bleeping-computer · Crawled Oct 8, 2026

FakeGit malware campaign returns with 17,610 malicious GitHub repos

1 IoCs 2 Malware
Read original article ↗

AI Summary

The FakeGit malware campaign has reemerged, leveraging 17,610 malicious GitHub repositories to distribute the SmartLoader malware, which in turn delivers the StealC infostealer. The attack uses throwaway and compromised developer accounts to host repositories with deceptive README files that include download links to malicious ZIP archives. The campaign rapidly redeployed, creating over 13,000 repositories in 34 hours, with 97% of commits modifying only the README to point to SmartLoader payloads. Attackers maintain persistence by using forks, release assets, and issue attachments to host backup copies of malware, evading takedown efforts.

AI-extracted · verify before operational use

Extracted Entities 2 found

Indicators of Compromise 1 extracted

Type Value Detail
GitHub Repo SmartLoader Details →

MITRE ATT&CK TTPs 10 techniques