bleeping-computer · Crawled Jul 21, 2026

FakeGit campaign uses 7,600 GitHub repos to push SmartLoader malware

1 IoCs 1 Actors 2 Malware
Read original article ↗

AI Summary

The FakeGit campaign leverages over 7,600 malicious GitHub repositories to distribute SmartLoader and StealC malware, primarily through a technique called 'agentbaiting' that targets AI agents and developers. These repositories mimic legitimate AI tools and services, often appearing in public AI registries, and deliver malware via malicious ZIP files disguised as installers. SmartLoader establishes persistence, retrieves C2 addresses via a Polygon smart contract, and downloads further stages from GitHub to deploy the StealC information stealer.

AI-extracted · verify before operational use

Extracted Entities 3 found

Indicators of Compromise 1 extracted

Type Value Detail
GitHub Repo FakeGit Details →

MITRE ATT&CK TTPs 10 techniques