FakeGit returns: 17,610 malicious GitHub repositories, many posing as AI skills or MCP servers, re-pointed to push the SmartLoader malware after the campaign restarted on 4 October
Software supply-chain security firm Apiiro reported, and BleepingComputer covered on 8 October 2026, that the FakeGit campaign resumed on 4 October and now uses 17,610 GitHub repositories to spread SmartLoader, a loader that pulls in further malware such as the StealC infostealer. In 34 hours the operator pushed changes to more than 13,000 repositories, peaking at 2,999 an hour; in sampled commits 97% touched only the README and 88% pointed its Download button at a ZIP that installs SmartLoader. Most accounts are disposable, but at least 700 appear to belong to real developers. Island named the operation in July after finding 7,600 such repositories, 800 of them posing as AI skills or MCP servers listed in public AI registries. Apiiro says takedowns fail because they work from lists that cover a fraction of the repositories, and copies sit in forks, older files, release assets, issue attachments and separate download repositories, so the operator just changes the link. 71% of the fleet was missing from URLhaus before the report, and DNS blocking cannot single out one file on GitHub. Primary: Apiiro research; wire: BleepingComputer.
- Product
- GitHub repositories (fake projects, AI skills and MCP servers) delivering SmartLoader
- Versions
- n/a — malware campaign
- Exploited in Australia?
- unknown
- Patch to
- Install AI skills and MCP servers only from official registries or the vendor's own repository, check who owns a repository before downloading release ZIPs, and block execution of downloaded archives on developer machines. If SmartLoader ran, treat it as a GitHub account compromise: revoke sessions and tokens and move to passkeys.
Primary: Apiiro — FakeGit research: never deleted, only re-pointed (Oct 2026) · BleepingComputer — FakeGit malware campaign returns with 17,610 malicious GitHub repos (8 Oct 2026)
