FakeGit floods GitHub with 17,610 malware repositories

FakeGit malware campaign returns with 17,610 malicious GitHub repos. The FakeGit campaign has reactivated with seventeen thousand six hundred ten GitHub repositories distributing SmartLoader and the StealC information stealer.

This is a DailyCyber.News update, brought to you by BareMetalCyber.com, for Friday, October 9th, 2026.

The FakeGit campaign has reactivated with seventeen thousand six hundred ten GitHub repositories distributing SmartLoader and the StealC information stealer. More than thirteen thousand repositories were redirected in just 34 hours, often through convincing download buttons placed in README files. Researchers found that at least 700 accounts appeared to belong to legitimate developers. Malicious archives also remained available through forks, release assets, older files, and issue attachments, making one-link-at-a-time removal less effective.

Developers searching for tools, AI skills, or MCP servers may encounter repositories that look established and credible. Leaders should understand that trusted development platforms can become large-scale malware delivery channels without the platform itself being breached. Defenders should verify repository ownership and rely on official registries or vendor repositories for installation. If SmartLoader execution is suspected, teams should revoke sessions and access tokens and investigate possible account compromise.

Restrict installations to verified sources and investigate unexpected downloads initiated from repository README files.

For the sources and the full Daily Cyber newsletter, visit DailyCyber.News.

FakeGit floods GitHub with 17,610 malware repositories
Broadcast by