Summary:**FakeGit Campaign Hijacks 7,600 GitHub Repos, Spreading Dangerous SmartLoader Malware****Introducti
referrerpolicy="no-referrer"
style="max-width:100%;height:auto;display:block;margin:0 auto;">
**FakeGit Campaign Hijacks 7,600 GitHub Repos, Spreading Dangerous SmartLoader Malware**
**Introduction**
A newly uncovered operation dubbed “FakeGit” has flooded GitHub with thousands of counterfeit repositories, turning the popular code‑hosting platform into a launchpad for the SmartLoader malware family. Security analysts first noticed the anomaly when a surge of repositories masquerading as artificial‑intelligence tools and Model Context Protocol (MCP) servers began appearing in search results. Within weeks, the count climbed to roughly 7,600 malicious projects, more than 800 of which explicitly advertised AI‑related functionality to lure developers seeking ready‑made models or utilities.
**Key Developments**
Investigators from several threat‑intelligence firms traced the campaign to a coordinated network of automated accounts that cloned legitimate open‑source projects, injected a obfuscated SmartLoader dropper, and then re‑published the altered code under slightly modified names. The dropper uses multi‑stage PowerShell and Bash scripts to evade static analysis, ultimately downloading a secondary payload that establishes persistence, exfiltrates credentials, and can deploy additional ransomware or cryptominers. Notably, over 600 of the bogus repos claimed to offer “MCP server” implementations—a niche protocol gaining traction in AI‑agent frameworks—thereby exploiting a trust gap in emerging tech communities. GitHub’s security team has begun removing the identified repositories, but the attackers continue to register new accounts at a rate that outpaces manual takedowns.
**Industry Analysis**
The FakeGit incident underscores a growing trend: threat actors are weaponizing the very openness that makes platforms like GitHub indispensable for innovation. By targeting niches such as AI skill‑sharing and MCP servers, the campaign capitalizes on developers’ eagerness to adopt cutting‑edge tools without rigorous vetting. This mirrors earlier supply‑chain attacks (e.g., event‑stream, Codecov) but differs in