FakeGit GitHub lure campaign
Campaign
Summary
Hide ▲
Show ▼
The FakeGit campaign is using nearly 7,600 malicious GitHub repositories to distribute SmartLoader, creating a large-scale lure network that can reach both users and AI agents. More than 800 repositories pose as AI Skills or MCP servers and use convincing setup material to pull victims into the attack chain. The operation's reach and use of trusted developer workflows raise the risk of follow-on payloads such as StealC.
Related Happenings
North Korean Contagious Interview PolinRider supply-chain campaign
Campaign
H score51
First: 04.07.2026 14:17
Last: 04.07.2026 14:17
Sources 1
About this happening:
The Contagious Interview / PolinRider campaign is still active, with 108 unique packages and browser extensions published across npm, Packagist, Go, and Google Chrome....
North Korean Contagious Interview PolinRider supply-chain campaign
CampaignAbout this happening: The Contagious Interview / PolinRider campaign is still active, with 108 unique packages and browser extensions published across npm, Packagist, Go, and Google Chrome....
PolinRider GitHub supply-chain campaign delivering BeaverTail and InvisibleFerret
Campaign
H score9
First: 23.06.2026 11:54
Last: 23.06.2026 11:54
Sources 1
About this happening:
A North Korean supply-chain campaign dubbed PolinRider is injecting obfuscated JavaScript into compromised GitHub repositories, exposing developers to staged malware d...
PolinRider GitHub supply-chain campaign delivering BeaverTail and InvisibleFerret
CampaignAbout this happening: A North Korean supply-chain campaign dubbed PolinRider is injecting obfuscated JavaScript into compromised GitHub repositories, exposing developers to staged malware d...
Rust-based clipboard hijacker spreading via fake crypto tools
Malware Activity
H score13
First: 18.06.2026 18:00
Last: 18.06.2026 18:00
Sources 1
About this happening:
A Rust-based clipboard hijacker is spreading through fake crypto tools and silently replacing copied wallet addresses, putting Windows and macOS users at risk of theft...
Rust-based clipboard hijacker spreading via fake crypto tools
Malware ActivityAbout this happening: A Rust-based clipboard hijacker is spreading through fake crypto tools and silently replacing copied wallet addresses, putting Windows and macOS users at risk of theft...
Ghost Networks crypto-clipper promotion campaign
Campaign
H score15
First: 17.06.2026 21:14
Last: 17.06.2026 21:14
Sources 1
About this happening:
Unknown threat actor is running an active June 2026 campaign that fakes legitimacy to distribute a Rust-based clipboard hijacker. The operation uses bogus GitHub sta...
Ghost Networks crypto-clipper promotion campaign
CampaignAbout this happening: Unknown threat actor is running an active June 2026 campaign that fakes legitimacy to distribute a Rust-based clipboard hijacker. The operation uses bogus GitHub sta...
North Korea-aligned developer-targeting operations shift from fake interviews to recruitment phishing at scale
Threat Actor Meta
H score31
First: 15.06.2026 22:32
Last: 15.06.2026 22:32
Sources 1
About this happening:
North Korea-aligned developer-targeting operations are shifting from fake interviews to recruitment-themed phishing at scale, increasing the risk of industrialized crede...
North Korea-aligned developer-targeting operations shift from fake interviews to recruitment phishing at scale
Threat Actor MetaAbout this happening: North Korea-aligned developer-targeting operations are shifting from fake interviews to recruitment-themed phishing at scale, increasing the risk of industrialized crede...
Timeline
-
20.07.2026 21:23 2 articles · 11h ago
Researchers uncover FakeGit campaign flooding GitHub with malicious AI Skill and MCP server repositories
Initial DisclosureResearchers identified nearly 7,600 malicious GitHub repositories tied to FakeGit, with more than 800 posing as AI Skills or Model Context Protocol (MCP) servers to deliver SmartLoader through copied projects, lookalike developer profiles, convincing READMEs, and malicious ZIP files. The campaign had also recorded more than 14 million downloads across GitHub Release assets in about 200 campaign repositories, and its lure set was built to deceive both users and AI agents into following attacker-controlled installation steps that can lead to SmartLoader and StealC.
Show sources
- FakeGit Campaign Uses 7,600 GitHub Repositories to Spread SmartLoader Malware — thehackernews.com — 20.07.2026 21:23
- FakeGit Campaign Uses 7,600 GitHub Repositories to Spread SmartLoader Malware — thehackernews.com — 20.07.2026 21:23