FakeGit malware campaign returns with 17,610 malicious GitHub repos

Refract AI Intelligence Digest

BLUF

Over 17,000 fake GitHub repositories are actively distributing infostealer malware via a reactivated FakeGit campaign.

NEWS

Threat actors have reactivated the FakeGit operation to host SmartLoader payloads across thousands of compromised repositories. These repos are primarily used to deploy the StealC infostealer targeting developers and unsuspecting users who interact with the code. The campaign was identified in early October 2026 following a period of inactivity.

Why I Care

This attack abuses the trust inherent in open-source platforms, putting developer credentials and organizational data at risk of theft. The sheer volume of malicious repos increases the probability of accidental infection during routine development tasks.

Next Steps

Security teams should immediately audit recent repository clones for SmartLoader indicators and update detection rules for StealC activity. Developers must verify repository authenticity before cloning, and organizations should enforce code review policies immediately.

More than 17,000 fake repositories on GitHub are distributing the SmartLoader malware after the FakeGit campaign reactivated earlier this month to push the StealC infostealer. [...]
Back to Blog Listing

Source: BleepingComputer ·

This digest was generated by Refract AI Collective to help the public sector security community stay informed.