MobbleOpen in Mobble ⇢
Technology · Cybersecurity · published 2026-10-08 · via BleepingComputer

FakeGit operation floods GitHub with thousands of malware-laden repositories

Image via BleepingComputer
Image via BleepingComputer

A revived malware operation has planted more than 17,000 deceptive repositories on GitHub, researchers at Apiiro report. These pages use convincing instructions and download links to deliver SmartLoader, a loader that can deploy the StealC infostealer. The campaign's persistence is aided by duplicate payloads in forks, releases, and other GitHub locations, making removal difficult.

Expanded Detail

Apiiro's latest report says FakeGit restarted on October 4 and now spans 17,610 GitHub repositories. In roughly 34 hours, the campaign added over 13,000 repos, reaching nearly 3,000 per hour. Most sampled commits changed only README files, and 88% directed users to a ZIP that installs SmartLoader.

Earlier, Island documented 7,600 fake repos in July, including 800 posing as AI skills or MCP servers. Apiiro also found about 700 accounts that looked like real developers, alongside many disposable ones. Cleanup is complicated because copies persist in forks, releases, issue attachments, and separate hosting repos.

Context

The campaign may affect developers, AI-tool users, and organizations that install software from GitHub or public registries. A successful SmartLoader infection could expose credentials, tokens, and sensitive data through StealC, potentially leading to account takeovers and downstream breaches. Because malicious copies can hide in forks and release assets, trust in repository search results and community download links may erode. Users and platform operators could face added verification burdens, while security teams may need to treat suspicious installs as compromise events.

Expanded detail and Context are AI-generated analysis; the linked article remains the authoritative source.
Read the full article at BleepingComputer →
This summary is Al-enhanced to contain extended analysis and broader social context. The original is {NAME); the linked article is the authoritative source. Original headline: “FakeGit malware campaign returns with 17,610 malicious GitHub repos.” Browse more stories.