CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

FakeGit Campaign Uses 7,600 GitHub Repositories to Spread SmartLoader Malware

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 2871

As cited

Copy frozen at (site build).

threat intel

FakeGit Campaign Uses 7,600 GitHub Repositories to Spread SmartLoader Malware

Researchers identified approximately 7,600 malicious GitHub repositories in the FakeGit campaign, with over 800 masquerading as AI tools or Model Context Protocol servers to distribute SmartLoader malware. The campaign employs copied projects, lookalike developer profiles, and deceptive README files to deceive users into downloading infected packages.

Why it matters: Developers and organizations using GitHub for AI or MCP tools face supply chain risk; practitioners should audit dependencies and verify repository authenticity before integration.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

FakeGit Campaign Uses 7,600 GitHub Repositories to Spread SmartLoader Malware

No summary had been written when this copy was frozen.

First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

FakeGit Campaign Uses 7,600 GitHub Repositories to Spread SmartLoader Malware

Researchers identified nearly 7,600 malicious GitHub repositories in a campaign called FakeGit, with over 800 impersonating artificial intelligence (AI) tools or Model Context Protocol (MCP) servers to distribute SmartLoader malware. The repositories use copied projects, lookalike developer profiles, and deceptive documentation to deceive developers into downloading infected code.

Why it matters: Developers using GitHub for open source dependencies face a supply chain risk from this distribution method; practitioners should review procurement policies for package verification and developer training on repository authenticity checks.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

FakeGit Campaign Uses 7,600 GitHub Repositories to Spread SmartLoader Malware

Researchers identified nearly 7,600 malicious GitHub repositories in a campaign called FakeGit, with over 800 impersonating artificial intelligence (AI) tools or Model Context Protocol (MCP) servers to distribute SmartLoader malware. The repositories use copied projects, lookalike developer profiles, and deceptive documentation to deceive developers into downloading infected code.

Why it matters: Developers using GitHub for open source dependencies face a supply chain risk from this distribution method; practitioners should review procurement policies for package verification and developer training on repository authenticity checks.

VendorsGitHub
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary