Scworld FakeGit Malware Campaign Resurfaces with 17,610 Malicious Repositories
Article Content
- •FakeGit campaign has over 17,610 malicious GitHub repositories.
- •SmartLoader malware is distributed via convincing README files with download links.
- •Users should verify repository owners and consider potential account compromises.
The FakeGit malware campaign has reactivated, distributing SmartLoader malware via over 17,610 fake repositories on GitHub. This resurgence, noted by researchers from Apiiro, began on October 4, 2026, and has already seen the creation of more than 13,000 repositories in just 34 hours. The malicious repositories employ convincing README files with download buttons that link to ZIP archives containing SmartLoader, which is used to further distribute malware, including the StealC infostealer. The campaign's persistence is attributed to GitHub's repository removal policies, which often overlook a significant number of malicious repositories. Attackers can easily redirect existing repositories to new malicious payloads, rendering traditional blocklisting ineffective. Users are advised to verify repository owners and obtain software from official sources to mitigate risks. If SmartLoader execution is suspected, users should treat it as a potential account compromise and revoke sessions and access tokens.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track StealC in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
How many repositories are involved?
What should users do if they suspect infection?
What is the primary malware being distributed?
Continue Reading
CVE-2015-3306 Exploited in ProFTPD FTP Servers CVE-2015-3306, a vulnerability in ProFTPD 1.3.5, allows remote attackers to read and write arbitrary files using the SITE CPFR and SITE CPTO commands. This exploit can lead to unauthorized access and potential remote code execution, as the commands are executed with the privileges of the ProFTPD service. Active…
CISA Sets Oct. 11 Deadline for Patching Flaws Exploited by Flax Typhoon The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added five vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog after they were exploited by the China-linked group Flax Typhoon. Federal agencies must patch or retire the affected software by October 11, 2026. The vulnerabilities…