FakeGit malware campaign returns with 17,610 malicious GitHub repos
Description
The FakeGit malware campaign has resurfaced, distributing the SmartLoader malware through over 17,000 fake GitHub repositories. These repositories use convincing README files with download links to ZIP archives containing SmartLoader, which then delivers additional malware such as the StealC infostealer. The campaign leverages both throwaway and apparently legitimate developer accounts to maintain a large and persistent malicious repository fleet. Attempts to remove these repositories are ineffective due to the attackers' use of multiple backup copies and alternative download locations within GitHub. Users are advised to verify repository ownership and rely on official sources for software installations.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The FakeGit campaign involves a large-scale operation distributing SmartLoader malware via fake GitHub repositories. After reactivating in early October 2026, the campaign expanded to 17,610 malicious repositories, many of which were repurposed from an existing fleet. The repositories typically contain README instructions with download buttons linking to ZIP archives that install SmartLoader, which subsequently delivers other malware such as the StealC infostealer. The campaign uses a mix of throwaway and legitimate developer accounts to evade detection. Removal efforts are hindered by the presence of backup copies in forks, older files, release assets, and issue attachments, allowing attackers to quickly redirect download links. Researchers recommend verifying repository ownership and using official registries or vendor repositories for installing software components.
Potential Impact
The campaign enables widespread distribution of SmartLoader malware and the StealC infostealer through fake GitHub repositories, potentially compromising users who download and execute the malicious payloads. The persistence and scale of the campaign make it difficult to fully remove the threat from GitHub, increasing the risk of infection. Compromise may lead to information theft and further malware deployment. Users of GitHub and related software supply chains are at risk if they rely on unverified repositories.
Defensive Guidance
Users should verify the ownership of GitHub repositories before downloading or executing any code, especially for AI skills or MCP servers. Only use official registries or vendor repositories for software installations. If SmartLoader execution is suspected, treat it as a potential GitHub account compromise by revoking active sessions and access tokens and transitioning to passkeys. Due to the campaign's persistence and use of backup copies, removal of individual repositories or files is ineffective. Continuous vigilance and reliance on trusted sources are essential.
Technical Details
- Classification
- {"confidence":0.76,"severitySource":"default","classifier":"rss-v2"}
- Article Source
- {"url":"https://www.bleepingcomputer.com/news/security/fakegit-malware-campaign-returns-with-17-610-malicious-github-repos/","fetched":true,"fetchedAt":"2026-10-08T17:19:42.015Z","wordCount":739}
Threat ID: 6ac7d0b02cdf04f6562ba01a
Added to database: 10/08/2026, 17:19:44 UTC
Last enriched: 10/08/2026, 17:20:02 UTC
Last updated: 10/09/2026, 00:56:19 UTC
Views: 9
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.