Skip to content

Security1 publisherNot yet confirmed elsewhere2 min readPublished

FakeGit rewrote more than 13,000 GitHub repos in 34 hours to spread SmartLoader

FakeGit's operator re-aimed more than 13,000 existing GitHub repositories at the SmartLoader malware in 34 hours, Apiiro found. At least 700 of the accounts involved appear to belong to legitimate developers, so a credible-looking owner is weak evidence that a download is safe.

The Watch · Security desk

How we use AISend a correction

What happened

  • Apiiro says FakeGit resumed activity on October 4 and now runs 17,610 repositories on GitHub.
  • That count is more than double the 7,600 malicious repositories Island reported in July, when the FakeGit name was first attached to the operation.
  • Each lure is a README with a download button linked to a ZIP archive holding SmartLoader, a loader that delivers other malware.
  • In the October wave, SmartLoader is being used to deliver the StealC infostealer, BleepingComputer reported.
  • In July, Island found 800 of the repositories posing as AI skills or MCP servers that appeared in public AI registries and catalogs.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • constraint The lures cannot be blocked at DNS, because Apiiro says a domain-level blocklist cannot stop one GitHub file without blocking all of GitHub. Defenders have to check the file itself or the endpoint.
  • precedent The fleet was already in place when it was re-aimed in October. Until the repositories and their spare copies are removed together, the operator can point it at a new payload again.
  • exposure Developers who take AI skills or MCP servers from public catalogs can reach these lures. Apiiro's advice is to install them only from official registries or vendor repositories.
  • decision Apiiro advises treating a suspected SmartLoader run on a developer machine as a GitHub account incident: revoke active sessions and access tokens, and move the account to passkeys.

The operator can change the payload across thousands of repositories by editing the README in each one [8]. "Nobody had to create a single new repo. The fleet was already there. It just got re-aimed," Apiiro's researchers said [9]. Apiiro said that in the commits it sampled, 97% touched only the README, and 88% pointed the README's Download button at a ZIP that installs SmartLoader [8]. More than 13,000 repos in 34 hours [7] works out to at least 382 an hour on average, and the peak of 2,999 in one hour was nearly eight times that [19]. The 13,000 is about three quarters of the 17,610 repositories Apiiro now counts [22].

Similar activity with various payloads has been seen since at least January, and the FakeGit name dates from Island's July report [4]. Removals have not kept up. According to Apiiro, takedowns work from lists that cover only a fraction of the malicious repos [10]. "71% of the fleet was missing from URLhaus before our report," the researchers said [11]. Across 17,610 repositories, that comes to roughly 12,500 that were not in the feed [21].

Deleting a payload leaves the lure in place. Apiiro found the malicious archives in forks, older files, release assets, issue attachments and separate download-hosting repositories [13]. "Delete one file and the operator can point the lure at a spare copy: a fork, an older ZIP, a release asset or an issue attachment," the researchers said [14]. Payloads that are already blocklisted, and backup copies, can still be downloaded. The operator changes the download link and the repository stays live [15].

Most of the fleet runs on throwaway accounts [2]. Apiiro's first recommendation is to check who owns a repository [16]. That check assumes the developer the account appears to belong to is the one controlling it. BleepingComputer's report does not say how the operator came to be using the accounts that look legitimate [2].

What to watch

  • Whether GitHub removes the 17,610 repositories together with their forks, release assets and issue attachments, or one link at a time.
  • Any public explanation of how the operator came to use the at least 700 accounts that appear to belong to legitimate developers.
  • A current count of FakeGit repositories listed as AI skills or MCP servers, to compare with Island's July figure of 800.

Clarity's read

What the record supports and how the coverage leans. The claims behind it follow.

Reality

Evidence55
Adoption
Insufficient
Hype gap+10
Incentives40
Confidence52
Why these scores

Claim ledger

Ranked by verification strength, evidence, and original report placement.

  1. [1]

    More than 17,000 fake repositories on GitHub are distributing the SmartLoader malware after the FakeGit campaign reactivated earlier this month to push the StealC infostealer.

    ReportedSupportedSource: BleepingComputerView cited source
  2. [2]

    The FakeGit operator uses mostly throwaway accounts, but researchers identified at least 700 accounts that appear to belong to legitimate developers.

    ReportedSupportedSource: BleepingComputer, citing researchersView cited source
  3. [3]

    The malicious repositories use convincing README instructions with a download button pointing to a ZIP archive containing the initial payload, SmartLoader, which is used to distribute other malware.

    ReportedSupportedSource: BleepingComputerView cited source

Sources

1 independent publisher whose own reporting we read for this story.

  1. bleepingcomputer.com

    1 article · October 8, 2026

    FakeGit malware campaign returns with 17,610 malicious GitHub repos

Share your take

Let Clarity write the post for you.

Signed-in readers get a short post drafted on this story in the register they choose — narrative, analytical, or a direct position — editable to the last word before it goes anywhere. The share buttons at the top of this story work without an account.

Topics and entities

Follow any of these and your For You feed starts watching them — no settings page required.

Loading related stories