hacker-news · Crawled Jul 20, 2026

FakeGit Campaign Uses 7,600 GitHub Repositories to Spread SmartLoader Malware

1 IoCs 2 Malware
Read original article ↗

AI Summary

The FakeGit campaign leverages nearly 7,600 malicious GitHub repositories to distribute SmartLoader malware, often disguised as AI skills or Model Context Protocol (MCP) servers. These repositories use convincing READMEs and copied projects to trick both human users and AI agents into downloading malicious ZIP files. The attack chain involves a LuaJIT loader that drops SmartLoader, which then deploys StealC, an information stealer. A novel technique called AgentBaiting enables AI agents to autonomously discover and act on malicious repositories without human intervention, increasing the risk of supply chain compromise.

AI-extracted · verify before operational use

Extracted Entities 2 found

Indicators of Compromise 1 extracted

Type Value Detail
GitHub Repo https://github.com/FakeGit Details →

MITRE ATT&CK TTPs 10 techniques