FakeGit Campaign โ GitHub Repository Malware Distribution
The FakeGit campaign is a large-scale malware distribution operation using nearly 7,600 malicious GitHub repositories to deliver the Smartloader malware. Discovered and reported by Island researchers in July 2026.
Campaign Details
| Attribute | Detail |
|---|---|
| Scale | ~7,600 malicious repositories |
| Lures | 800+ repos posing as AI skills or MCP servers |
| Technique | Copied projects, lookalike developer profiles, convincing READMEs |
| Primary Payload | Smartloader |
| Secondary Payload | StealC info-stealer |
| Discovered by | Island researchers |
| Date reported | 2026-07-20 |
Technique
The campaign operators: 1. Copy legitimate projects to create plausible repositories 2. Create lookalike developer profiles to establish credibility 3. Write convincing READMEs to appear as useful tools 4. Bury malicious code within otherwise functional projects 5. Use AI-themed lures (AI skills, MCP servers) to attract developers
Distribution Scale
With ~7,600 repositories, this is one of the largest known supply-chain attacks via GitHub. The volume suggests automated or semi-automated repository creation pipelines.
Australian Significance
Australian developers and organisations using GitHub for AI/ML projects or MCP server deployments are at elevated risk. The use of AI skills and MCP server lures is particularly relevant given the growing adoption of AI coding assistants and MCP-based tooling in the Australian tech sector.
Related Pages
- Smartloader โ The primary malware payload
- Stealc โ Secondary info-stealer payload
- Mcp Tool Poisoning โ Related MCP-based supply chain threat