hacker-news · Crawled Jul 20, 2026
FakeGit Campaign Uses 7,600 GitHub Repositories to Spread SmartLoader Malware
1 IoCs 2 Malware
Read original article ↗
AI Summary
The FakeGit campaign leverages nearly 7,600 malicious GitHub repositories to distribute SmartLoader malware, often disguised as AI skills or Model Context Protocol (MCP) servers. These repositories use convincing READMEs and copied projects to trick both human users and AI agents into downloading malicious ZIP files. The attack chain involves a LuaJIT loader that drops SmartLoader, which then deploys StealC, an information stealer. A novel technique called AgentBaiting enables AI agents to autonomously discover and act on malicious repositories without human intervention, increasing the risk of supply chain compromise.
AI-extracted · verify before operational use
Extracted Entities 2 found
Indicators of Compromise 1 extracted
| Type | Value | Detail |
|---|---|---|
| GitHub Repo | https://github.com/FakeGit | Details → |
MITRE ATT&CK TTPs 10 techniques
T1059.001 PowerShell · Execution T1059.005 Visual Basic · Execution T1071.001 Web Protocols · Command And Control T1090 Proxy · Command And Control T1105 Ingress Tool Transfer · Command And Control T1106 Native API · Execution T1136 Create Account · Persistence T1170 T1170 T1195.001 Compromise Software Dependencies and Development Tools · Initial Access T1204.002 Malicious File · Execution