< Back to all clusters
[TECHNOLOGY] · 6 sources

FakeGit campaign spreads SmartLoader malware via 7,600 GitHub repositories

Cybersecurity researchers have identified a large‑scale operation, dubbed FakeGit, that created nearly 7,600 malicious GitHub repositories. Over 800 of these repos masquerade as artificial‑intelligence skills or Model Context Protocol (MCP) servers, using copied projects, look‑alike developer profiles and convincing READMEs to lure users into downloading malicious ZIP files.

The repositories deliver the SmartLoader malware family, which installs the StealC information‑stealer to harvest a wide range of data from compromised systems. As of July 2026 the campaign has generated more than 14 million downloads across roughly 200 repository releases. A new technique called “Agent Baiting” enables AI agents such as Anthropic Claude, Google Gemini and OpenAI ChatGPT to discover these bogus repos automatically, allowing the attack to proceed without human interaction.

Lead researcher Oleg Zaytsev of Island noted that the fake repos borrow familiar tool names—including Gmail, WhatsApp, Databricks, Jenkins and Docker—to increase credibility, and that earlier reports had flagged the use of trojanised MCP servers for distributing SmartLoader and StealC.