Skip to content
FakeGit Infrastructure Re-Armed in Large-Scale RePointing Campaign

FakeGit Infrastructure Re-Armed in Large-Scale RePointing Campaign

Broadcom • October 9, 2026

According to Apiiro, security researchers observed a massive automated campaign re-arming a fleet of more than 17,000 malicious GitHub repositories linked to the FakeGit ecosystem. Skipping the need for new infrastructure, the threat actor utilizes a tactic termed RePointing, executing rapid, automated commits to update existing project README files so their download links redirect to fresh ZIP archives. These archives contain a modified LuaJIT runtime and obfuscated scripts designed to deliver the SmartLoader loader and ultimately drop the StealC infostealer. The operation relies on thousands of throwaway developer accounts alongside compromised legitimate accounts to maintain persistence, bypass static URL blocklists, and harvest user credentials and session tokens.

Symantec protects you from this threat, identified by the following:

Associated malicious indicators are blocked and detected by existing policies within Carbon Black products. The recommended policy at a minimum is to block all types of malware from executing (Known, Suspect, and PUP) as well as delay execution for cloud scan to get maximum benefit from Carbon Black Cloud reputation service.

Machine Learning-based

Extracted Entities

Attack Types (1)

Campaigns (1)

Malware (1)

Platforms (2)