The security firm Apiiro counts 17,610 malicious repositories in the FakeGit campaign on GitHub, a fleet of fake projects built to push the SmartLoader malware onto people who download them. In one 34-hour stretch after the operation restarted on Oct. 4, it pushed out more than 13,000 repositories, peaking at 2,999 in a single hour.
The payload that SmartLoader fetches next, an infostealer called StealC, goes after saved browser passwords.
Seventeen thousand repositories and one switch
The figures come from Apiiro, a software supply-chain security company, as BleepingComputer reported on Oct. 8. The trick, in Apiiro’s telling, is reuse: the operator did not have to create a single new repository, because the fleet already existed. In Apiiro’s words, “the fleet was already there. It just got re-aimed.” Similar activity with various payloads has been seen since at least January, and the FakeGit name was tied to this operation in July. Each repository carries a convincing README with a Download button, so a visitor sees what looks like a maintained project rather than a trap.
In sampled commits, 97 percent changed only the README file, and 88 percent pointed the Download button at a ZIP archive that installs SmartLoader. Most of the accounts are throwaways, though Apiiro says at least 700 appear to belong to legitimate developers. That matters for anyone judging a project by its owner, since an account with a real history can still be hosting a lure.
StealC, the credential stealer SmartLoader brings in
SmartLoader is a loader, a first-stage program whose job is to bring in other malware. In this campaign it delivers StealC. Island, the enterprise browser company whose researchers tracked the earlier wave, says StealC takes browser passwords and extension data, cookies and active sessions, screenshots and host information, and email and remote-access credentials, according to DevOps.com.
The download button leads to an archive that, in Island’s description, holds a heavily obfuscated 300 KB Lua payload disguised as a text, icon, license or data file. Hexnode’s summary of the July research traces the rest of the chain: a launcher script and a renamed LuaJIT runtime run the Lua script, SmartLoader persists through Windows Scheduled Tasks, it reads its command address from a Polygon smart contract instead of a conventional domain, and it pulls encrypted stages from GitHub itself.
URLhaus gaps and the blocklist problem
Apiiro’s central finding is that takedowns miss most of the fleet. Before its report, 71 percent of the repositories were missing from URLhaus, the malware-URL list many defenders feed into blocklists. A domain-level DNS block cannot stop a single file on GitHub without blocking GitHub, and the malicious archives also turned up in forks, older files, release assets, issue attachments and separate download-hosting repositories. Removing one link, the firm warns, lets the operator point the lure at a spare copy.
Apiiro’s advice, as relayed by BleepingComputer, is to verify a repository’s owner before installing anything, to take AI skills and MCP servers only from official registries or vendor repositories, and, where SmartLoader execution is suspected, to treat the event as a possible GitHub account compromise: revoke active sessions and access tokens and move to passkeys. BleepingComputer’s report does not include a response from GitHub.
From 7,600 repositories to 17,610
The operation has grown sharply since it was named in July, when Island’s researchers first counted its repositories by the thousand and Hexnode recorded a dated timeline of the AI-themed phase that began in March. Island’s July research, summarized by The Hacker News on July 20, found nearly 7,600 malicious repositories created by about 6,600 profiles, with more than 800 posing as AI skills or Model Context Protocol servers and more than 600 listings flagged across registries such as LobeHub, Glama, MCP.so and MCP Market. Island lead researcher Oleg Zaytsev said the campaign relies on “copied projects, lookalike developer profiles, convincing READMEs.”
The same research recorded more than 14 million downloads from about 200 campaign repositories, a number BleepingComputer’s July report quotes Zaytsev as saying should not be read as infections, since it includes repeated and automated requests. DevOps.com adds that about 1,400 of the profiles were tied to AI tools, agents or workflows, that AI-related repository creation began building in March and peaked in April at almost 300 repositories, and that thousands more repositories embedded malicious ZIP files directly, downloads that GitHub does not publicly count. Island also showed that Claude Code, Gemini and ChatGPT could surface malicious repositories without being handed a link, which it named AgentBaiting.
Apiiro’s count of 17,610 is the first figure for the restarted campaign, and the firm’s finding that 71 percent of the fleet sat outside URLhaus is the measure of how much of it defenders could not see.
This article was produced with the assistance of AI and reviewed by Morning Overview editors prior to publication.
More from Morning Overview
- Tropical Storm Rachel is dumping up to 12 inches on four Mexican states on its way to major hurricane strength
- The FTC says Lens.com doubled the price shoppers saw in Google ads
- Common allergy, bladder and sleep pills tied to sharply higher dementia odds
- NOAA now gives this winter a 75% chance of the strongest El Nino since 1950