LIVE · cybersecurity feed
Live wire
malware

FakeGit campaign uses 7,600 GitHub repos to push SmartLoader malware

A large-scale operation dubbed 'FakeGit' is pushing SmartLoader and StealC malware through 7,600 malicious GitHub repositories that accumulated more than 14 million downloads. [...]

zeroday.news · 11d ago

A large-scale operation, dubbed "FakeGit" by researchers, has been observed distributing SmartLoader and StealC malware through approximately 7,600 malicious repositories hosted on GitHub. These repositories have collectively accumulated over 14 million download events.

The campaign is believed to be a continuation of an earlier operation that utilized Lumma Stealer and was previously attributed to a threat actor tracked as Water Kurita by Trend Micro. The current iteration of the campaign has introduced a significant focus on artificial intelligence (AI) tools, agents, and workflows, a technique researchers at Island refer to as "AgentBaiting."

The AI-centric approach began in March and saw a peak in April with the creation of 300 AI-related GitHub repositories. This number has since grown to over 1,400 such repositories, all linking to SmartLoader or StealC malware downloads. More than 800 repositories specifically pretended to be AI skills or MCP (Minecraft Pocket Edition) servers.

These malicious repositories are designed to appear legitimate, often imitating popular consumer and enterprise tools like Gmail, WhatsApp, Databricks, Jenkins, and Docker. They feature convincing documentation, fabricated star and fork counts, copied project descriptions, and even use real developer account names to enhance their credibility.

The `README` files within these repositories direct users to download ZIP archives, which are presented as installers or project releases. However, these archives contain disguised Lua payloads that initiate the SmartLoader malware. Once active, SmartLoader establishes persistence through scheduled tasks, retrieves its command-and-control (C2) address via a Polygon smart contract, and then downloads additional encrypted stages from GitHub, ultimately delivering the StealC information stealer.

The "AgentBaiting" technique aims to increase the visibility of these malicious repositories to AI agents and improve the likelihood of their adoption. Researchers suggest that AI agents are prone to parsing the `README` contents as legitimate documentation, potentially leading them to recommend the repository or its associated ZIP file to human operators.

Tests conducted by Island researchers showed that AI models such as ChatGPT, Gemini, and Claude surfaced various malicious repositories when prompted with related tasks, sometimes even relaying the malicious installation instructions. Furthermore, over 600 listings for skills and MCP servers linked to the FakeGit campaign were found in public registries and catalogs, including LobeHub, Glama, MCP.so, and MCP Market. This indicates that the operation has successfully infiltrated public resources, enhancing the discoverability and perceived credibility of the malicious repositories.

In controlled testing, Claude Code was observed cloning malicious repositories and downloading the malicious files onto a test machine. However, the agent subsequently detected suspicious indicators and halted execution before the malware could fully execute. These tests were not designed to establish a definitive detection rate for coding agents.

Regarding the overall impact, GitHub's public download counters for 335 unique Release assets across 211 FakeGit repositories recorded a cumulative 14,084,688 download events. Oleg Zaytsev, Lead Security Researcher at Island, clarified that this figure includes repeated requests and automated activity and should not be interpreted as the number of infections.

Organizations are advised to maintain approved catalogs of skills and MCP servers, test new capabilities in isolated environments, and independently verify publishers and repositories. In cases where SmartLoader execution is suspected, all secrets on affected environments should be immediately rotated.

malware
ShareXLinkedInWhatsAppFacebook

More News

view all →
phishing

Phishing Campaigns Targeting AI Solutions Providers, (Sat, Aug 1st)

Most phishing campaigns rely on the fact that the victim is afraid to loose "something": money, access to information, ... Many brands have been impersonated by campaigns but I spotted some phishing emails that focus on AI services like ChatGPT.

CVE-2026-48449

Adobe Campaign Classic CVSS 10.0 Flaw Could Run Code Without User Interaction

Adobe has released security updates to address a maximum-severity security flaw in Campaign Classic (ACC), its enterprise-focused marketing automation platform, that could result in arbitrary code execution. The vulnerability, tracked as CVE-2026-48449, carries a severity score of 10.0 on the CVSS scoring system. It has been described as a case of incorrect authorization that could result in

vulnerability

Elastic goes all-in on Hacker Summer Camp at Black Hat and DEF CON in Las Vegas

Attack Discovery turns raw alerts into validated threats and Elastic Defend closes vulnerable driver gaps as fast as they're disclosed. Watch it all run against real attacks at the booth.

breach

Hermes AI agent used to automate attack on Thai Finance Ministry

A threat actor used the open-source Hermes AI agent in unattended "YOLO" mode to automate post-exploitation activity during an alleged breach of Thailand's Ministry of Finance. [...]

security

Hackers hijack hotel Wi-Fi DNS to steal Microsoft 365 accounts

Hackers are changing the DNS settings on Wi-Fi devices at hotels and conference centers to redirect users to fake Microsoft 365 login pages. [...]

security

BGP ORIGIN attribute manipulation and its impact on the Internet

By doing in-depth testing, we found nearly 70% of BGP paths experience ORIGIN attribute rewrites by transit providers seeking traffic advantages. We examine the global impact of this practice and argue for deprecating ORIGIN in route selection.