Home ยท Wiki ยท Incidents & Campaigns
type: incident ยท created: 2026-07-21 ยท updated: 2026-07-21 ยท tags: [campaign, supply-chain, loader, stealer] ยท confidence: high ยท affected_sectors: [technology, education] ยท au_impact: true

FakeGit Campaign โ€” GitHub Repository Malware Distribution

The FakeGit campaign is a large-scale malware distribution operation using nearly 7,600 malicious GitHub repositories to deliver the Smartloader malware. Discovered and reported by Island researchers in July 2026.

Campaign Details

Attribute Detail
Scale ~7,600 malicious repositories
Lures 800+ repos posing as AI skills or MCP servers
Technique Copied projects, lookalike developer profiles, convincing READMEs
Primary Payload Smartloader
Secondary Payload StealC info-stealer
Discovered by Island researchers
Date reported 2026-07-20

Technique

The campaign operators: 1. Copy legitimate projects to create plausible repositories 2. Create lookalike developer profiles to establish credibility 3. Write convincing READMEs to appear as useful tools 4. Bury malicious code within otherwise functional projects 5. Use AI-themed lures (AI skills, MCP servers) to attract developers

Distribution Scale

With ~7,600 repositories, this is one of the largest known supply-chain attacks via GitHub. The volume suggests automated or semi-automated repository creation pipelines.

Australian Significance

Australian developers and organisations using GitHub for AI/ML projects or MCP server deployments are at elevated risk. The use of AI skills and MCP server lures is particularly relevant given the growing adoption of AI coding assistants and MCP-based tooling in the Australian tech sector.

Related Pages

  • Smartloader โ€” The primary malware payload
  • Stealc โ€” Secondary info-stealer payload
  • Mcp Tool Poisoning โ€” Related MCP-based supply chain threat