<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/fakegit-malware-campaign-returns-with-17-610-malicious-github-repos-m5lmz662i" -->

---
title: FakeGit malware campaign returns with 17,610 malicious...
description: The FakeGit malware campaign has reactivated, now spanning 17,610 malicious GitHub repositories that push the SmartLoader malware and, downstream, the StealC...
canonical: https://daily.dev/posts/fakegit-malware-campaign-returns-with-17-610-malicious-github-repos-m5lmz662i
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: FakeGit malware campaign returns with 17,610 malicious GitHub repos | daily.dev
og:description: The FakeGit malware campaign has reactivated, now spanning 17,610 malicious GitHub repositories that push the SmartLoader malware and, downstream, the StealC...
og:url: https://daily.dev/posts/fakegit-malware-campaign-returns-with-17-610-malicious-github-repos-m5lmz662i
og:image: https://api.daily.dev/og/posts/M5lMz662i.png
og:image:alt: FakeGit malware campaign returns with 17,610 malicious GitHub repos
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# FakeGit malware campaign returns with 17,610 malicious GitHub repos

**[BleepingComputer](https://daily.dev/sources/bleepingcomputer)** · 3 min read · 1 upvotes · 0 comments

## Summary

The FakeGit malware campaign has reactivated, now spanning 17,610 malicious GitHub repositories that push the SmartLoader malware and, downstream, the StealC infostealer. Apiiro researchers found the campaign resumed on October 4, pushing over 13,000 new repos in 34 hours at a peak of nearly 3,000 per hour, by simply re-pointing existing repos' download links rather than creating new ones. Repos use convincing README files with download buttons leading to malicious ZIPs; 97% of sampled commits only touched the README and 88% pointed to a SmartLoader-installing ZIP. The campaign survives takedown efforts because blocklists cover only a fraction of repos (71% missing from URLhaus) and attackers can re-point to forks, older files, release assets, or issue attachments. Some malicious repos masquerade as AI skills or MCP servers. Researchers recommend verifying repo owners, using official registries for AI skills/MCP servers, and treating suspected SmartLoader execution as a GitHub account compromise requiring session/token revocation and passkey adoption.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://www.bleepingcomputer.com/news/security/fakegit-malware-campaign-returns-with-17-610-malicious-github-repos>

## Questions this post answers

### What is the FakeGit campaign on GitHub and what malware does it install?

FakeGit is a malware distribution campaign using fake GitHub repositories with convincing README files that include a download button linking to a ZIP archive. That ZIP installs SmartLoader, which then deploys further malware such as the StealC infostealer. As of October 4, the campaign reactivated and expanded to 17,610 malicious repositories, up from 7,600 reported in July.

_Developers vetting unfamiliar repos before cloning can follow ongoing coverage of this malware on daily.dev._

### Why can't GitHub just remove all the FakeGit malicious repositories?

Takedown lists only cover a fraction of the malicious repositories, so attackers simply re-point download links to spare copies already stored as forks, older ZIP files, release assets, or issue attachments instead of creating new repos. Researchers found 71% of the fleet was missing from the URLhaus blocklist, and a domain-level DNS blocklist cannot target a single GitHub file without blocking the whole platform.

_Security teams tracking resilient malware distribution tactics can follow this kind of research on daily.dev._

### How do I avoid downloading malware disguised as an AI skill or MCP server on GitHub?

Install AI skills and MCP servers only from official registries or vendor repositories rather than from arbitrary GitHub repos, since hundreds of malicious repositories in the FakeGit campaign have masqueraded as AI skills or MCP servers. Also verify the repository owner's identity before downloading, and if SmartLoader execution is suspected, treat it as a possible GitHub account compromise and revoke sessions and tokens.

_Developers adopting MCP servers and AI skills safely can keep tabs on emerging supply-chain risks via daily.dev._

## Similar posts on daily.dev

- [FakeGit campaign uses 7,600 GitHub repos to push SmartLoader malware](https://daily.dev/posts/fakegit-campaign-uses-7-600-github-repos-to-push-smartloader-malware-7kg3uwtby) · BleepingComputer · 0 upvotes · 0 comments
- [Operation RepoGhost: Exposing a Russian-Linked Malware Campaign Hiding in GitHub’s Open-Source Ecosystem](https://daily.dev/posts/operation-repoghost-exposing-a-russian-linked-malware-campaign-hiding-in-github-s-open-source-ecosy-otywwtpum) · InfoSec Write-ups · 15 upvotes · 4 comments
- [Fake Claude Code source downloads actually delivered malware](https://daily.dev/posts/fake-claude-code-source-downloads-actually-delivered-malware-5gamzwr6l) · The Register · 1 upvotes · 0 comments

---

Tags: [#cyber](https://daily.dev/tags/cyber), [#github](https://daily.dev/tags/github), [#malware](https://daily.dev/tags/malware), [#mcp](https://daily.dev/tags/mcp)

[View this post on daily.dev](https://daily.dev/posts/fakegit-malware-campaign-returns-with-17-610-malicious-github-repos-m5lmz662i)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"FakeGit malware campaign returns with 17,610 malicious GitHub repos","url":"https://daily.dev/posts/fakegit-malware-campaign-returns-with-17-610-malicious-github-repos-m5lmz662i","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/fakegit-malware-campaign-returns-with-17-610-malicious-github-repos-m5lmz662i"},"datePublished":"2026-10-08T17:15:53.599Z","dateModified":"2026-10-08T19:08:57.166Z","description":"The FakeGit malware campaign has reactivated, now spanning 17,610 malicious GitHub repositories that push the SmartLoader malware and, downstream, the StealC...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/7956e1e9916e0afe1433ff576151e911?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/7956e1e9916e0afe1433ff576151e911?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"BleepingComputer","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"BleepingComputer","logo":"https://media.daily.dev/image/upload/s--as8nJ3qy--/f_auto,q_auto/v1774959951/logos/bleepingcomputer?_a=BAMAMiWQ0","url":"https://daily.dev/sources/bleepingcomputer"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/fakegit-malware-campaign-returns-with-17-610-malicious-github-repos-m5lmz662i","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":1},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"cyber,github,malware,mcp","timeRequired":"PT3M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"BleepingComputer","item":"https://daily.dev/sources/bleepingcomputer"},{"@type":"ListItem","position":3,"name":"FakeGit malware campaign returns with 17,610 malicious GitHub repos"}]}
{"@context":"https://schema.org","@type":"FAQPage","@id":"https://daily.dev/posts/fakegit-malware-campaign-returns-with-17-610-malicious-github-repos-m5lmz662i#faq","mainEntity":[{"@type":"Question","name":"What is the FakeGit campaign on GitHub and what malware does it install?","acceptedAnswer":{"@type":"Answer","text":"FakeGit is a malware distribution campaign using fake GitHub repositories with convincing README files that include a download button linking to a ZIP archive. That ZIP installs SmartLoader, which then deploys further malware such as the StealC infostealer. As of October 4, the campaign reactivated and expanded to 17,610 malicious repositories, up from 7,600 reported in July. Developers vetting unfamiliar repos before cloning can follow ongoing coverage of this malware on daily.dev."}},{"@type":"Question","name":"Why can't GitHub just remove all the FakeGit malicious repositories?","acceptedAnswer":{"@type":"Answer","text":"Takedown lists only cover a fraction of the malicious repositories, so attackers simply re-point download links to spare copies already stored as forks, older ZIP files, release assets, or issue attachments instead of creating new repos. Researchers found 71% of the fleet was missing from the URLhaus blocklist, and a domain-level DNS blocklist cannot target a single GitHub file without blocking the whole platform. Security teams tracking resilient malware distribution tactics can follow this kind of research on daily.dev."}},{"@type":"Question","name":"How do I avoid downloading malware disguised as an AI skill or MCP server on GitHub?","acceptedAnswer":{"@type":"Answer","text":"Install AI skills and MCP servers only from official registries or vendor repositories rather than from arbitrary GitHub repos, since hundreds of malicious repositories in the FakeGit campaign have masqueraded as AI skills or MCP servers. Also verify the repository owner's identity before downloading, and if SmartLoader execution is suspected, treat it as a possible GitHub account compromise and revoke sessions and tokens. Developers adopting MCP servers and AI skills safely can keep tabs on emerging supply-chain risks via daily.dev."}}]}
```

