Threats · 55 days ago
AI assistants can now be steered into malicious repos without a human click. FakeGit has shifted from impersonating projects for people to baiting agents that search GitHub for skills or MCP servers and then follow the README on their own. That breaks the old assumption that a user has to choose the bad repo for the campaign to work.
Researchers say the campaign now spans about 7,600 malicious GitHub repositories, including more than 800 AI skills and MCP lures. Island found Claude Code, Gemini, and ChatGPT could be tricked into surfacing the bogus repos, and the operation has already racked up more than 14 million downloads across about 200 campaign repositories.
The exposure is broader than a phishing click. Any workflow that lets an agent browse GitHub for code or integrations can be pushed into attacker-controlled repos, which then deliver SmartLoader and set up follow-on StealC theft.
3 sources covering this story
FakeGit campaign uses 7,600 GitHub repos to push SmartLoader malware
A large-scale operation dubbed 'FakeGit' is pushing SmartLoader and StealC malware through 7,600 malicious GitHub repositories that accumulated more than 14 million downloads.
FakeGit Campaign Uses 7,600 GitHub Repositories to Spread SmartLoader Malware
Researchers uncover 7,600 FakeGit GitHub repos, including 800 AI skills and MCP lures spreading SmartLoader malware.
A threat actor is impersonating hundreds of brands on GitHub and pushing a smash-and-grab infostealer masquerading as legitimate downloads.
Nearly 300 GitHub repos pose as legit software to push malware
A threat actor has published hundreds of fake GitHub repositories impersonating legitimate software and security projects to distribute infostealer malware.
Part of the PlainSec briefing for 2026-07-21