FakeGit malware campaign returns with 17,610 malicious GitHub repos
BLUF
Over 17,000 fake GitHub repositories are actively distributing infostealer malware via a reactivated FakeGit campaign.
NEWS
Threat actors have reactivated the FakeGit operation to host SmartLoader payloads across thousands of compromised repositories. These repos are primarily used to deploy the StealC infostealer targeting developers and unsuspecting users who interact with the code. The campaign was identified in early October 2026 following a period of inactivity.
Why I Care
This attack abuses the trust inherent in open-source platforms, putting developer credentials and organizational data at risk of theft. The sheer volume of malicious repos increases the probability of accidental infection during routine development tasks.
Next Steps
Security teams should immediately audit recent repository clones for SmartLoader indicators and update detection rules for StealC activity. Developers must verify repository authenticity before cloning, and organizations should enforce code review policies immediately.
Source: BleepingComputer ·