FakeGit malware campaign returns with 17,610 malicious GitHub repos
The FakeGit campaign reactivated on October 4 and now uses 17,610 GitHub repositories to distribute SmartLoader and StealC. In 34 hours it pushed over 13,000 repos, with 97% of commits touching only the README and 88% of download buttons pointing to a ZIP that installs malware.
- FakeGit uses 17,610 GitHub repositories to spread SmartLoader malware
- Over 13,000 repos were pushed in 34 hours, peaking at 2,999 per hour
- 97% of commits touched only the README, 88% of download buttons led to a malicious ZIP
- 71% of the repos were missing from URLhaus before Apiiro's report
Read next
Security