FakeGit campaign reactivates with 17,610 fake GitHub repos spreading SmartLoader
Apiiro researchers report that the FakeGit campaign resumed activity on October 4, pushing over 13,000 malicious repositories in 34 hours and reaching a total of 17,610 fake GitHub repos. The repos use README files with download buttons linking to ZIP archives containing SmartLoader malware, which is then used to deliver other payloads like StealC. At least 700 of the accounts involved reportedly belong to legitimate developers, though most are throwaway accounts.
GoKawiil's interpretation of the reporting above, not reported fact.
The campaign's resilience suggests that current takedown efforts, which rely on incomplete blocklists, are poorly suited to GitHub-hosted threats where attackers can simply swap download links while reusing the same repository infrastructure. This points to a broader gap in how platforms and security tools track malicious content that persists even after partial detection, potentially allowing similar campaigns to resurface repeatedly with minimal new effort from attackers.
- FakeGit campaign relaunched October 4 and now spans 17,610 fake GitHub repositories distributing SmartLoader malware.
- Researchers found 97% of sampled commits only modified README files, with 88% linking to malicious ZIP downloads.
- Incomplete blocklists and reusable repository infrastructure let attackers revive the campaign without creating new repos.
YubiKey 5C NFC Security Key — With malicious repos and credential-stealing campaigns like FakeGit proliferating on GitHub, securing your developer and GitHub accounts with hardware-based two-factor authentication is a smart move. A YubiKey adds a physical layer of protection so stolen passwords alone can't compromise your accounts.
See YubiKey 5C NFC Security Key on Amazon → Affiliate link — we may earn a commission on purchases, at no extra cost to you. Product picked by AI based on this article; it is not a tested recommendation.Source: bleepingcomputer.com, 2026-10-08
Published there as: “FakeGit malware campaign returns with 17,610 malicious GitHub repos”
Read the original report → The summary and analysis above are GoKawiil's own, written from reporting by the source above. Facts and quotes belong to the original publisher.