Malware

CVE: SmartLoader Malware Spread via 7,600 Fake GitHub Repos

July 23, 2026 08:26 · 12 min read
CVE: SmartLoader Malware Spread via 7,600 Fake GitHub Repos

Introduction to the FakeGit Campaign

A large-scale operation known as the FakeGit campaign is utilizing 7,600 malicious GitHub repositories to distribute SmartLoader and StealC malware. These repositories have accumulated over 14 million downloads, according to researchers at the enterprise browser platform Island.

The campaign is considered a continuation of an older operation that used Lumma Stealer and was attributed to a threat actor tracked as “Water Kurita” by researchers at cybersecurity company Trend Micro. The AI focus was introduced in March and peaked in April, with the creation of 300 GitHub repositories linked to AI tools.

AgentBaiting Technique

Researchers at Island have identified the malicious repositories as part of an emerging technique called AgentBaiting. This technique is designed to increase visibility to AI agents and improve the chances of being used. The malicious repositories pretend to be AI skills or MCP servers and appear in public AI registries and catalogs, making them more likely to be discovered by AI agents and developers.

In a typical scenario, agents are likely to parse the README contents as legitimate documentation and recommend the repository or ZIP file to the human operator. Island’s tests showed that ChatGPT, Gemini, and Claude surfaced various malicious repositories when prompted with related tasks, and sometimes relayed the installation instructions.

Malicious Repositories and Their Impact

Many of the repositories imitate consumer and enterprise tools such as Gmail, WhatsApp, Databricks, Jenkins, and Docker, and include convincing documentation, fabricated stars and fork counts, copied project descriptions, and real developer account names. Their README files direct visitors to download ZIP archives that pose as installers or project releases but are disguised Lua payloads that trigger SmartLoader.

Once SmartLoader is active, it establishes persistence through scheduled tasks, retrieves its command-and-control (C2) address through a Polygon smart contract, and downloads additional encrypted stages from GitHub, ultimately delivering the StealC information stealer.

Recommendations and Precautions

Island recommends that organizations maintain approved catalogs of skills and MCP servers, test new capabilities in isolated environments, and verify publishers and repositories independently. Where SmartLoader execution is suspected, all secrets on impacted environments should be rotated immediately.

Oleg Zaytsev, Lead Security Researcher at Island, clarified that the figure of 14 million downloads includes repeated requests and automated activity, so it should not be interpreted as infections. The researchers could not determine if listings were submitted manually or indexed automatically, but said their presence made the repositories easier to discover and added to their credibility.

Conclusion

The FakeGit campaign highlights the importance of being cautious when using AI agents and repositories. By using the AgentBaiting technique, the attackers were able to increase their visibility and improve the chances of being used. It is essential for organizations to take precautions and maintain approved catalogs of skills and MCP servers to prevent such attacks.

The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection. Get the whitepaper to learn more about how to protect your organization from such attacks.


Source: BleepingComputer

Source: BleepingComputer

Powered by ZeroBot

Protect your website from bots, scrapers, and automated threats.

Try ZeroBot Free