Malware
SmartLoader
Indicators of Compromise 2
MITRE ATT&CK TTPs 10
T1059.001 T1059.005 T1071.001 T1090 T1105 T1106 T1136 T1170 T1195.001 T1204.002
PowerShell
Execution
Visual Basic
Execution
Web Protocols
Command And Control
Proxy
Command And Control
Ingress Tool Transfer
Command And Control
Native API
Execution
Create Account
Persistence
T1170
Compromise Software Dependencies and Development Tools
Initial Access
Malicious File
Execution
Source Articles
FakeGit campaign uses 7,600 GitHub repos to push SmartLoader malware
The FakeGit campaign leverages over 7,600 malicious GitHub repositories to distribute SmartLoader and StealC malware, primarily through a technique called 'agentbaiting' that targets AI agents and developers. These repositories mimic legitimate AI tools and services, often appearing in public AI registries, and deliver malware via malicious ZIP files disguised as installers. SmartLoader establishes persistence, retrieves C2 addresses via a Polygon smart contract, and downloads further stages from GitHub to deploy the StealC information stealer.
bleeping-computer ·6d ago
FakeGit Campaign Uses 7,600 GitHub Repositories to Spread SmartLoader Malware
The FakeGit campaign leverages nearly 7,600 malicious GitHub repositories to distribute SmartLoader malware, often disguised as AI skills or Model Context Protocol (MCP) servers. These repositories use convincing READMEs and copied projects to trick both human users and AI agents into downloading malicious ZIP files. The attack chain involves a LuaJIT loader that drops SmartLoader, which then deploys StealC, an information stealer. A novel technique called AgentBaiting enables AI agents to autonomously discover and act on malicious repositories without human intervention, increasing the risk of supply chain compromise.
hacker-news ·1w ago