Skip to main content

FakeGit malware campaign returns with 17,610 malicious GitHub repos

0
High
Malwaremalware
Published: 10/08/2026 (10/08/2026, 17:10:55 UTC)
Source: Bleeping Computer

Description

The FakeGit malware campaign has resurfaced, distributing the SmartLoader malware through over 17,000 fake GitHub repositories. These repositories use convincing README files with download links to ZIP archives containing SmartLoader, which then delivers additional malware such as the StealC infostealer. The campaign leverages both throwaway and apparently legitimate developer accounts to maintain a large and persistent malicious repository fleet. Attempts to remove these repositories are ineffective due to the attackers' use of multiple backup copies and alternative download locations within GitHub. Users are advised to verify repository ownership and rely on official sources for software installations.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 10/08/2026, 17:20:02 UTC

Technical Analysis

The FakeGit campaign involves a large-scale operation distributing SmartLoader malware via fake GitHub repositories. After reactivating in early October 2026, the campaign expanded to 17,610 malicious repositories, many of which were repurposed from an existing fleet. The repositories typically contain README instructions with download buttons linking to ZIP archives that install SmartLoader, which subsequently delivers other malware such as the StealC infostealer. The campaign uses a mix of throwaway and legitimate developer accounts to evade detection. Removal efforts are hindered by the presence of backup copies in forks, older files, release assets, and issue attachments, allowing attackers to quickly redirect download links. Researchers recommend verifying repository ownership and using official registries or vendor repositories for installing software components.

Potential Impact

The campaign enables widespread distribution of SmartLoader malware and the StealC infostealer through fake GitHub repositories, potentially compromising users who download and execute the malicious payloads. The persistence and scale of the campaign make it difficult to fully remove the threat from GitHub, increasing the risk of infection. Compromise may lead to information theft and further malware deployment. Users of GitHub and related software supply chains are at risk if they rely on unverified repositories.

Defensive Guidance

Users should verify the ownership of GitHub repositories before downloading or executing any code, especially for AI skills or MCP servers. Only use official registries or vendor repositories for software installations. If SmartLoader execution is suspected, treat it as a potential GitHub account compromise by revoking active sessions and access tokens and transitioning to passkeys. Due to the campaign's persistence and use of backup copies, removal of individual repositories or files is ineffective. Continuous vigilance and reliance on trusted sources are essential.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Classification
{"confidence":0.76,"severitySource":"default","classifier":"rss-v2"}
Article Source
{"url":"https://www.bleepingcomputer.com/news/security/fakegit-malware-campaign-returns-with-17-610-malicious-github-repos/","fetched":true,"fetchedAt":"2026-10-08T17:19:42.015Z","wordCount":739}

Threat ID: 6ac7d0b02cdf04f6562ba01a

Added to database: 10/08/2026, 17:19:44 UTC

Last enriched: 10/08/2026, 17:20:02 UTC

Last updated: 10/09/2026, 00:56:19 UTC

Views: 9

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses