FakeGit is back: 17,610 malicious GitHub repos in one week
The FakeGit campaign returned with 17,610 malicious GitHub repos pushing SmartLoader, some posing as AI skills and MCP servers. Here is how to vet installs.
The FakeGit malware campaign is back, and it is bigger. Security firm Apiiro says the operation restarted on October 4 and now runs 17,610 malicious GitHub repositories, BleepingComputer reports. It pushed more than 13,000 repos in 34 hours, peaking near 3,000 an hour. The payload is SmartLoader, which installs the StealC infostealer. In its last wave, hundreds of the lures posed as AI skills and MCP servers — the exact things developers are installing fastest right now.
What actually happened
Per BleepingComputer's report on Apiiro's research:
- Restart date: October 4, 2026. Similar activity has run since at least January.
- Scale: 17,610 repos. More than 13,000 pushed in 34 hours, with a peak of 2,999 per hour.
- The lure: a convincing README with a "Download" button to a ZIP. In Apiiro's sample, 88% of repos pointed that button at a ZIP that installs SmartLoader, and 97% of commits touched only the README.
- Accounts: mostly throwaways, but at least 700 look like real developers' accounts.
- Why takedowns fail: 71% of the fleet was missing from the URLhaus blocklist before Apiiro's report. Blocked payloads have spare copies in forks, release assets, and issue attachments, so the operator re-points the link.
The name dates to July, when Island reported about 7,600 FakeGit repos — more than 800 of them posing as AI skills or MCP servers listed in public AI catalogs.
Why it matters for your business
The developer habit this exploits is new: "find an MCP server for X on GitHub, download, run." A year ago that was a weekend project. Now it is how teams connect agents to Stripe, Shopify, and their database. A stealer on that laptop gets the browser sessions, the .env files, and the GitHub token — and through that token, your repos.
And a star count, a clean README, or a real-looking account no longer tells you anything. The attacker owns all three.
What we do, and what we would have you do:
Install agent tools from the source, not from search. Official registries or the vendor's own repo. If Stripe ships an MCP server, it comes from Stripe's GitHub org.
Never run a ZIP from a README. Real projects publish through package managers or signed releases. A download button pointing at an archive is the tell.
If someone ran one, treat GitHub as compromised. Apiiro's guidance: revoke sessions and access tokens, and move to passkeys. Then rotate every secret that laptop could read.
Write down your approved list. Five vetted MCP servers in a shared doc beats every developer searching on their own.
Key takeaways
- FakeGit restarted October 4 with 17,610 malicious GitHub repos, per Apiiro via BleepingComputer
- More than 13,000 repos were pushed in 34 hours; 88% of sampled repos served a SmartLoader ZIP
- SmartLoader delivers the StealC infostealer; earlier waves disguised 800+ repos as AI skills and MCP servers
- At least 700 accounts in the fleet look like real developers, so account reputation is not a safety signal
- Install MCP servers and agent skills only from official registries or vendor repos; if SmartLoader ran, revoke GitHub tokens and rotate secrets
Every MCP server is code with your credentials. We build agent integrations from vetted, pinned sources, with scoped tokens and an approved-tools list your team can actually follow. See how we build agent systems, or send us the list of tools your agents use today.
Sources: BleepingComputer, The Hacker News (July wave).
- #github
- #malware
- #supply-chain
- #mcp
- #smartloader
Tommy Rush — Founder, Rush Commerce
Operator turned builder. 15+ years running operations — now shipping the systems businesses run on. More
Get The Rush Report weekly — one email, zero fluff.
Keep reading
NetScaler CVE-2026-107406: last week's SAML patch isn't enough
Citrix NetScaler CVE-2026-107406 (CVSS 9.5) hits SAML IdP builds up to 14.1-73.41, the fix for last week's KEV bug. Patch to 14.1-73.46 or 13.1-64.29.
Read itHarness buys Augment Code assets: coding agents consolidate
Harness bought Augment Code's Cosmos, Auggie CLI and Context Engine. Coding agent vendors are consolidating. Keep your context and workflow portable.
Read it