The FakeGit malware campaign has used more than 7,600 malicious GitHub repositories to spread SmartLoader and StealC malware. Public download counters recorded over 14 million download events across parts of the operation.
However, that figure does not represent confirmed infections. It includes repeated downloads and automated requests.
Researchers say the campaign increasingly targets developers and AI-tool users. More than 800 repositories posed as AI skills or Model Context Protocol servers. These listings appeared hundreds of times across public AI registries and catalogues.
Fake AI Tools Boost Repository Visibility
The campaign used a technique known as AgentBaiting. Attackers created repositories that appeared useful to AI agents, coding assistants, and developers searching for software tools.
Many of the pages looked convincing. They copied legitimate project descriptions and used familiar names from consumer and enterprise software. Some also displayed fabricated stars, forks, and other signals of popularity.
The repositories included detailed README files that resembled genuine installation documentation. These pages directed visitors to ZIP files presented as software installers or project releases.
In reality, the archives contained disguised Lua payloads. Opening them could launch SmartLoader on the victim’s computer.
SmartLoader Delivers StealC Malware
After execution, SmartLoader attempts to remain active on the affected device. It creates scheduled tasks to establish persistence.
The malware then retrieves its command-and-control address through a Polygon smart contract. Next, it downloads additional encrypted payloads from GitHub.
The final stage delivers StealC, an information-stealing malware family. Information stealers can target browser data, saved credentials, session tokens, cryptocurrency wallets, and other sensitive material.
The campaign reportedly expanded its AI focus in March and peaked in April. During that period, attackers created hundreds of repositories linked to AI tools, agents, and workflows.
Researchers ultimately identified more than 1,400 AI-related repositories connected to SmartLoader or StealC downloads.
AI Agents Can Surface Malicious Repositories
Public AI registries can make the malicious pages easier to discover. Researchers found more than 600 listings for skills and MCP servers associated with the FakeGit malware campaign.
In controlled tests, several AI systems surfaced malicious repositories in response to related prompts. In some cases, they also repeated the installation instructions found in the repository documentation.
One coding agent reportedly cloned a malicious repository and downloaded its files in a controlled environment. It then detected suspicious indicators and stopped before executing the payload.
These tests did not measure a reliable detection rate. Therefore, organisations should not assume that an AI tool will always identify a malicious repository before damage occurs.
How Organisations Can Reduce the Risk
Teams should maintain approved internal catalogues for AI skills, MCP servers, and development tools. They should also verify publishers independently before downloading code or installation files.
New tools should be tested in isolated environments. In addition, companies should restrict access to sensitive credentials during evaluation.
If SmartLoader execution is suspected, administrators should rotate all secrets on the affected systems immediately.
Conclusion
The FakeGit malware campaign shows how attackers can abuse open-source platforms and AI ecosystems to distribute malware at scale. Careful repository checks, controlled testing, and fast credential rotation can limit the damage from a successful infection.


0 responses to “FakeGit Malware Campaign Uses 7,600 GitHub Repos”