Researchers at enterprise browser company Island have uncovered FakeGit malware, a large-scale campaign that uses roughly 7,600 fake GitHub repositories created by approximately 6,600 throwaway accounts to distribute SmartLoader and the StealC information stealer.
More than 800 repositories impersonate AI Skills or Model Context Protocol (MCP) servers, enabling a technique researchers call AgentBaiting to target both developers and AI coding agents. While campaign files have generated over 14 million download events, researchers stress that this figure reflects download activity, not confirmed malware infections.
FakeGit malware is a large-scale software supply chain campaign that exploits developers’ trust in GitHub and open-source software. Instead of targeting software vulnerabilities, attackers create convincing fake GitHub repositories that mimic legitimate projects, developer tools, and AI integrations to trick developers or AI coding assistants into downloading and running malicious code.
According to Island’s research, the campaign delivers SmartLoader, which installs additional malware, including the StealC information stealer.
The campaign highlights how threat actors are increasingly abusing trusted developer platforms and AI-assisted software discovery to distribute malware.
Many of these repositories impersonate well-known open-source projects and developer tools, including Gmail, WhatsApp, Databricks, Jenkins, and Docker.
To appear legitimate, attackers use convincing README files, fabricated GitHub star counts, copied project descriptions, and stolen or borrowed developer identities.
Some repositories are fully fake, while others closely replicate real projects, making them difficult to distinguish from authentic software.
The campaign also abuses GitHub Releases to distribute malware at scale:
Around 200 repositories were used for malware distribution (as of July 2026)
These generated more than 14 million download events
However, researchers note that:
These figures include automated requests and bot traffic
Download counts should not be interpreted as confirmed infections
In addition, FakeGit malware actively targets AI-assisted software discovery systems:
These repositories appeared more than 600 times across public AI tool registries, including:
LobeHub
Glama
MCP.so
MCP Market
This widespread impersonation increases the risk that both developers and AI coding assistants may unknowingly interact with malicious repositories.
How the FakeGit Infection Chain Works
The attack begins when a developer or an AI coding assistant acting on the developer’s behalf downloads a ZIP archive disguised as a legitimate software release from a fake GitHub repository.
The archive contains a launcher script, a renamed LuaJIT runtime executable, and a payload disguised as a harmless file, such as an icon, text document, or software license. Running the launcher executes an obfuscated Lua script that installs SmartLoader.
According to Island’s research, SmartLoader establishes persistence using Windows Scheduled Tasks before retrieving its command-and-control (C2) endpoint from a Polygon smart contract instead of a traditional domain or IP address.
It then retrieves additional encrypted payloads from GitHub, ultimately deploying StealC to steal browser credentials, cookies, cryptocurrency wallets, and other sensitive data.
Featured resource
Hexnode UEM Capability Statement
Learn how Hexnode UEM helps secure developer devices with application control, endpoint management, and policy enforcement to reduce software-based security risks.
Unlike traditional typosquatting campaigns, FakeGit malware targets AI-assisted software discovery.
Island calls this technique AgentBaiting. Instead of waiting for developers to find malicious repositories, attackers publish fake AI Skills and Model Context Protocol (MCP) servers so they appear in AI tool registries and are more likely to be recommended by AI coding assistants.
Researchers report that the AI-focused phase of the campaign began in March 2026, peaked in April 2026, and eventually expanded to more than 1,400 repositories linked to AI tools, agents, and development workflows.
As AI coding assistants increasingly recommend repositories and install tools with limited human review, organizations should apply the same verification and security controls to AI-recommended software as they do to software selected by developers.
What We Know About FakeGit Malware So Far
Several widely reported figures about FakeGit malware require careful interpretation.
The reported 14 million download events came from roughly 200 GitHub repositories.
GitHub download counters include automated requests, bots, and repeated downloads, so they should not be interpreted as confirmed malware infections.
The campaign’s 600+ appearances across public AI tool registries indicate visibility rather than confirmed installations by developers or AI coding assistants.
Attribution also remains unconfirmed. Public reporting links FakeGit to an earlier Lumma Stealer campaign that Trend Micro attributed to the threat actor Water Kurita.
However, this reflects similarities in infrastructure or tradecraft, not a confirmed attribution of FakeGit itself. Other reports suggest the campaign may be operated by a single threat actor, although this has not been consistently corroborated.
How to Protect Against FakeGit Malware
Because FakeGit malware relies on deception rather than software vulnerabilities, organizations should strengthen developer security and verify software before execution.
Security teams can reduce the risk by:
Verifying repository owners, contributor history, and commit activity before downloading code.
Treating unfamiliar GitHub repositories, AI Skills, and MCP servers as untrusted until validated.
Restricting unauthorized software with application allowlisting or application control policies.
Enforcing multi-factor authentication (MFA) for developer accounts and source-control platforms.
Monitoring developer endpoints for unusual process execution and persistence mechanisms.
Training developers to verify AI-recommended repositories before installing or running software.
As AI coding assistants become part of everyday development workflows, organizations should apply the same security controls to AI-recommended software as they do to software selected by developers.
Explore how compromised GitHub credentials enabled a software supply chain attack.
How Hexnode Helps Secure Developer Endpoints Against FakeGit Malware
Because FakeGit malware succeeds when developers execute untrusted software, organizations should combine application control, endpoint visibility, and identity protection to reduce risk.
Hexnode UEM helps enforce application allowlisting and blocklisting on Windows and macOS devices, reducing the risk of developers running unverified executables from malicious GitHub repositories.
Hexnode XDR helps security teams investigate suspected infections on managed Windows endpoints using Process Tree and Advanced Investigation Queries. Administrators can also use Kill Process or Isolate Device to support incident response.
Hexnode IdP helps reduce the impact of stolen credentials by enforcing device compliance and multi-factor authentication (MFA) through conditional access policies.
Together, Hexnode UEM, Hexnode XDR, and Hexnode IdP help reduce the attack surface exposed to FakeGit malware by strengthening application control, endpoint visibility, and identity security.
The Bottom Line
The FakeGit malware campaign demonstrates how threat actors are evolving beyond traditional software supply chain attacks. Instead of exploiting software vulnerabilities, they abuse trusted GitHub repositories and AI-assisted software discovery to deliver malware.
Organizations should treat AI-recommended repositories, AI Skills, and MCP servers with the same scrutiny as any other third-party software. Combining repository verification, application control, endpoint monitoring, and strong identity protections can significantly reduce the risk of campaigns like FakeGit.
By combining Hexnode UEM, Hexnode XDR, and Hexnode IdP, organizations can strengthen application control, improve endpoint visibility, and reduce the impact of credential theft associated with campaigns like FakeGit malware.
Protect Developer Endpoints from Modern Malware
Strengthen application control, endpoint visibility, and identity security with Hexnode's unified endpoint management and security solutions.
I write at the intersection of technology, process, and people, focusing on explaining complex products with clarity. I break down tools, systems, and workflows without any noise, jargon, or the hype.