bleeping-computer · Crawled Oct 8, 2026
FakeGit malware campaign returns with 17,610 malicious GitHub repos
1 IoCs 2 Malware
Read original article ↗
AI Summary
The FakeGit malware campaign has reemerged, leveraging 17,610 malicious GitHub repositories to distribute the SmartLoader malware, which in turn delivers the StealC infostealer. The attack uses throwaway and compromised developer accounts to host repositories with deceptive README files that include download links to malicious ZIP archives. The campaign rapidly redeployed, creating over 13,000 repositories in 34 hours, with 97% of commits modifying only the README to point to SmartLoader payloads. Attackers maintain persistence by using forks, release assets, and issue attachments to host backup copies of malware, evading takedown efforts.
AI-extracted · verify before operational use
Extracted Entities 2 found
Indicators of Compromise 1 extracted
| Type | Value | Detail |
|---|---|---|
| GitHub Repo | SmartLoader | Details → |
MITRE ATT&CK TTPs 10 techniques
T1059.001 PowerShell · Execution T1059.005 Visual Basic · Execution T1071.001 Web Protocols · Command And Control T1090 Proxy · Command And Control T1105 Ingress Tool Transfer · Command And Control T1106 Native API · Execution T1136 Create Account · Persistence T1170 T1170 T1195.001 Compromise Software Dependencies and Development Tools · Initial Access T1204.002 Malicious File · Execution