chiprook
← Security
SecurityOctober 9, 2026, 00:10

FakeGit malware campaign returns with 17,610 malicious GitHub repos

The FakeGit campaign reactivated on October 4 and now uses 17,610 GitHub repositories to distribute SmartLoader and StealC. In 34 hours it pushed over 13,000 repos, with 97% of commits touching only the README and 88% of download buttons pointing to a ZIP that installs malware.

FakeGit malware campaign returns with 17,610 malicious GitHub repos
#GitHub#SmartLoader#StealC#Apiiro
Read next
Security

GitHub lost 3,800 repos after malicious VSCode extension

Security

Attackers Use Malicious Terraform Providers to Deliver Go Malware via HashiCorp Registry

Security

Hackers hide malware commands in blockchains as malicious activity jumps 440%

Security

JFrog Finds 3,022 Malicious Gems in OpenAI AI Agent Campaign