The FakeGit malware campaign resumed activity on October 4, using 17,610 malicious GitHub repositories to distribute SmartLoader, which subsequently delivers malware including the StealC infostealer. Repositories masquerade as AI skills or Model Context Protocol (MCP) servers, attracting developers and users seeking legitimate tools. Convincing README files feature download buttons that redirect visitors to malicious ZIP archives. Apiiro researchers observed more than 13,000 repositories created within 34 hours, while the operation also reused and updated an existing repository fleet.
Incomplete repository removal, redundant payload copies across GitHub, and attackers’ ability to redirect existing repositories to new payloads allow the campaign to survive individual takedowns and undermine static blocklists. Researchers recommend verifying repository owners and obtaining AI skills, MCP servers, and other software from official sources rather than trusting polished README files. Organizations should treat suspected SmartLoader execution as a potential GitHub account compromise and investigate affected accounts and endpoints.

Pull IOCs and campaign context straight into your stack.
5 events from the most recent confirmed update back to the earliest known activity.
FakeGit resumed activity on October 4, using a fleet of 17,610 GitHub repositories to distribute SmartLoader and ultimately the StealC infostealer. Convincing README instructions and download buttons directed users to malicious ZIP archives.
Apiiro identified at least 700 associated accounts that appeared to belong to legitimate developers and reported that 71% of the repository fleet was absent from URLhaus before its report. Researchers also found redundant malicious archives across GitHub, allowing the operator to replace removed payload links with spare copies while keeping repositories active.
The operator pushed changes across more than 13,000 existing repositories within 34 hours, peaking at 2,999 repositories per hour. Apiiro found that 97% of sampled commits changed only the README and 88% redirected its download button to a ZIP archive that installs SmartLoader.
In July, Island researchers associated the FakeGit name with an operation using 7,600 fake GitHub repositories to distribute SmartLoader. They reported that 800 repositories masqueraded as AI skills or MCP servers and appeared in public AI registries and catalogs.
Researchers observed similar malicious GitHub repository activity involving various payloads since at least January. The operation was subsequently associated with the FakeGit name.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.