FakeGit Resurfaces on GitHub with Over 17,000 Malicious Repositories Deploying SmartLoader Malware
The FakeGit operation has reemerged, this time populating more than 17,600 counterfeit repositories on GitHub with the SmartLoader payload. Security researchers observed the campaign restart earlier this month, using the new repositories to deliver the StealC infostealer to unsuspecting users who clone or download the code.
FakeGit is not new to the open‑source ecosystem; it first attracted attention in 2022 when threat actors began publishing bogus projects that appeared legitimate, often copying popular library names or mimicking well‑known open‑source tools. By leveraging GitHub's free hosting and its built‑in CI/CD features, the attackers can embed malicious scripts that execute when a victim runs typical setup commands, such as npm install or pip install. The latest wave expands the scale dramatically, with more than seventeen thousand repositories now indexed by the platform’s search tools.
The payload being distributed, SmartLoader, is a modular loader designed to fetch additional malicious components from remote servers. In this iteration it retrieves StealC, an infostealer that harvests credentials, browser cookies, and cryptocurrency wallet information before transmitting the data to command‑and‑control infrastructure. Because the loader is lightweight and can be disguised as a legitimate dependency, it often evades basic antivirus checks and can persist on compromised machines for extended periods.
GitHub has responded by issuing takedown notices for the identified repositories and urging developers to verify the authenticity of any third‑party code before execution. The company’s security team also recommends enabling two‑factor authentication, reviewing repository provenance, and using tools such as Software Bill of Materials (SBOM) generators to spot unexpected dependencies. Security firms, including BleepingComputer, have published indicators of compromise to aid detection in endpoint protection platforms.
Analysts caution that the resurgence of FakeGit signals a broader trend of threat actors exploiting the trust placed in open‑source ecosystems. As the number of malicious repositories continues to climb, developers and organizations will need to adopt stricter vetting practices and maintain up‑to‑date security tooling. Ongoing monitoring of GitHub’s repository landscape and rapid response to newly flagged projects will be essential to curb the spread of SmartLoader and its associated stealer.
Comments (0)
Be the first to comment.
Join the discussion