FakeGit campaign returns with 17,610 GitHub repos pushing SmartLoader and StealC
Apiiro says the FakeGit operation re-aimed thousands of GitHub repositories, many posing as AI tools and MCP servers, to deliver SmartLoader and the StealC infostealer.
At a glance
- FakeGit resumed on October 4, 2026, and now uses 17,610 GitHub repositories, according to Apiiro.
- More than 13,000 repos were pushed in 34 hours, peaking at 2,999 per hour.
- README download buttons lead to ZIP files that install SmartLoader, which was used to deliver the StealC infostealer.
- Apiiro says 71% of the fleet was missing from the URLhaus blocklist before its report.
A malware operation known as FakeGit has resumed activity with 17,610 malicious GitHub repositories that lure developers and users into downloading the SmartLoader malware loader, which is now being used to deliver the StealC information stealer, BleepingComputer reported on October 8, 2026, citing new research from software supply-chain security firm Apiiro. The campaign is notable because many of the repositories imitate AI skills, MCP servers and similar developer tools.
What happened
According to Apiiro, FakeGit came back to life on October 4, 2026. In just 34 hours the operator pushed changes to more than 13,000 repositories, peaking at 2,999 per hour. Rather than creating new projects, the operator re-pointed existing ones; as Apiiro put it, the fleet "just got re-aimed." Most of the accounts are throwaway accounts, but at least 700 appear to belong to legitimate developers, the researchers said.
The FakeGit name was first tied to the operation in July 2026, when enterprise browser company Island reported 7,600 fake GitHub repositories distributing SmartLoader. At the time, Island noted that about 800 of those repositories posed as AI skills or MCP servers listed in public AI registries. BleepingComputer adds that similar activity with various payloads has been observed since at least January.
Technical details
In sampled commits, 97% changed only the README file and 88% pointed the README's "Download" button at a ZIP archive that installs SmartLoader. Apiiro found the malicious archives hosted in forks, older files, release assets, issue attachments and separate download-hosting repositories, which lets the operator switch to a spare copy when one file is removed.
The researchers argue that takedowns struggle to keep up because blocklists cover only part of the fleet. Apiiro reported that 71% of the repositories were missing from the URLhaus blocklist before its report, and noted that domain-level DNS blocking cannot stop a single file on GitHub without blocking GitHub entirely. BleepingComputer's article does not describe any statement or action from GitHub.
What to do
Apiiro advises verifying the owner of a repository before installing anything from it and obtaining AI skills and MCP servers only from official registries or vendor repositories. Download buttons in README files that lead to ZIP archives, rather than to the project's own releases, should be treated with suspicion. If SmartLoader may have run on a system, Apiiro recommends treating it as a possible GitHub account compromise: revoke active sessions and access tokens and move the account to passkeys. Since StealC is an infostealer, credentials and browser sessions stored on an affected machine should also be considered exposed and rotated.
Sources
- FakeGit malware campaign returns with 17,610 malicious GitHub repos — BleepingComputer
This story is based on the sources listed above. Always check the vendor’s official advisory before acting on critical systems.



