FakeGit Is Back: 17,610 GitHub Repositories Used to Spread SmartLoader
17,610 booby-trapped GitHub repositories, including more than 13,000 reactivated in 34 hours: the FakeGit campaign is back! The attackers’ goal is to distribute the SmartLoader malware. Here’s what we know.
As a reminder, the name FakeGit appeared in July 2026, when researchers at Island, the maker of an enterprise browser, highlighted a campaign linked to 7,600 fake GitHub repositories used to distribute the SmartLoader malware. More than 800 of them posed as AI skills or MCP servers, listed in public registries and catalogs. During its tests, Island even found that ChatGPT, Gemini, and Claude could surface these repositories when asked to perform a task related to those tools. Enough to fool users who tend to place blind trust in resources promoted by AI.
The FakeGit campaign relies on a fairly simple playbook: a convincing repository, often a copy of a legitimate project, a polished README, and a download button pointing to a ZIP archive. That archive contains SmartLoader, a loader designed to deploy other malware, starting with the StealC infostealer. According to Island researchers, SmartLoader establishes persistence through a scheduled task and retrieves its C2 server address from a smart contract on the Polygon blockchain.
There is a huge amount of interesting content on GitHub, whether open source projects, code snippets, or AI tools. Attackers know this very well! In any case, this is far from the first time GitHub has been abused by cybercriminals. In March 2025, I published an article about a malvertising campaign that infected nearly one million PCs using GitHub repositories controlled by the attackers.
13,000 Repositories Reactivated in 34 Hours
At the start of October 2026, the FakeGit campaign appears to have resumed activity, according to a new report published by Apiiro, a company specializing in software supply chain security. Researchers estimate that FakeGit has been active again since October 4 and that the campaign now relies on 17,610 GitHub repositories. In just 34 hours, more than 13,000 of them were modified, at a rate of up to 2,999 repositories per hour.

In the sample of commits analyzed by Apiiro, 97% only touched the README file, and 88% redirected the download button to a ZIP archive that installs SmartLoader. In other words, the attackers did not have to create anything from scratch. They simply changed the links. "The fleet was already there. It was just redirected," the Apiiro researchers sum up. Most of the accounts used are disposable, but Apiiro identified at least 700 that appear to belong to real developers. How they ended up in this fleet is not explained in the report.
When looking at the diagram below, you can see AI’s role in setting up this campaign. That also helps explain how cybercriminals manage to make changes across so many repositories in such a short time. I am thinking in particular of the README rewrite.

Removing Repositories Is Not Enough
According to Apiiro, takedown efforts rely on lists that cover only a fraction of the malicious repository fleet. In addition, a malicious archive placed on a blocklist remains downloadable on GitHub, as do its backup copies. When one link is detected, the attacker only has to update the README download button to point to another copy.
Researchers found malicious archives in forks, older file versions, release assets, issue attachments, and repositories dedicated to hosting downloads. Deleting one file therefore does not help much, because there is always another copy somewhere else.
Proof that identification is not easy: at the time Apiiro’s report was published, 71% of FakeGit repositories were missing from URLhaus, abuse.ch’s database of malicious links.
How Can You Protect Yourself?
People who are used to installing AI skills and MCP servers are particularly exposed to this type of malicious campaign. So here are the recommendations shared by Apiiro:
- Verify the repository owner: a copied project under another account should raise suspicion, even if the README looks convincing.
- Install AI skills and MCP servers from official sources: official registries or the vendor’s repositories.
- Treat any execution of SmartLoader as a GitHub account compromise: revoke active sessions and access tokens, then switch to passkeys.
The last point deserves a quick clarification: the StealC malware targets credentials and active sessions present on the infected machine. That can therefore include access to a GitHub account.


