
More than 17,000 fake repositories on GitHub are distributing the SmartLoader malware after the FakeGit campaign reactivated earlier this month to push the StealC infostealer. The repositories carry convincing README instructions and a “Download” button that points to a ZIP archive holding the initial payload, SmartLoader, which then installs other malware. The operator mostly uses throwaway accounts, but researchers identified at least 700 accounts that appear to belong to legitimate developers.
Researchers at software supply-chain security firm Apiiro say FakeGit resumed activity on October 4 and now uses 17,610 repositories. In 34 hours it pushed more than 13,000 repos, peaking at 2,999 an hour. In the commits Apiiro sampled, 97% touched only the README and 88% pointed the download button at a ZIP that installs SmartLoader. The fleet already existed; it was simply re-aimed. The FakeGit name dates to July, when Island published a report on 7,600 fake repositories pushing SmartLoader, 800 of which posed as AI skills or MCP servers listed in public AI registries.
The campaign survives because takedowns work from lists that cover only a fraction of the malicious repos. Apiiro says 71% of the fleet was missing from the URLhaus malware-URL list before its report, and a domain-level block cannot stop one file on GitHub without blocking GitHub itself. Malicious archives were also found in forks, older files, release assets, issue attachments and separate download-hosting repositories, so when one link is deleted the operator can point the lure at a spare copy.
How to check if you’re affected
Affected products are any software, AI skill or MCP server you downloaded from a GitHub repository whose README sent you to a ZIP archive rather than a normal release or package install, especially if the repo was found through a search result, an AI registry or an unfamiliar account.
- Check the repository owner before you run anything: look at the account’s age, history and whether it matches the project’s real maintainers. Install AI skills and MCP servers only from official registries or the vendor’s own repositories.
- If you ran something from a repo like this, Apiiro advises treating it as a potential GitHub account compromise: revoke active sessions and access tokens, and move to passkeys. Because StealC steals saved browser logins, also change passwords for accounts saved on that device from a clean one.
