Skip to content
FakeGit Malware Campaign Resurfaces with 17,610 Malicious Repositories

FakeGit Malware Campaign Resurfaces with 17,610 Malicious Repositories

First seen 9 Oct 2026, 21:38 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 9, 2026 at 22:37 UTC
  • •FakeGit campaign has over 17,610 malicious GitHub repositories.
  • •SmartLoader malware is distributed via convincing README files with download links.
  • •Users should verify repository owners and consider potential account compromises.

The FakeGit malware campaign has reactivated, distributing SmartLoader malware via over 17,610 fake repositories on GitHub. This resurgence, noted by researchers from Apiiro, began on October 4, 2026, and has already seen the creation of more than 13,000 repositories in just 34 hours. The malicious repositories employ convincing README files with download buttons that link to ZIP archives containing SmartLoader, which is used to further distribute malware, including the StealC infostealer. The campaign's persistence is attributed to GitHub's repository removal policies, which often overlook a significant number of malicious repositories. Attackers can easily redirect existing repositories to new malicious payloads, rendering traditional blocklisting ineffective. Users are advised to verify repository owners and obtain software from official sources to mitigate risks. If SmartLoader execution is suspected, users should treat it as a potential account compromise and revoke sessions and access tokens.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-10-04
FakeGit campaign reactivated
The FakeGit malware campaign resumed activity, creating over 17,610 malicious repositories on GitHub.
BleepingComputer
2026-10-08
Bleeping Computer reports on FakeGit
Bleeping Computer published details on the resurgence of the FakeGit campaign and its distribution methods.
BleepingComputer
2026-10-09
Scworld coverage of FakeGit
Scworld provided further coverage on the FakeGit campaign, highlighting its distribution of SmartLoader malware.
Scworld

More articles in this cluster (3)

Following this threat?

Track StealC in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

How many repositories are involved?
The FakeGit campaign has over 17,610 malicious repositories on GitHub.
What should users do if they suspect infection?
Users should treat it as a potential account compromise, revoke sessions, and consider implementing passkeys.
What is the primary malware being distributed?
The primary malware being distributed is SmartLoader, which is used to further distribute other malware like StealC.