FakeGit campaign uses 7,600 GitHub repos to push SmartLoader malware

FakeGit campaign uses 7,600 GitHub repos to push SmartLoader malware
A large-scale campaign called FakeGit is using 7,600 malicious GitHub repositories to distribute SmartLoader and StealC, with more than 14 million recorded download events across public release assets. Researchers say the operation uses “agentbaiting” to lure AI agents and developers into trusting fake AI tools, while its roots appear tied to an earlier Lumma Stealer campaign linked to Water Kurita. #FakeGit #SmartLoader #StealC #LummaStealer #WaterKurita

Keypoints

  • FakeGit uses thousands of malicious GitHub repositories to spread SmartLoader and StealC.
  • More than 800 repositories impersonate AI skills or MCP servers to attract AI agents.
  • The campaign relies on fake documentation, copied descriptions, and inflated popularity signals.
  • README files trick users into downloading ZIP archives that deliver Lua payloads.
  • Researchers found the operation had spread into public AI catalogs and registries.

Read More: https://www.bleepingcomputer.com/news/security/fakegit-campaign-uses-7-600-github-repos-to-push-smartloader-malware/