HackerFeeds

CyberSecurity News

FakeGit Campaign Uses 7,600 GitHub Repositories to Spread SmartLoader Malware

The Hacker News
· July 20, 2026

AI summary

Cybersecurity researchers have found a large number of malicious GitHub repositories, approximately 7,600, that are being used to spread malware. Over 800 of these repositories disguise themselves as artificial intelligence skills or Model Context Protocol servers. They are part of a campaign called FakeGit, which delivers a type of malware known as SmartLoader. The FakeGit campaign uses tactics such as copying projects and creating lookalike developer profiles to appear legitimate. It also includes convincing README files and malicious ZIP files to carry out its malicious activities. The campaign's use of fake repositories and disguised malware highlights the ongoing threat of malicious activity on platforms like GitHub.

Read the full article at The Hacker Newsthehackernews.com/2026/07/fakegit-campaign-uses-7600-github.html

This is an AI-generated brief aggregated by HackerFeeds for convenience and grounded in the source’s own summary; the related CVE, threat-group and country data is from HackerFeeds’ own indexes. The original article is the authoritative source — all rights belong to The Hacker News.

FakeGit Campaign Uses 7,600 GitHub Repositories to Spread SmartLoader Malware — CyberSecurity News | HackerFeeds