importantSYS.SOURCE: The Hacker News• 2026-07-20T23:53:03+05:30
FakeGit Malware Campaign Exploits 7,600 GitHub Repositories to Distribute SmartLoader and StealC Malware
A cybersecurity campaign named FakeGit has leveraged 7,600 malicious GitHub repositories to distribute SmartLoader malware, with 800 posing as AI skills or MCP servers. The campaign uses AI-powered AgentBaiting to trick both users and AI agents into downloading malware, exploiting public registries for credibility.
Cybersecurity researchers have discovered nearly 7,600 malicious GitHub repositories, out of which more than 800 pose as artificial intelligence (AI) skills or Model Context Protocol (MCP) servers to deliver a malware family known as SmartLoader as part of an ongoing campaign codenamed FakeGit.
"FakeGit uses copied projects, lookalike developer profiles, convincing READMEs, and malicious ZIP
*** END OF TRANSMISSION ***