FakeGit: How Fake GitHub Repos Spread SmartLoader and StealC
FakeGit: How Fake GitHub Repos Spread SmartLoader and StealC
The New Face of Open-Source ThreatsOpen-source platforms have long been trusted by developers and system administrators as reliable sources for code,...
The New Face of Open-Source Threats
Open-source platforms have long been trusted by developers and system administrators as reliable sources for code, libraries, and tools. However, a recent large-scale campaign, dubbed FakeGit, has turned this trust into a weapon. Attackers have flooded GitHub with thousands of deceptive repositories designed to distribute SmartLoader, a malware loader that ultimately delivers the StealC information stealer. This campaign highlights a worrying trend: even AI agents can be tricked into recommending and installing malicious code.

For businesses in Spain, from startups in Barcelona to established firms in Madrid, understanding this threat is crucial. The supply chain is no longer just about compromised dependencies; it now includes seemingly helpful repositories that can compromise your entire infrastructure.
How FakeGit Works: A Closer Look
The FakeGit campaign is notable for its scale and sophistication. Researchers have identified around 7,600 repositories created or repurposed for malicious purposes. The attackers do not simply upload suspicious code; they clone legitimate projects, replicate documentation, and create developer profiles that mimic real identities. The result is a repository with a convincing README that guides visitors to download a ZIP file from GitHub Releases—a channel many teams consider more trustworthy because of its official appearance.
In about 200 of these repositories, the malicious assets have accumulated over 14 million downloads, underscoring the campaign's reach. The infection chain typically starts with a ZIP file that initiates a multi-stage payload, passing through LuaJIT and executing an obfuscated Lua script that installs SmartLoader. Once active, SmartLoader maintains persistence and can deploy secondary payloads, including the StealC infostealer, which exfiltrates sensitive information.
The Rise of AgentBaiting: AI as an Attack Vector
One of the most concerning aspects of FakeGit is its use of AI-related lures. Over 800 repositories are disguised as AI Skills or MCP (Model Context Protocol) servers. This tactic, known as AgentBaiting, exploits the growing reliance on AI agents for development tasks. An attacker does not need to send a direct link; they simply ensure that when an agent searches for a free Skill or an MCP server, it finds and follows instructions that lead to executing malicious code.
Internal tests have shown that AI systems like Anthropic Claude Code, Google Gemini, and OpenAI ChatGPT can return malicious repositories during discovery. For companies deploying AI tools, this adds a new dimension to supply chain security: your AI assistant might inadvertently install malware.
Beyond GitHub: Expanding the Attack Surface
The exposure is not limited to GitHub. These fake Skills and MCP servers have also been listed on public registries such as LobeHub, Glama, MCP.so, and MCP Market. More than 600 listings linked to the campaign have been identified in these directories, broadening the reach and complicating automated discovery hygiene. This means that even if you avoid GitHub, your team might encounter these malicious components through other channels.
Protecting Your Infrastructure: Practical Steps
To mitigate the risk, organizations should adopt a multi-layered approach. Start with the basics: never execute ZIP files, scripts, or installers from unverified repositories, even if the documentation looks impeccable. Establish an internal catalog of approved Skills, MCP servers, and plugins, with clear ownership, and validate any new agent capability in a sandboxed environment before deploying it to production.
On workstations, apply application control to block unauthorized interpreters and scripts, harden Windows policies, and restrict execution from user-writable paths like Downloads or %TEMP%. Additionally, strengthen your EDR with rules focused on LuaJIT execution, loader patterns, and exfiltration signals, and correlate events with downloads from GitHub Releases.
For Windows environments, monitor persistence paths, especially the creation of scheduled tasks from user directories, and review outbound traffic for anomalies, including access to RPC endpoints linked to Polygon or communications with IP-only endpoints, such as POST requests to a bare IP address.
Centralised Protection for Your Servers
For system administrators and hosting companies, managing security across multiple servers can be overwhelming. A centralised solution that aggregates threat intelligence and automates blocking can significantly reduce the risk. By sharing reputation data across all your machines, you can quickly identify and block malicious IPs before they cause harm. This approach not only saves time but also ensures a consistent security posture across your entire infrastructure.
Consider implementing a service that manages fail2ban across multiple servers, automatically updating blocklists based on real-time threat feeds. This way, if one server detects an attack, all others are immediately protected. Such proactive measures are essential in today's threat landscape, where attackers are constantly evolving their tactics.
Training and Awareness: The Human Element
Finally, do not underestimate the importance of training. Developers and those who operate AI agents must understand that the supply chain can break not only in a library but also in a 'useful' repository that someone—or something—installs without a second thought. Regular security awareness sessions can help your team spot red flags, such as unusual download sources or overly eager installation instructions.
In Spain, where GDPR compliance is critical, a breach involving an infostealer like StealC can have legal and financial repercussions beyond the immediate data loss. Protecting your systems is not just about uptime; it is about safeguarding your customers' data and your company's reputation.
Conclusion
The FakeGit campaign is a stark reminder that cyber threats are becoming more sophisticated and more targeted. By understanding how these attacks work and implementing robust security measures, you can significantly reduce your risk. Remember, the goal is not to eliminate all threats—that is impossible—but to make your organisation a harder target. With the right combination of technology, processes, and training, you can stay one step ahead of the attackers.
Related
- Gitea Critical Flaw: Git Hooks Open Door to Server Takeover
- Cisco FMC zero-day exploited: what sysadmins must do now
- Coldcard Flaw: How Weak Seed Entropy Led to a $88M Bitcoin Heist
- Desarrollo web
Put these ideas into practice
Talk to ALMC about a solution for your business. Explore your options or contact our team.
