Jump to content
  • FakeGit campaign uses 7,600 GitHub repos to push SmartLoader malware

    Karlston

    • 87 views
    • 4 minutes
     Share


    • 87 views
    • 4 minutes

    A large-scale operation dubbed ‘FakeGit’ is pushing SmartLoader and StealC malware through 7,600 malicious GitHub repositories that accumulated more than 14 million downloads.

     

    Over 800 repositories pretended to be AI skills or MCP servers and appeared more than 600 times in public AI registries and catalogs. This increased the likelihood of being discovered by AI agents and developers, a technique that researchers call "agentbaiting."

     

    The campaign is considered a continuation of an older operation that used Lumma Stealer and was attributed to a threat actor tracked as “Water Kurita” by researchers at cybersecurity company Trend Micro.

     

    According to researchers at the enterprise browser platform Island, the AI focus was introduced in March and peaked in April, with the creation of 300 GitHub repositories linked to AI tools.

     

    Researchers found that FakeGit grew to more than 1,400 repositories related to AI tools, agents, and workflows, all linking to SmartLoader or StealC  malware downloads.

    Malicious GitHub repository
    Malicious GitHub repository
    Source: Island

    Many of the repositories imitate consumer and enterprise tools such as Gmail, WhatsApp, Databricks, Jenkins, and Docker, and include convincing documentation, fabricated stars and fork counts, copied project descriptions, and real developer account names.

     

    Their README files direct visitors to download ZIP archives that pose as installers or project releases but are disguised Lua payloads that trigger SmartLoader.

     

    Once SmartLoader is active, it establishes persistence through scheduled tasks, retrieves its command-and-control (C2) address through a Polygon smart contract, and downloads additional encrypted stages from GitHub, ultimately delivering the StealC information stealer.

    The AgentBaiting technique

    Researchers at Island say the malicious repositories are part of an emerging technique they call AgentBaiting, which is designed to increase their visibility to AI agents and improve the chances of being used.

     

    In a typical scenario, agents are likely to parse the README contents as legitimate documentation and recommend the repository or ZIP file to the human operator.

    Malicious README file
    Malicious README file
    Source: Island

    In Island’s tests, ChatGPT, Gemini, and Claude surfaced various malicious repositories when prompted with related tasks, and sometimes relayed the installation instructions.

     

    Island found in public registries and catalogs more than 600 listings for skills and MCP servers that were linked to the FakeGit campaign. Some of them included LobeHub, Glama, MCP.so, and MCP Market, indicating that the operation has already penetrated the ecosystem and poisoned public resources.

     

    The researchers could not determine if listings were submitted manually or indexed automatically, but said their presence made the repositories easier to discover and added to their credibility.

     

    Island researchers told BleepingComputer that in limited, controlled testing, Claude Code cloned malicious repositories and downloaded the malicious files onto the test machine.

     

    However, the agent subsequently detected suspicious indicators and stopped before execution.

     

    The tests were not designed to establish a detection rate, so they cannot provide conclusive results on whether coding agents can consistently recognize the danger during the execution stage.

    Attack chain
    Attack chain
    Source: Island

    Concerning the broader impact of the campaign, Island reports that GitHub’s public download counters for 335 unique Release assets across 211 GitFake repositories recorded 14,084,688 cumulative download events.

     

    Oleg Zaytsev, Lead Security Researcher at Island, clarified that this figure included repeated requests and automated activity, so it should not be interpreted as infections.

     

    Island recommends that organizations maintain approved catalogs of skills and MCP servers, test new capabilities in isolated environments, and verify publishers and repositories independently.

     

    Where SmartLoader execution is suspected, all secrets on impacted environments should be rotated immediately.

     

    Source


    Hope you enjoyed this news post. Feedback welcome.

    Posted Wednesday 22 July 2026 at 9:21 am AEST (my time).

    News posts: 2023 5,800+ | 2024 5,700+ | 2025 5,700+ | 2026 (to end of June) 2,475

    RIP Matrix


    User Feedback

    Recommended Comments

    There are no comments to display.



    Join the conversation

    You can post now and register later. If you have an account, sign in now to post with your account.
    Note: Your post will require moderator approval before it will be visible.

    Guest
    Add a comment...

    ×   Pasted as rich text.   Paste as plain text instead

      Only 75 emoji are allowed.

    ×   Your link has been automatically embedded.   Display as a link instead

    ×   Your previous content has been restored.   Clear editor

    ×   You cannot paste images directly. Upload or insert images from URL.


  • Recently Browsing   0 members

    • No registered users viewing this page.
×
×
  • Create New...