{"id":719,"date":"2026-07-27T16:55:44","date_gmt":"2026-07-27T11:25:44","guid":{"rendered":"https:\/\/www.hexnode.com\/threat-watch\/?p=719"},"modified":"2026-08-18T17:00:10","modified_gmt":"2026-08-18T11:30:10","slug":"fakegit-malware-github-repositories-smartloader-stealc","status":"publish","type":"post","link":"https:\/\/www.hexnode.com\/threat-watch\/fakegit-malware-github-repositories-smartloader-stealc\/","title":{"rendered":"FakeGit Malware: How 7,600 Fake GitHub Repositories Spread SmartLoader and StealC"},"content":{"rendered":"<h2>What Is FakeGit Malware?<\/h2>\n<p>FakeGit malware is a large-scale software supply chain campaign that exploits developers&#8217; trust in GitHub and open-source software. Instead of targeting software vulnerabilities, attackers create convincing fake GitHub repositories that mimic legitimate projects, developer tools, and AI integrations to trick developers or AI coding assistants into downloading and running malicious code.<\/p>\n<p>According to Island&#8217;s research, the campaign delivers SmartLoader, which installs additional malware, including the StealC information stealer.<\/p>\n<p>The campaign highlights how threat actors are increasingly abusing trusted developer platforms and AI-assisted software discovery to distribute malware.<\/p>\n<h2>How the FakeGit Malware Campaign Works<\/h2>\n<p>Researchers identified approximately <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/fakegit-campaign-uses-7-600-github-repos-to-push-smartloader-malware\/?utm_source=hexnode_blog&amp;utm_medium=referral&amp;utm_campaign=fakegit_malware\" target=\"_blank\" rel=\"nofollow noreferrer noopener\">7,600 malicious GitHub repositories spread across nearly 6,600 disposable GitHub accounts<\/a>.<\/p>\n<p>Many of these repositories impersonate well-known open-source projects and developer tools, including Gmail, WhatsApp, Databricks, Jenkins, and Docker.<\/p>\n<p>To appear legitimate, attackers use convincing README files, fabricated GitHub star counts, copied project descriptions, and stolen or borrowed developer identities.<\/p>\n<p>Some repositories are fully fake, while others closely replicate real projects, making them difficult to distinguish from authentic software.<\/p>\n<p>The campaign also abuses GitHub Releases to distribute malware at scale:<\/p>\n<ul>\n<li>Around 200 repositories were used for malware distribution (as of July 2026)<\/li>\n<li>These generated more than 14 million download events<\/li>\n<\/ul>\n<p>However, researchers note that:<\/p>\n<ul>\n<li>These figures include automated requests and bot traffic<\/li>\n<li>Download counts should not be interpreted as confirmed infections<\/li>\n<\/ul>\n<p>In addition, FakeGit malware actively targets AI-assisted software discovery systems:<\/p>\n<ul>\n<li>Over 800 repositories impersonated AI Skills or <a href=\"https:\/\/www.hexnode.com\/blogs\/explained\/what-is-model-context-protocol-mcp\/\">Model Context Protocol<\/a> (MCP) servers<\/li>\n<li>These repositories appeared more than 600 times across public AI tool registries, including:\n<ul>\n<li>LobeHub<\/li>\n<li>Glama<\/li>\n<li>MCP.so<\/li>\n<li>MCP Market<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<p>This widespread impersonation increases the risk that both developers and AI coding assistants may unknowingly interact with malicious repositories.<\/p>\n<h2>How the FakeGit Infection Chain Works<\/h2>\n<p>The attack begins when a developer or an AI coding assistant acting on the developer&#8217;s behalf downloads a ZIP archive disguised as a legitimate software release from a fake GitHub repository.<\/p>\n<p>The archive contains a launcher script, a renamed LuaJIT runtime executable, and a payload disguised as a harmless file, such as an icon, text document, or software license. Running the launcher executes an obfuscated Lua script that installs SmartLoader.<\/p>\n<p>According to Island&#8217;s research, SmartLoader establishes persistence using Windows Scheduled Tasks before retrieving its <a href=\"https:\/\/www.hexnode.com\/blogs\/explained\/what-is-command-and-control-c2\/\">command-and-control<\/a> (C2) endpoint from a Polygon smart contract instead of a traditional domain or IP address.<\/p>\n<p>It then retrieves additional encrypted payloads from GitHub, ultimately deploying StealC to steal browser credentials, cookies, cryptocurrency wallets, and other sensitive data.<br \/>\n<section id='resource-single'>\n                    <div class='resource-box'>\n                        <div class='resource-box__image-section'>\n                            <div class='resource-box__image-wrap'>\n                                <img decoding=\"async\" src=\"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Hexnode_UEM-Capability-statement-e1783572504474.png?format=webp\" class=\"resource-box__image\" alt=\"Hexnode_UEM-Capability-statement\" loading=\"lazy\" srcset=\"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Hexnode_UEM-Capability-statement-e1783572504474.png?format=webp 698w, https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Hexnode_UEM-Capability-statement-e1783572504474-300x284.png?format=webp 300w, https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Hexnode_UEM-Capability-statement-e1783572504474-106x100.png?format=webp 106w\" sizes=\"auto, (max-width: 698px) 100vw, 698px\" title=\"Hexnode_UEM-Capability-statement\" \/>\n                            <\/div>\n                        <\/div>\n                        <div class='resource-box__content-section'>\n                            <h5 class='resource-box__content-subheading'>\n                            Featured resource\n                            <\/h5>\n                            <h4 class='resource-box__content-heading'>\n                            Hexnode UEM Capability Statement\n                            <\/h4>\n                            <p class='resource-box__contents'>\n                            Learn how Hexnode UEM helps secure developer devices with application control, endpoint management, and policy enforcement to reduce software-based security risks.\n                            <\/p>\n                            <a class='resource-box__content-link hn-cta__blogs--resource-box' href='https:\/\/www.hexnode.com\/resources\/brochures\/hexnode-uem-capability-statement\/'>\n                            Download the brochure\n                            <svg xmlns='http:\/\/www.w3.org\/2000\/svg' width='20' height='20' viewBox='0 0 20 20'>\n                            <g id='arrow' transform='translate(-309 -191)' opacity='0'>\n                                <rect id='base' width='20' height='20' transform='translate(309 191)' fill='none'\/>\n                                <path id='arrow-2' data-name='arrow' d='M13.093.5,6.8,6.8.5.5' transform='translate(315 207.594) rotate(-90)' fill='none' stroke='#0549d1' stroke-linecap='round' stroke-linejoin='round' stroke-width='1.2'\/>\n                            <\/g>\n                            <\/svg>\n\n                            <\/a>\n                        <\/div>\n                    <\/div>\n                <\/section><\/p>\n<h2>Why AI Coding Agents Increase the Risk<\/h2>\n<p>Unlike traditional typosquatting campaigns, FakeGit malware targets AI-assisted software discovery.<\/p>\n<p>Island calls this technique AgentBaiting. Instead of waiting for developers to find malicious repositories, attackers publish fake AI Skills and Model Context Protocol (MCP) servers so they appear in AI tool registries and are more likely to be recommended by AI coding assistants.<\/p>\n<p>Researchers report that the AI-focused phase of the campaign began in March 2026, peaked in April 2026, and eventually expanded to more than 1,400 repositories linked to AI tools, agents, and development workflows.<\/p>\n<p>As AI coding assistants increasingly recommend repositories and install tools with limited human review, organizations should apply the same verification and security controls to AI-recommended software as they do to software selected by developers.<\/p>\n<h2>What We Know About FakeGit Malware So Far<\/h2>\n<p>Several widely reported figures about FakeGit malware require careful interpretation.<\/p>\n<p>The reported 14 million download events came from roughly 200 GitHub repositories.<\/p>\n<p>GitHub download counters include automated requests, bots, and repeated downloads, so they should not be interpreted as confirmed malware infections.<\/p>\n<p>The campaign&#8217;s 600+ appearances across public AI tool registries indicate visibility rather than confirmed installations by developers or AI coding assistants.<\/p>\n<p>Attribution also remains unconfirmed. Public reporting links FakeGit to an earlier Lumma Stealer campaign that Trend Micro attributed to the threat actor Water Kurita.<\/p>\n<p>However, this reflects similarities in infrastructure or tradecraft, not a confirmed attribution of FakeGit itself. Other reports suggest the campaign may be operated by a single <a href=\"https:\/\/www.hexnode.com\/blogs\/explained\/what-is-threat-actor-in-cyber-security\/\">threat actor<\/a>, although this has not been consistently corroborated.<\/p>\n<h2>How to Protect Against FakeGit Malware<\/h2>\n<p>Because FakeGit malware relies on deception rather than software vulnerabilities, organizations should strengthen developer security and verify software before execution.<\/p>\n<p>Security teams can reduce the risk by:<\/p>\n<ul>\n<li>Verifying repository owners, contributor history, and commit activity before downloading code.<\/li>\n<li>Treating unfamiliar GitHub repositories, AI Skills, and MCP servers as untrusted until validated.<\/li>\n<li>Restricting unauthorized software with <a href=\"https:\/\/www.hexnode.com\/blogs\/explained\/what-is-application-allowlisting\/\">application allowlisting<\/a> or application control policies.<\/li>\n<li>Enforcing multi-factor authentication (MFA) for developer accounts and source-control platforms.<\/li>\n<li>Monitoring developer endpoints for unusual process execution and persistence mechanisms.<\/li>\n<li>Training developers to verify AI-recommended repositories before installing or running software.<\/li>\n<\/ul>\n<p>As AI coding assistants become part of everyday development workflows, organizations should apply the same security controls to AI-recommended software as they do to software selected by developers.<br \/>\n<div class=\"next_blog\"><div class=\"post-next\"><div class=\"hex_blog_box_parent\"><div class=\"blog_warp_next\"><div class=\"next_blog_thumb\" style=\"background-image:url(https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/07\/grafana-github-token-breach-150x150-2.webp?format=webp)\"><\/div><div class=\"next_post_content\"><div class=\"center_box\"><h4>Grafana GitHub Token Breach Highlights Growing Supply Chain Security Risks<\/h4><p>Explore how compromised GitHub credentials enabled a software supply chain attack.<\/p><\/div><\/div><\/div><a class=\"hex_blog_box_link hn-cta__blogs--blog-box\" href=\"https:\/\/www.hexnode.com\/blogs\/grafana-github-token-breach-highlights-growing-supply-chain-security-risks\/\" aria-label=\"Grafana GitHub Token Breach Highlights Growing Supply Chain Security Risks\"><\/a><\/div><\/div><\/div><\/p>\n<h2>How Hexnode Helps Secure Developer Endpoints Against FakeGit Malware<\/h2>\n<p>Because FakeGit malware succeeds when developers execute untrusted software, organizations should combine application control, endpoint visibility, and identity protection to reduce risk.<\/p>\n<p><a href=\"https:\/\/www.hexnode.com\/uem\/\">Hexnode UEM<\/a> helps enforce application allowlisting and blocklisting on Windows and macOS devices, reducing the risk of developers running unverified executables from malicious GitHub repositories.<\/p>\n<p><a href=\"https:\/\/www.hexnode.com\/xdr\/\">Hexnode XDR<\/a> helps security teams investigate suspected infections on managed Windows endpoints using Process Tree and Advanced Investigation Queries. Administrators can also use Kill Process or Isolate Device to support incident response.<\/p>\n<p><a href=\"https:\/\/www.hexnode.com\/idp\/\">Hexnode IdP<\/a> helps reduce the impact of stolen credentials by enforcing device compliance and multi-factor authentication (MFA) through conditional access policies.<\/p>\n<p>Together, Hexnode UEM, Hexnode XDR, and Hexnode IdP help reduce the attack surface exposed to FakeGit malware by strengthening application control, endpoint visibility, and identity security.<\/p>\n<h3>The Bottom Line<\/h3>\n<p>The FakeGit malware campaign demonstrates how threat actors are evolving beyond traditional software supply chain attacks. Instead of exploiting software vulnerabilities, they abuse trusted GitHub repositories and AI-assisted software discovery to deliver malware.<\/p>\n<p>Organizations should treat AI-recommended repositories, AI Skills, and MCP servers with the same scrutiny as any other third-party software. Combining repository verification, application control, endpoint monitoring, and strong identity protections can significantly reduce the risk of campaigns like FakeGit.<\/p>\n<p>By combining Hexnode UEM, Hexnode XDR, and Hexnode IdP, organizations can strengthen application control, improve endpoint visibility, and reduce the impact of credential theft associated with campaigns like FakeGit malware.<br \/>\n<div class=\"signup_box\"><div class=\"signup_wrap_img\"><div class=\"signup-bg\" style=\"background-image:url(https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Hexnode-MDM-free-trial.jpg?format=webp)\"><\/div><\/div><div class=\"signup_wrap\"><h5>Protect Developer Endpoints from Modern Malware<\/h5><p>Strengthen application control, endpoint visibility, and identity security with Hexnode's unified endpoint management and security solutions.<\/p><a href=\"https:\/\/www.hexnode.com\/xdr\/signup\/\" class=\"hn-cta__blogs--signup-stripe\" target=\"_blank\"> Try Hexnode Now<\/a><\/div><\/div><\/p>\n","protected":false},"excerpt":{"rendered":"<p>What Is FakeGit Malware? FakeGit malware is a large-scale software supply chain campaign that exploits&#8230;<\/p>\n","protected":false},"author":4,"featured_media":724,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[1,15],"class_list":["post-719","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-ai-security","category-malware","product_category-extended-detection-and-response","tab_group-malware-and-ransomware"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.3 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>FakeGit Malware: 7,600 Fake GitHub Repositories<\/title>\n<meta name=\"description\" content=\"Learn how FakeGit malware uses 7,600 fake GitHub repositories, AI Skills, and MCP servers to spread SmartLoader and StealC malware.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.hexnode.com\/threat-watch\/fakegit-malware-github-repositories-smartloader-stealc\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"FakeGit Malware: 7,600 Fake GitHub Repositories\" \/>\n<meta property=\"og:description\" content=\"Learn how FakeGit malware uses 7,600 fake GitHub repositories, AI Skills, and MCP servers to spread SmartLoader and StealC malware.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.hexnode.com\/threat-watch\/fakegit-malware-github-repositories-smartloader-stealc\/\" \/>\n<meta property=\"og:site_name\" content=\"Hexnode Threat Watch\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/Hexnode\/\" \/>\n<meta property=\"article:published_time\" content=\"2026-07-27T11:25:44+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-08-18T11:30:10+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/FakeGit-Malware-How-7600-Fake-GitHub-Repositories-Spread-SmartLoader-and-StealC.jpeg?format=webp\" \/>\n\t<meta property=\"og:image:width\" content=\"1340\" \/>\n\t<meta property=\"og:image:height\" content=\"754\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Nora Blake\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@thehexnode\" \/>\n<meta name=\"twitter:site\" content=\"@thehexnode\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Nora Blake\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"5 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":[\"Article\",\"BlogPosting\"],\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/fakegit-malware-github-repositories-smartloader-stealc\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/fakegit-malware-github-repositories-smartloader-stealc\\\/\"},\"author\":{\"name\":\"Nora Blake\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/person\\\/0c83856887182474458e211729d39f9d\"},\"headline\":\"FakeGit Malware: How 7,600 Fake GitHub Repositories Spread SmartLoader and StealC\",\"datePublished\":\"2026-07-27T11:25:44+00:00\",\"dateModified\":\"2026-08-18T11:30:10+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/fakegit-malware-github-repositories-smartloader-stealc\\\/\"},\"wordCount\":1038,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/fakegit-malware-github-repositories-smartloader-stealc\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/FakeGit-Malware-How-7600-Fake-GitHub-Repositories-Spread-SmartLoader-and-StealC.jpeg?format=webp\",\"articleSection\":[\"AI Security\",\"Malware\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/fakegit-malware-github-repositories-smartloader-stealc\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/fakegit-malware-github-repositories-smartloader-stealc\\\/\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/fakegit-malware-github-repositories-smartloader-stealc\\\/\",\"name\":\"FakeGit Malware: 7,600 Fake GitHub Repositories\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/fakegit-malware-github-repositories-smartloader-stealc\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/fakegit-malware-github-repositories-smartloader-stealc\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/FakeGit-Malware-How-7600-Fake-GitHub-Repositories-Spread-SmartLoader-and-StealC.jpeg?format=webp\",\"datePublished\":\"2026-07-27T11:25:44+00:00\",\"dateModified\":\"2026-08-18T11:30:10+00:00\",\"description\":\"Learn how FakeGit malware uses 7,600 fake GitHub repositories, AI Skills, and MCP servers to spread SmartLoader and StealC malware.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/fakegit-malware-github-repositories-smartloader-stealc\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/fakegit-malware-github-repositories-smartloader-stealc\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/fakegit-malware-github-repositories-smartloader-stealc\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/FakeGit-Malware-How-7600-Fake-GitHub-Repositories-Spread-SmartLoader-and-StealC.jpeg?format=webp\",\"contentUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/FakeGit-Malware-How-7600-Fake-GitHub-Repositories-Spread-SmartLoader-and-StealC.jpeg?format=webp\",\"width\":1340,\"height\":754,\"caption\":\"FakeGit Malware: How 7600 Fake GitHub Repositories Spread SmartLoader and StealC\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/fakegit-malware-github-repositories-smartloader-stealc\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"FakeGit Malware: How 7,600 Fake GitHub Repositories Spread SmartLoader and StealC\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#website\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\",\"name\":\"Hexnode Threat Watch\",\"description\":\"Latest cyber threats, smarter enterprise response.\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\"},\"alternateName\":\"Threat Watch\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\",\"name\":\"Hexnode\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/hexnode-2.png?format=webp\",\"contentUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/hexnode-2.png?format=webp\",\"width\":100,\"height\":100,\"caption\":\"Hexnode\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/Hexnode\\\/\",\"https:\\\/\\\/x.com\\\/thehexnode\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/hexnode\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/person\\\/0c83856887182474458e211729d39f9d\",\"name\":\"Nora Blake\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/a3937eeab99c0b56fb02ea93c3ccf9d03e2a8056395f0c69ce21777a1907569c?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/a3937eeab99c0b56fb02ea93c3ccf9d03e2a8056395f0c69ce21777a1907569c?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/a3937eeab99c0b56fb02ea93c3ccf9d03e2a8056395f0c69ce21777a1907569c?s=96&d=mm&r=g\",\"caption\":\"Nora Blake\"},\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/author\\\/nora-blake\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"FakeGit Malware: 7,600 Fake GitHub Repositories","description":"Learn how FakeGit malware uses 7,600 fake GitHub repositories, AI Skills, and MCP servers to spread SmartLoader and StealC malware.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.hexnode.com\/threat-watch\/fakegit-malware-github-repositories-smartloader-stealc\/","og_locale":"en_US","og_type":"article","og_title":"FakeGit Malware: 7,600 Fake GitHub Repositories","og_description":"Learn how FakeGit malware uses 7,600 fake GitHub repositories, AI Skills, and MCP servers to spread SmartLoader and StealC malware.","og_url":"https:\/\/www.hexnode.com\/threat-watch\/fakegit-malware-github-repositories-smartloader-stealc\/","og_site_name":"Hexnode Threat Watch","article_publisher":"https:\/\/www.facebook.com\/Hexnode\/","article_published_time":"2026-07-27T11:25:44+00:00","article_modified_time":"2026-08-18T11:30:10+00:00","og_image":[{"width":1340,"height":754,"url":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/FakeGit-Malware-How-7600-Fake-GitHub-Repositories-Spread-SmartLoader-and-StealC.jpeg?format=webp","type":"image\/jpeg"}],"author":"Nora Blake","twitter_card":"summary_large_image","twitter_creator":"@thehexnode","twitter_site":"@thehexnode","twitter_misc":{"Written by":"Nora Blake","Est. reading time":"5 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":["Article","BlogPosting"],"@id":"https:\/\/www.hexnode.com\/threat-watch\/fakegit-malware-github-repositories-smartloader-stealc\/#article","isPartOf":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/fakegit-malware-github-repositories-smartloader-stealc\/"},"author":{"name":"Nora Blake","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/person\/0c83856887182474458e211729d39f9d"},"headline":"FakeGit Malware: How 7,600 Fake GitHub Repositories Spread SmartLoader and StealC","datePublished":"2026-07-27T11:25:44+00:00","dateModified":"2026-08-18T11:30:10+00:00","mainEntityOfPage":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/fakegit-malware-github-repositories-smartloader-stealc\/"},"wordCount":1038,"commentCount":0,"publisher":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/fakegit-malware-github-repositories-smartloader-stealc\/#primaryimage"},"thumbnailUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/FakeGit-Malware-How-7600-Fake-GitHub-Repositories-Spread-SmartLoader-and-StealC.jpeg?format=webp","articleSection":["AI Security","Malware"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.hexnode.com\/threat-watch\/fakegit-malware-github-repositories-smartloader-stealc\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.hexnode.com\/threat-watch\/fakegit-malware-github-repositories-smartloader-stealc\/","url":"https:\/\/www.hexnode.com\/threat-watch\/fakegit-malware-github-repositories-smartloader-stealc\/","name":"FakeGit Malware: 7,600 Fake GitHub Repositories","isPartOf":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/fakegit-malware-github-repositories-smartloader-stealc\/#primaryimage"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/fakegit-malware-github-repositories-smartloader-stealc\/#primaryimage"},"thumbnailUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/FakeGit-Malware-How-7600-Fake-GitHub-Repositories-Spread-SmartLoader-and-StealC.jpeg?format=webp","datePublished":"2026-07-27T11:25:44+00:00","dateModified":"2026-08-18T11:30:10+00:00","description":"Learn how FakeGit malware uses 7,600 fake GitHub repositories, AI Skills, and MCP servers to spread SmartLoader and StealC malware.","breadcrumb":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/fakegit-malware-github-repositories-smartloader-stealc\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.hexnode.com\/threat-watch\/fakegit-malware-github-repositories-smartloader-stealc\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.hexnode.com\/threat-watch\/fakegit-malware-github-repositories-smartloader-stealc\/#primaryimage","url":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/FakeGit-Malware-How-7600-Fake-GitHub-Repositories-Spread-SmartLoader-and-StealC.jpeg?format=webp","contentUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/FakeGit-Malware-How-7600-Fake-GitHub-Repositories-Spread-SmartLoader-and-StealC.jpeg?format=webp","width":1340,"height":754,"caption":"FakeGit Malware: How 7600 Fake GitHub Repositories Spread SmartLoader and StealC"},{"@type":"BreadcrumbList","@id":"https:\/\/www.hexnode.com\/threat-watch\/fakegit-malware-github-repositories-smartloader-stealc\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.hexnode.com\/threat-watch\/"},{"@type":"ListItem","position":2,"name":"FakeGit Malware: How 7,600 Fake GitHub Repositories Spread SmartLoader and StealC"}]},{"@type":"WebSite","@id":"https:\/\/www.hexnode.com\/threat-watch\/#website","url":"https:\/\/www.hexnode.com\/threat-watch\/","name":"Hexnode Threat Watch","description":"Latest cyber threats, smarter enterprise response.","publisher":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization"},"alternateName":"Threat Watch","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.hexnode.com\/threat-watch\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization","name":"Hexnode","url":"https:\/\/www.hexnode.com\/threat-watch\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/logo\/image\/","url":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-2.png?format=webp","contentUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-2.png?format=webp","width":100,"height":100,"caption":"Hexnode"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/Hexnode\/","https:\/\/x.com\/thehexnode","https:\/\/www.linkedin.com\/company\/hexnode"]},{"@type":"Person","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/person\/0c83856887182474458e211729d39f9d","name":"Nora Blake","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/a3937eeab99c0b56fb02ea93c3ccf9d03e2a8056395f0c69ce21777a1907569c?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/a3937eeab99c0b56fb02ea93c3ccf9d03e2a8056395f0c69ce21777a1907569c?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/a3937eeab99c0b56fb02ea93c3ccf9d03e2a8056395f0c69ce21777a1907569c?s=96&d=mm&r=g","caption":"Nora Blake"},"url":"https:\/\/www.hexnode.com\/threat-watch\/author\/nora-blake\/"}]}},"_links":{"self":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/719","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/comments?post=719"}],"version-history":[{"count":3,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/719\/revisions"}],"predecessor-version":[{"id":734,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/719\/revisions\/734"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/media\/724"}],"wp:attachment":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/media?parent=719"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/categories?post=719"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}