repositories. It uses a renamed LuaJIT interpreter and a text-based payload to evade detection, gathers victim geolocation data, takes screenshots, resolves C2 via the Polygon blockchain using EtherHiding, and downloads a second-stage payload that ultimately delivers an infostealer.
A two-stage Lua-based loader distributed through cloned GitHub repositories impersonating legitimate AI and developer projects. A batch script launches a renamed LuaJIT interpreter to execute an obfuscated script disguised as a text file. SmartLoader collects the victim's public IP address, geolocation, time zone, internet provider, and a screenshot, then sends an encrypted command-and-control beacon. Both stages resolve their control-server address through a Polygon smart contract using EtherHiding, allowing operators to change infrastructure without redistributing the loader. The second stage downloads additional Lua code and information-stealing payloads from attacker-controlled GitHub accounts; observed payloads include an unnamed NodeJS-based stealer.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.