#10
BleepingComputer
general
October 08, 2026 at 17:10 UTC
FakeGit malware campaign returns with 17,610 malicious GitHub repos
By Bill Toulas
AI Summary
The FakeGit campaign reactivated in October 2026, creating over 17,610 malicious GitHub repositories distributing SmartLoader malware as a dropper for the StealC infostealer. The campaign's industrial-scale abuse of GitHub's trusted platform makes it particularly dangerous for developers who may inadvertently clone or reference the repositories as dependencies.
Relevance score: 72.0/100
Sponsored
Protect Your Business
Expert cybersecurity solutions to safeguard your organization from evolving threats.
Get Protected →