• 3 min read
7,600 GitHub repos spread SmartLoader malware
FakeGit used 7,600 GitHub repositories to distribute SmartLoader and StealC, including AI projects designed to attract agents and developers.

Image: BleepingComputer
A campaign dubbed FakeGit has used 7,600 malicious GitHub repositories to distribute SmartLoader and StealC malware. The repositories recorded more than 14 million downloads, although researchers caution that this figure does not represent confirmed infections.
More than 800 repositories posed as AI skills or Model Context Protocol (MCP) servers and appeared over 600 times in public AI registries and catalogs. The strategy, which researchers call “agentbaiting,” is intended to make malicious projects more visible to AI agents and developers.
Researchers at enterprise browser company Island said the campaign’s AI focus began in March and peaked in April, when about 300 repositories linked to AI tools were created. FakeGit eventually expanded to more than 1,400 repositories connected to AI tools, agents, and workflows, all directing users toward SmartLoader or StealC downloads.
The operation appears to continue an older campaign that distributed Lumma Stealer and was attributed by Trend Micro researchers to a threat actor tracked as Water Kurita.
How the malicious repositories work
Malicious GitHub repository — Source: Island

Recommended reading
Kratos phishing platform dismantled, developer arrested
Many repositories imitate familiar consumer and enterprise products, including Gmail, WhatsApp, Databricks, Jenkins, and Docker. They use copied project descriptions, fabricated star and fork counts, convincing documentation, and real developer account names to appear legitimate.
Their README files instruct visitors to download ZIP archives presented as installers or project releases. The archives instead contain disguised Lua payloads that activate SmartLoader. The loader then:
- Establishes persistence through scheduled tasks.
- Retrieves its command-and-control address through a Polygon smart contract.
- Downloads additional encrypted stages from GitHub.
- Delivers the StealC information stealer.
AI registries expose malicious projects
Malicious README file — Source: Island
Island researchers say FakeGit’s repositories were designed to be parsed as legitimate documentation by AI agents. In tests, ChatGPT, Gemini, and Claude surfaced malicious repositories when prompted with related tasks and sometimes repeated their installation instructions.
Island also found more than 600 listings for FakeGit-linked skills and MCP servers in public registries and catalogs, including LobeHub, Glama, MCP.so, and MCP Market. The researchers could not determine whether these listings were submitted manually or indexed automatically, but said their presence improved the repositories' discoverability and apparent credibility.
In limited, controlled tests, Claude Code cloned malicious repositories and downloaded their files onto a test machine. The agent later detected suspicious indicators and stopped before execution. Island said the tests were not designed to measure a detection rate and cannot show whether coding agents consistently identify the threat during execution.
Attack chain — Source: Island
GitHub’s public counters for 335 unique Release assets across 211 repositories recorded 14,084,688 cumulative download events. Oleg Zaytsev, lead security researcher at Island, said the total includes repeated requests and automated activity and should not be treated as an infection count.
Island recommends that organizations maintain approved catalogs of AI skills and MCP servers, test new capabilities in isolated environments, and independently verify publishers and repositories. If SmartLoader execution is suspected, organizations should immediately rotate all secrets stored in affected environments.
Security Editor
Sophia unpacks the invisible wars happening on our networks. Covering cybersecurity, privacy legislation, and cryptography, she exposes how our data is weaponized and defended. Before joining for(geeks), she spent years as a penetration tester. She's the reason the rest of the team uses physical security keys.
via BleepingComputer


