Home ยท Wiki ยท Entities & Threat Actors
type: entity ยท created: 2026-07-21 ยท updated: 2026-07-21 ยท tags: [loader, stealer] ยท confidence: medium ยท affected_sectors: [technology] ยท au_impact: false

SmartLoader โ€” Malware Loader

SmartLoader is a malware loader distributed through the Fakegit Campaign โ€” nearly 7,600 malicious GitHub repositories discovered by Island researchers. It establishes persistence on infected systems and delivers StealC info-stealer as a secondary payload.

Capabilities

  • Initial access: Distributed via fake/piggybacked GitHub repositories
  • Persistence: Establishes persistence mechanisms on infected hosts
  • Secondary payload: Delivers Stealc info-stealer (credential theft, data exfiltration)

Distribution: FakeGit Campaign

SmartLoader was the primary payload of the Fakegit Campaign: - ~7,600 malicious GitHub repositories - Over 800 posing as AI skills or MCP servers - Uses copied projects, lookalike developer profiles, and convincing READMEs

Related Pages

  • Fakegit Campaign โ€” The campaign distributing SmartLoader
  • Stealc โ€” Secondary payload delivered after initial load