bleeping-computer · Crawled Jul 21, 2026
FakeGit campaign uses 7,600 GitHub repos to push SmartLoader malware
1 IoCs 1 Actors 2 Malware
Read original article ↗
AI Summary
The FakeGit campaign leverages over 7,600 malicious GitHub repositories to distribute SmartLoader and StealC malware, primarily through a technique called 'agentbaiting' that targets AI agents and developers. These repositories mimic legitimate AI tools and services, often appearing in public AI registries, and deliver malware via malicious ZIP files disguised as installers. SmartLoader establishes persistence, retrieves C2 addresses via a Polygon smart contract, and downloads further stages from GitHub to deploy the StealC information stealer.
AI-extracted · verify before operational use
Extracted Entities 3 found
Indicators of Compromise 1 extracted
| Type | Value | Detail |
|---|---|---|
| GitHub Repo | FakeGit | Details → |
MITRE ATT&CK TTPs 10 techniques
T1059.001 PowerShell · Execution T1059.005 Visual Basic · Execution T1071.001 Web Protocols · Command And Control T1090 Proxy · Command And Control T1105 Ingress Tool Transfer · Command And Control T1106 Native API · Execution T1136 Create Account · Persistence T1170 T1170 T1195.001 Compromise Software Dependencies and Development Tools · Initial Access T1204.002 Malicious File · Execution