ALMC
ALMC Security Logo - Mantenimiento Web, Programación Web Barcelona, Servidores Barcelona, Ciberseguridad Barcelona
  • English
    Español English Français Català

Quick search

Results without leaving the page.

Type to search ALMC products, services, articles and tools.

View all results
Habla a nuestro AgenteIA · respuestas al instante · 24/7
  • HomeALMC
  • ALMCAbout Us
  • ALMC SECURITY S.L.U.Contact
  • Posts
    • Posts
    • Categorías
    • Etiquetas
    • Estados
  • Soluciones
    • Desarrollo Web en Lleida — Diseño a Medida que Vende
    • Tienda Online a Medida — E-commerce que Vende de Verdad
    • Chatbot IA para Empresas — Automatiza tu Atención al Cliente
    • Automatización de Procesos para Empresas — Menos Tareas, Más Resultados
    • Desarrollo de Apps Móviles — iOS y Android a Medida
  • Services
    • Cybersecurity
      • Security Audits and Pentesting
      • Monitoring & Incident Response (SIEM)
      • System & Server Hardening
      • Compliance Consulting (GDPR, ENS, ISO 27001)
      • Cloud Security (AWS, Azure, Google Cloud)
    • Programming
      • Full Stack Web Development Laravel, Vue.js
      • Process Automation (Scripts and Bots)
      • Process Automation Scripts and Bots
      • API Integrations & Microservices
      • Code Maintenance and Optimization
    • Servers
      • Server Management & Monitoring
      • Cloud Migration (AWS, Azure, Google Cloud)
      • Performance Optimization
      • Virtualization & Containers (Docker, Kubernetes)
      • Backup & Disaster Recovery Plans
    • Malware Removal
    • Website Maintenance
      • WordPress Maintenance
      • PrestaShop Maintenance
      • Magento Maintenance
      • Joomla Maintenance
      • Drupal Maintenance
      • Shopify Maintenance
      • Wix Maintenance
      • Concrete5 Maintenance
      • HTML Maintenance
      • PHP Maintenance
      • JavaScript Maintenance
      • Python Maintenance
    • Website Repair
      • Hacked site cleanup
      • Fix WordPress
      • Fix PrestaShop
      • Fix Magento
      • Fix Joomla
      • Fix Drupal
      • Fix Shopify
      • Fix OpenCart
      • Fix Moodle
  • Industries
    • 3D Printing & Additive
    • Accounting
    • Advertising & Marketing
    • Aerospace & Defense
    • Agriculture
    • Architecture & Engineering
    • Arts & Culture
    • Automotive
    • Banking & Finance
    • Biomedical Research
    • Biotechnology
    • Breweries
    • Call Centers & BPO
    • Chemicals
    • Cleaning Services
    • Clinics
    • Cloud Providers
    • Construction
    • Consulting
    • Cosmetics & Beauty
    • Courier & Last Mile
    • Cybersecurity
    • Data Centers
    • Defense & Security
    • E-Commerce
    • EdTech
    • Education (K-12)
    • Electrical Equipment
    • Electronics
    • Environmental NGOs
    • Environmental Services
    • Events & Conferences
    • Facilities Management
    • Fashion & Luxury
    • FinTech
    • Fishing & Aquaculture
    • Food & Beverage Manufacturing
    • Forestry
    • Freight Transport
    • Furniture
    • Gaming
    • Government & Public Administration
    • GovTech
    • Gyms & Fitness Centers
    • Healthcare Providers
    • HealthTech
    • Higher Education
    • Home Appliances
    • Home Services
    • Hospitality
    • Hospitals
    • Human Resources
    • Insurance
    • InsurTech
    • Internet & Web Services
    • Investment & Asset Management
    • IT Services
    • Jewelry
    • Landscaping & Gardening
    • Legal Services
    • Logistics & Supply Chain
    • Machinery
    • Maritime
    • Media & Entertainment
    • Medical Devices
    • Metals
    • Mining
    • Music Industry
    • Nonprofit & NGOs
    • Oil & Gas
    • Paper & Print Media
    • Paper & Pulp
    • Pharmaceuticals
    • Photography & Video
    • Plastics
    • Postal & Courier
    • Printing
    • Private Education & Academies
    • Property Development
    • Property Management
    • PropTech
    • Public Safety & Emergency
    • Publishing
    • Rail & Public Transport
    • Real Estate
    • Real Estate Agencies
    • Religious Organizations
    • Renewable Energy
    • Research & Development
    • Research Labs
    • Restaurants & Food Service
    • Retail
    • Security Services
    • Semiconductors
    • Software Development
    • Sports & Fitness
    • Sports Clubs
    • Staffing & Recruitment
    • Telecommunications
    • Textile & Apparel
    • Tobacco
    • Toys
    • Travel & Tourism
    • Travel Agencies
    • Utilities
    • Veterinary & Animal Care
    • Warehousing
    • Waste Management
    • Water Treatment
    • Wholesale
    • Wineries & Vineyards
  • Tools
    • Network
      • What's my IP
      • WHOIS IP
      • Domain WHOIS
      • Geolocate IP
      • DNS Lookup
      • DNS Propagation
      • ASN Lookup
      • Reverse Lookup
      • Domain monitoring
    • Image Compressor
    • MCP Servers
  • Products
    • Whatsboost
      • Whatsboost PrestaShop
      • Whatsboost WordPress
      • Whatsboost Shopify
    • Ulix
      • Extension QR para navegador
    • Chatbot
      • Chatbot WhatsApp
      • Chatbot Instagram
      • Chatbot Facebook
      • Chatbot TikTok
    • VeriFactu
    • Web TV
      • Mis pantallas
      • Vincular nueva TV
      • Dispositivos vinculados
      • Releases APK
      • Pantallas por cliente
    • Control de Fichajes

5 News at ALMC
  • Inauguration of the... Web Maintenance, Web Development Barcelona, Servers Barcelona, Cybersecurity Barcelona
    Inauguration of the...It was a very busy and special day. 30 Jun 2025
  • Website Web Maintenance, Web Development Barcelona, Servers Barcelona, Cybersecurity Barcelona
    WebsiteI recover the domain I had in the past and set up... 01 Jun 2025
  • Signing of the Lease... Web Maintenance, Web Development Barcelona, Servers Barcelona, Cybersecurity Barcelona
    Signing of the Lease...After spending some time looking for premises, my... 01 Jun 2025
  • ALMC returns and com... Web Maintenance, Web Development Barcelona, Servers Barcelona, Cybersecurity Barcelona
    ALMC returns and com...We reactivate the brand with ALMC SECURITY SL (CIF... 23 Apr 2025
  • feb. 2025 Web Maintenance, Web Development Barcelona, Servers Barcelona, Cybersecurity Barcelona
    feb. 2025The decision to start entrepreneurship again was b... 01 Feb 2025

View all news

FakeGit: How Fake GitHub Repos Spread SmartLoader and StealC

  1. Home
  2. Blog
  3. Categories
  4. Cybersecurity
  5. FakeGit: How Fake GitHub Repos Spread SmartLo...
  • All articles
  • Categories
  • Tags
  • Statuses

FakeGit: How Fake GitHub Repos Spread SmartLoader and StealC

The New Face of Open-Source ThreatsOpen-source platforms have long been trusted by developers and system administrators as reliable sources for code,...

The New Face of Open-Source Threats

Open-source platforms have long been trusted by developers and system administrators as reliable sources for code, libraries, and tools. However, a recent large-scale campaign, dubbed FakeGit, has turned this trust into a weapon. Attackers have flooded GitHub with thousands of deceptive repositories designed to distribute SmartLoader, a malware loader that ultimately delivers the StealC information stealer. This campaign highlights a worrying trend: even AI agents can be tricked into recommending and installing malicious code.

Illustration of a malicious fake code repository download in a server room

For businesses in Spain, from startups in Barcelona to established firms in Madrid, understanding this threat is crucial. The supply chain is no longer just about compromised dependencies; it now includes seemingly helpful repositories that can compromise your entire infrastructure.

How FakeGit Works: A Closer Look

The FakeGit campaign is notable for its scale and sophistication. Researchers have identified around 7,600 repositories created or repurposed for malicious purposes. The attackers do not simply upload suspicious code; they clone legitimate projects, replicate documentation, and create developer profiles that mimic real identities. The result is a repository with a convincing README that guides visitors to download a ZIP file from GitHub Releases—a channel many teams consider more trustworthy because of its official appearance.

In about 200 of these repositories, the malicious assets have accumulated over 14 million downloads, underscoring the campaign's reach. The infection chain typically starts with a ZIP file that initiates a multi-stage payload, passing through LuaJIT and executing an obfuscated Lua script that installs SmartLoader. Once active, SmartLoader maintains persistence and can deploy secondary payloads, including the StealC infostealer, which exfiltrates sensitive information.

The Rise of AgentBaiting: AI as an Attack Vector

One of the most concerning aspects of FakeGit is its use of AI-related lures. Over 800 repositories are disguised as AI Skills or MCP (Model Context Protocol) servers. This tactic, known as AgentBaiting, exploits the growing reliance on AI agents for development tasks. An attacker does not need to send a direct link; they simply ensure that when an agent searches for a free Skill or an MCP server, it finds and follows instructions that lead to executing malicious code.

Internal tests have shown that AI systems like Anthropic Claude Code, Google Gemini, and OpenAI ChatGPT can return malicious repositories during discovery. For companies deploying AI tools, this adds a new dimension to supply chain security: your AI assistant might inadvertently install malware.

Beyond GitHub: Expanding the Attack Surface

The exposure is not limited to GitHub. These fake Skills and MCP servers have also been listed on public registries such as LobeHub, Glama, MCP.so, and MCP Market. More than 600 listings linked to the campaign have been identified in these directories, broadening the reach and complicating automated discovery hygiene. This means that even if you avoid GitHub, your team might encounter these malicious components through other channels.

Protecting Your Infrastructure: Practical Steps

To mitigate the risk, organizations should adopt a multi-layered approach. Start with the basics: never execute ZIP files, scripts, or installers from unverified repositories, even if the documentation looks impeccable. Establish an internal catalog of approved Skills, MCP servers, and plugins, with clear ownership, and validate any new agent capability in a sandboxed environment before deploying it to production.

On workstations, apply application control to block unauthorized interpreters and scripts, harden Windows policies, and restrict execution from user-writable paths like Downloads or %TEMP%. Additionally, strengthen your EDR with rules focused on LuaJIT execution, loader patterns, and exfiltration signals, and correlate events with downloads from GitHub Releases.

For Windows environments, monitor persistence paths, especially the creation of scheduled tasks from user directories, and review outbound traffic for anomalies, including access to RPC endpoints linked to Polygon or communications with IP-only endpoints, such as POST requests to a bare IP address.

Centralised Protection for Your Servers

For system administrators and hosting companies, managing security across multiple servers can be overwhelming. A centralised solution that aggregates threat intelligence and automates blocking can significantly reduce the risk. By sharing reputation data across all your machines, you can quickly identify and block malicious IPs before they cause harm. This approach not only saves time but also ensures a consistent security posture across your entire infrastructure.

Consider implementing a service that manages fail2ban across multiple servers, automatically updating blocklists based on real-time threat feeds. This way, if one server detects an attack, all others are immediately protected. Such proactive measures are essential in today's threat landscape, where attackers are constantly evolving their tactics.

Training and Awareness: The Human Element

Finally, do not underestimate the importance of training. Developers and those who operate AI agents must understand that the supply chain can break not only in a library but also in a 'useful' repository that someone—or something—installs without a second thought. Regular security awareness sessions can help your team spot red flags, such as unusual download sources or overly eager installation instructions.

In Spain, where GDPR compliance is critical, a breach involving an infostealer like StealC can have legal and financial repercussions beyond the immediate data loss. Protecting your systems is not just about uptime; it is about safeguarding your customers' data and your company's reputation.

Conclusion

The FakeGit campaign is a stark reminder that cyber threats are becoming more sophisticated and more targeted. By understanding how these attacks work and implementing robust security measures, you can significantly reduce your risk. Remember, the goal is not to eliminate all threats—that is impossible—but to make your organisation a harder target. With the right combination of technology, processes, and training, you can stay one step ahead of the attackers.

Related

  • Gitea Critical Flaw: Git Hooks Open Door to Server Takeover
  • Cisco FMC zero-day exploited: what sysadmins must do now
  • Coldcard Flaw: How Weak Seed Entropy Led to a $88M Bitcoin Heist
  • Desarrollo web

Put these ideas into practice

Talk to ALMC about a solution for your business. Explore your options or contact our team.

Soluciones ALMC

Process Automation (Scripts and Bots)
Virtualization & Containers (Docker, Kubernetes)
Security Audits and Pentesting
Compliance Consulting (GDPR, ENS, ISO 27001)
Cloud Security (AWS, Azure, Google Cloud)
Relacionados
  • Critical LoadMaster RCE: What Sysadmins Must Do Now
    Cybersecurity · 57 minutes ago
  • CISA Warns: Actively Exploited SharePoint RCE Vulnerability
    Cybersecurity · 57 minutes ago
  • Opera GX Patch: Guarding Against Malicious Browser Mods
    Cybersecurity · 57 minutes ago
  • Azure CLI Password Spraying: Lessons for Server Security
    Cybersecurity · 57 minutes ago
  • SonicWall SMA1000 Zero-Days: Urgent Patch Guidance for SysAdmins
    Cybersecurity · 1 hour ago
  • UEFI Secure Boot Bypass: Why Old Shims Threaten Your Servers
    Cybersecurity · 1 hour ago
Servidores MCP Destacados
  • PayPal
    Cloud Service
  • NeoCoder
    Development
  • Plex
    Other
  • Textin MCP Server
    Development
  • Appcircle MCP Server
    Cloud Service
  • SearchAPI Agent
    Search
  • uMCP (ultraMCP)
    Development
  • Hostinger
    Cloud Service
  • PostgreSQL
    Database
Ver todos los servidores MCP
Cybersecurity · Blog Brain · 2026-09-08
Cerrar panel
Your ecosystem

SaaS applications

Open each workspace directly with your ALMC account.

My account Create account
VeriFactuVerified invoicingAbuse ShieldWeb securityWhatsBoostSales and CRMCommerceStore and POSEmail AISmart emailWebTVDigital signageTime trackingWorking-time controlPrintFlowPrint workflows
Agente Smith · ALMCAgente IA propio on-premise

Hola 👋 Soy Smith, el agente IA de ALMC. Pregúntame sobre ciberseguridad, IA, desarrollo a medida o nuestros productos SaaS.

¿Prefieres hablar con persona? Contacto humano

ALMC access centre

One account · All your services

Start wherever you want.

Create an account to centralise your services, or ask for guidance if you do not know what you need yet.

Create account Talk to ALMC

Explore by product

VeriFactuInvoicingAbuse ShieldSecurityWhatsBoostSalesCommerceStore and POSEmail AIAutomationWebTVDigital signage

Sign in to your account.

The same sign-in brings together your services, team and billing.

Enter my panelAccess your services, team and billing.
Sign in

Not a client yet? Create an account

ALMC Security Logo

Experts in cybersecurity, custom Laravel development, and server management. We deliver robust, secure, and personalized technological solutions.

Latest News

Inauguration of the first office in Lleida of ALMC SECURITY SL
Inauguration of the first office in Lleida of ALMC...
30 Jun 2025
Website
01 Jun 2025
Signing of the Lease Contract
Signing of the Lease Contract
01 Jun 2025

Main Services

  • desarrollo web lleida
  • tienda online a medida
  • chatbot ia empresa
  • automatización procesos empresa
  • desarrollo aplicaciones móviles

Suite SaaS

  • PrintFlow (copisterías)
  • WebTV (cartelería)
  • VeriFactu (facturación)
  • Fichaje horario

Contact

  • Rambla de Ferran, 37, 25007 Lleida

  • +34 614 443 757

  • info@almc.es

Follow Us

Useful links

  • About us
  • Contact
  • Reserva cita
  • Hacked website repair
  • Website maintenance
  • Website repair
  • Tools
  • What is my IP
  • Compress images
  • Site search
  • Blog

© Copyright 2026. ALMC SECURITY S.L.U.

  • Legal
      • Privacy Policy
      • Terms and Conditions of Service
      • Legal Notice and Corporate Information
      • Cookie Policy
  • Resources
    • Blog
    • Sitemap

ALMC

Legal

This site only uses first-party cookies and local browser storage, and only to make it work: keeping your session, protecting forms, remembering your language and not showing you this notice again. We use no analytics or advertising cookies, there are no third-party cookies and we do not build profiles. As strictly necessary technical cookies, they are exempt from consent under Article 22.2 of the Spanish LSSI-CE: this notice is informative and the button only stops it from appearing again. You can delete or block them from your browser, though some features may then stop working. Cookie Policy · Privacy Policy.

Chat now
Call Sales
+34 614 443 757

More ways to contact us

¿Hablamos directamente?

Reserva una cita en mi agenda — yo te llamo o nos vemos por Google Meet

  • ✓Confirmación instantánea por WhatsApp
  • ✓Disponibilidad en tiempo real
  • ✓Recordatorio 1h antes
  • ✓Cancela o cambia hora con un click
Initial consultation · 30min
📅 Ver disponibilidad y reservar