type: entity ยท created: 2026-07-21 ยท updated: 2026-07-21 ยท tags: [loader, stealer] ยท confidence: medium ยท affected_sectors: [technology] ยท au_impact: false
SmartLoader โ Malware Loader
SmartLoader is a malware loader distributed through the Fakegit Campaign โ nearly 7,600 malicious GitHub repositories discovered by Island researchers. It establishes persistence on infected systems and delivers StealC info-stealer as a secondary payload.
Capabilities
- Initial access: Distributed via fake/piggybacked GitHub repositories
- Persistence: Establishes persistence mechanisms on infected hosts
- Secondary payload: Delivers Stealc info-stealer (credential theft, data exfiltration)
Distribution: FakeGit Campaign
SmartLoader was the primary payload of the Fakegit Campaign: - ~7,600 malicious GitHub repositories - Over 800 posing as AI skills or MCP servers - Uses copied projects, lookalike developer profiles, and convincing READMEs
Related Pages
- Fakegit Campaign โ The campaign distributing SmartLoader
- Stealc โ Secondary payload delivered after initial load