FakeGit floods GitHub with 17,610 malware repositories

FakeGit malware campaign returns with 17,610 malicious GitHub repos. The FakeGit campaign has reactivated with seventeen thousand six hundred ten GitHub repositories distributing SmartLoader and the StealC information stealer.

Daily Cyber News: FakeGit malware campaign returns with 17,610 malicious GitHub repos

The FakeGit campaign has reactivated with seventeen thousand six hundred ten GitHub repositories distributing SmartLoader and the StealC information stealer. More than thirteen thousand repositories were redirected in just 34 hours, often through convincing download buttons placed in README files. Researchers found that at least 700 accounts appeared to belong to legitimate developers.

Key context: Developers searching for tools, AI skills, or MCP servers may encounter repositories that look established and credible.

Additional detail: Restrict installations to verified sources and investigate unexpected downloads initiated from repository README files.

For more cybersecurity news and the full Daily Cyber newsletter, visit DailyCyber.News.
Cybersecurity training, courses, books, and resources: BareMetalCyber.com.

Topics: cybersecurity news, cybersecurity, cyber risk, malware, FakeGit, campaign, returns, malicious, GitHub, repos.

FakeGit floods GitHub with 17,610 malware repositories
Broadcast by