FakeGit campaign uses 7,600 GitHub repositories and AI tool listings to spread SmartLoader and StealC malware

Attackers set up thousands of fake GitHub repositories to trick developers and AI coding tools into downloading malware. Island says the 'FakeGit' campaign used about 7,600 repositories, including more than 1,400 posing as AI tools, skills, agents, and MCP servers, with README files pointing to ZIP downloads that actually launched SmartLoader, which then used a Polygon smart contract to find command-and-control infrastructure and fetched later stages from GitHub to install the StealC information stealer.
Why it matters: Developers and organizations using GitHub projects or AI agent recommendations are at risk of downloading malware that steals credentials and other sensitive data. Teams should verify repositories and publishers, restrict approved AI tool catalogs, and avoid running downloaded installers or 'releases' from untrusted GitHub projects.

Sources

FakeGit campaign uses 7,600 GitHub repos to push SmartLoader malware
Bill Toulas 2026.07.21 100% relevant
This article establishes a distinct malware distribution campaign, dubbed FakeGit, centered on thousands of malicious GitHub repositories and AI ecosystem listings used to spread SmartLoader and StealC.
← Back to all stories