<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/fakegit-campaign-uses-7-600-github-repos-to-push-smartloader-malware-7kg3uwtby" -->

---
title: FakeGit campaign uses 7,600 GitHub repos to push...
description: A large-scale malware campaign called &#x27;FakeGit&#x27; has distributed SmartLoader and StealC malware through 7,600 malicious GitHub repositories, accumulating over...
canonical: https://daily.dev/posts/fakegit-campaign-uses-7-600-github-repos-to-push-smartloader-malware-7kg3uwtby
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: FakeGit campaign uses 7,600 GitHub repos to push SmartLoader malware | daily.dev
og:description: A large-scale malware campaign called &#x27;FakeGit&#x27; has distributed SmartLoader and StealC malware through 7,600 malicious GitHub repositories, accumulating over...
og:url: https://daily.dev/posts/fakegit-campaign-uses-7-600-github-repos-to-push-smartloader-malware-7kg3uwtby
og:image: https://api.daily.dev/og/posts/7KG3Uwtby.png
og:image:alt: FakeGit campaign uses 7,600 GitHub repos to push SmartLoader malware
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# FakeGit campaign uses 7,600 GitHub repos to push SmartLoader malware

**[BleepingComputer](https://daily.dev/sources/bleepingcomputer)** · 4 min read · 0 upvotes · 0 comments

## Summary

A large-scale malware campaign called 'FakeGit' has distributed SmartLoader and StealC malware through 7,600 malicious GitHub repositories, accumulating over 14 million downloads. The campaign impersonates popular tools like Gmail, WhatsApp, Docker, and Jenkins with convincing fake documentation and fabricated stars. Over 800 repositories posed as AI skills or MCP servers and appeared in public AI registries, using a technique researchers call 'AgentBaiting' — designed to get AI coding agents like Claude Code, ChatGPT, and Gemini to surface and recommend the malicious repos. SmartLoader establishes persistence via scheduled tasks, retrieves its C2 address through a Polygon smart contract, and ultimately delivers the StealC information stealer. Organizations are advised to maintain approved MCP server catalogs, test in isolated environments, and rotate secrets if SmartLoader execution is suspected.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://www.bleepingcomputer.com/news/security/fakegit-campaign-uses-7-600-github-repos-to-push-smartloader-malware>

## Questions this post answers

### What is the FakeGit campaign and how does it use GitHub repositories to spread malware?

FakeGit is a large-scale malicious campaign using over 7,600 fake GitHub repositories to distribute SmartLoader and StealC malware, accumulating more than 14 million cumulative download events. Repos impersonate tools like Gmail, WhatsApp, Databricks, Jenkins, and Docker with fabricated stars, forks, and documentation, tricking victims into downloading ZIP files that hide Lua payloads triggering SmartLoader, which later deploys the StealC info-stealer.

_Security teams tracking supply-chain threats like this can follow ongoing coverage on daily.dev._

### What is agentbaiting and how does it trick AI coding assistants into recommending malicious repositories?

Agentbaiting is a technique where attackers craft malicious GitHub repositories to look like legitimate AI skills or MCP servers so AI agents recommend or install them. Researchers at Island found over 800 such repos listed more than 600 times across registries like LobeHub, Glama, MCP.so, and MCP Market, and observed ChatGPT, Gemini, and Claude surfacing or relaying installation instructions for them during testing.

_Developers relying on AI agents to vet dependencies can track emerging attack techniques like this on daily.dev._

### Did Claude Code detect the malicious SmartLoader payloads during testing of the FakeGit campaign?

In controlled testing by Island researchers, Claude Code cloned malicious repositories and downloaded the malicious files onto the test machine, but it detected suspicious indicators and stopped before executing the payload. The testing was not designed to measure a detection rate, so it does not show whether coding agents can consistently catch this kind of threat during execution.

_Teams evaluating how safely coding agents handle untrusted repos can follow security findings like this on daily.dev._

## Similar posts on daily.dev

- [Fake Claude Code source downloads actually delivered malware](https://daily.dev/posts/fake-claude-code-source-downloads-actually-delivered-malware-5gamzwr6l) · The Register · 1 upvotes · 0 comments
- [Operation RepoGhost: Exposing a Russian-Linked Malware Campaign Hiding in GitHub’s Open-Source Ecosystem](https://daily.dev/posts/operation-repoghost-exposing-a-russian-linked-malware-campaign-hiding-in-github-s-open-source-ecosy-otywwtpum) · InfoSec Write-ups · 15 upvotes · 4 comments

---

Tags: [#cyber](https://daily.dev/tags/cyber), [#github](https://daily.dev/tags/github), [#malware](https://daily.dev/tags/malware), [#mcp](https://daily.dev/tags/mcp)

[View this post on daily.dev](https://daily.dev/posts/fakegit-campaign-uses-7-600-github-repos-to-push-smartloader-malware-7kg3uwtby)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"FakeGit campaign uses 7,600 GitHub repos to push SmartLoader malware","url":"https://daily.dev/posts/fakegit-campaign-uses-7-600-github-repos-to-push-smartloader-malware-7kg3uwtby","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/fakegit-campaign-uses-7-600-github-repos-to-push-smartloader-malware-7kg3uwtby"},"datePublished":"2026-07-21T22:34:28.683Z","dateModified":"2026-09-14T07:39:00.290Z","description":"A large-scale malware campaign called 'FakeGit' has distributed SmartLoader and StealC malware through 7,600 malicious GitHub repositories, accumulating over...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/c49cc8379629a2fe5f4ff9bde3c1ccdb?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/c49cc8379629a2fe5f4ff9bde3c1ccdb?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"BleepingComputer","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"BleepingComputer","logo":"https://media.daily.dev/image/upload/s--as8nJ3qy--/f_auto,q_auto/v1774959951/logos/bleepingcomputer?_a=BAMAMiWQ0","url":"https://daily.dev/sources/bleepingcomputer"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/fakegit-campaign-uses-7-600-github-repos-to-push-smartloader-malware-7kg3uwtby","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":0},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"cyber,github,malware,mcp","timeRequired":"PT4M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"BleepingComputer","item":"https://daily.dev/sources/bleepingcomputer"},{"@type":"ListItem","position":3,"name":"FakeGit campaign uses 7,600 GitHub repos to push SmartLoader malware"}]}
{"@context":"https://schema.org","@type":"FAQPage","@id":"https://daily.dev/posts/fakegit-campaign-uses-7-600-github-repos-to-push-smartloader-malware-7kg3uwtby#faq","mainEntity":[{"@type":"Question","name":"What is the FakeGit campaign and how does it use GitHub repositories to spread malware?","acceptedAnswer":{"@type":"Answer","text":"FakeGit is a large-scale malicious campaign using over 7,600 fake GitHub repositories to distribute SmartLoader and StealC malware, accumulating more than 14 million cumulative download events. Repos impersonate tools like Gmail, WhatsApp, Databricks, Jenkins, and Docker with fabricated stars, forks, and documentation, tricking victims into downloading ZIP files that hide Lua payloads triggering SmartLoader, which later deploys the StealC info-stealer. Security teams tracking supply-chain threats like this can follow ongoing coverage on daily.dev."}},{"@type":"Question","name":"What is agentbaiting and how does it trick AI coding assistants into recommending malicious repositories?","acceptedAnswer":{"@type":"Answer","text":"Agentbaiting is a technique where attackers craft malicious GitHub repositories to look like legitimate AI skills or MCP servers so AI agents recommend or install them. Researchers at Island found over 800 such repos listed more than 600 times across registries like LobeHub, Glama, MCP.so, and MCP Market, and observed ChatGPT, Gemini, and Claude surfacing or relaying installation instructions for them during testing. Developers relying on AI agents to vet dependencies can track emerging attack techniques like this on daily.dev."}},{"@type":"Question","name":"Did Claude Code detect the malicious SmartLoader payloads during testing of the FakeGit campaign?","acceptedAnswer":{"@type":"Answer","text":"In controlled testing by Island researchers, Claude Code cloned malicious repositories and downloaded the malicious files onto the test machine, but it detected suspicious indicators and stopped before executing the payload. The testing was not designed to measure a detection rate, so it does not show whether coding agents can consistently catch this kind of threat during execution. Teams evaluating how safely coding agents handle untrusted repos can follow security findings like this on daily.dev."}}]}
```

