Home/News/FakeGit Campaign Abuses 7,600 GitHub Repositories for Malware
The Hacker News2 min read

By Interestana AI Editorial — AI-drafted, human-overseen. How we report

FakeGit Campaign Abuses 7,600 GitHub Repositories for Malware

FakeGit Campaign Abuses 7,600 GitHub Repositories for Malware

Cybersecurity researchers have identified approximately 7,600 malicious GitHub repositories as part of an ongoing campaign dubbed FakeGit. This operation leverages these repositories to distribute a malware family known as SmartLoader. Over 800 of these repositories are designed to impersonate artificial intelligence (AI) skills or Model Context Protocol (MCP) servers, aiming to deceive unsuspecting users.

The FakeGit campaign employs a multi-faceted approach to achieve its malicious objectives. It utilizes copied legitimate projects, creates fabricated developer profiles that appear credible, and crafts convincing README files to lure victims. The malware is often delivered through malicious ZIP archives. The researchers' analysis indicates that this campaign has been active for at least two months, with a significant surge in malicious repository creation observed in the past month.

SmartLoader, the primary payload distributed by FakeGit, is a sophisticated malware capable of downloading and executing additional malicious payloads. Its functionalities include stealing sensitive information, establishing persistent access to compromised systems, and potentially facilitating further network intrusion. The campaign's reliance on GitHub, a platform widely used by developers for legitimate code sharing and collaboration, highlights the evolving tactics of cybercriminals in exploiting trusted environments.

The discovery of the FakeGit campaign underscores the persistent threat posed by sophisticated malware distribution schemes. The sheer volume of malicious repositories involved suggests a well-resourced and organized threat actor. Cybersecurity professionals are advising users to exercise extreme caution when downloading code or dependencies from public repositories, even those that appear legitimate, and to ensure robust security measures are in place to detect and prevent malware infections.

Original source — read the full reporting at the publisher:

Read on The Hacker News

Get the weekly AI digest

AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.

Read next