Find notable cyber news and cases, enriched with sources, timelines, and signals.

FakeGit GitHub lure campaign

Campaign
First reported
Last updated
Happening score
H score 30
1 unique sources, 1 articles

Summary

Hide ▲

The FakeGit campaign is using nearly 7,600 malicious GitHub repositories to distribute SmartLoader, creating a large-scale lure network that can reach both users and AI agents. More than 800 repositories pose as AI Skills or MCP servers and use convincing setup material to pull victims into the attack chain. The operation's reach and use of trusted developer workflows raise the risk of follow-on payloads such as StealC.

Related Happenings

North Korean Contagious Interview PolinRider supply-chain campaign

Campaign
H score51 First: 04.07.2026 14:17 Last: 04.07.2026 14:17 Sources 1

About this happening: The Contagious Interview / PolinRider campaign is still active, with 108 unique packages and browser extensions published across npm, Packagist, Go, and Google Chrome....

PolinRider GitHub supply-chain campaign delivering BeaverTail and InvisibleFerret

Campaign
H score9 First: 23.06.2026 11:54 Last: 23.06.2026 11:54 Sources 1

About this happening: A North Korean supply-chain campaign dubbed PolinRider is injecting obfuscated JavaScript into compromised GitHub repositories, exposing developers to staged malware d...

Rust-based clipboard hijacker spreading via fake crypto tools

Malware Activity
H score13 First: 18.06.2026 18:00 Last: 18.06.2026 18:00 Sources 1

About this happening: A Rust-based clipboard hijacker is spreading through fake crypto tools and silently replacing copied wallet addresses, putting Windows and macOS users at risk of theft...

Ghost Networks crypto-clipper promotion campaign

Campaign
H score15 First: 17.06.2026 21:14 Last: 17.06.2026 21:14 Sources 1

About this happening: Unknown threat actor is running an active June 2026 campaign that fakes legitimacy to distribute a Rust-based clipboard hijacker. The operation uses bogus GitHub sta...

North Korea-aligned developer-targeting operations shift from fake interviews to recruitment phishing at scale

Threat Actor Meta
H score31 First: 15.06.2026 22:32 Last: 15.06.2026 22:32 Sources 1

About this happening: North Korea-aligned developer-targeting operations are shifting from fake interviews to recruitment-themed phishing at scale, increasing the risk of industrialized crede...

Timeline

  1. 20.07.2026 21:23 2 articles · 11h ago

    Researchers uncover FakeGit campaign flooding GitHub with malicious AI Skill and MCP server repositories

    Initial Disclosure

    Researchers identified nearly 7,600 malicious GitHub repositories tied to FakeGit, with more than 800 posing as AI Skills or Model Context Protocol (MCP) servers to deliver SmartLoader through copied projects, lookalike developer profiles, convincing READMEs, and malicious ZIP files. The campaign had also recorded more than 14 million downloads across GitHub Release assets in about 200 campaign repositories, and its lure set was built to deceive both users and AI agents into following attacker-controlled installation steps that can lead to SmartLoader and StealC.

    Show sources