CyberSecurity News
FakeGit Campaign Uses 7,600 GitHub Repositories to Spread SmartLoader Malware
AI summary
Cybersecurity researchers have found a large number of malicious GitHub repositories, approximately 7,600, that are being used to spread malware. Over 800 of these repositories disguise themselves as artificial intelligence skills or Model Context Protocol servers. They are part of a campaign called FakeGit, which delivers a type of malware known as SmartLoader. The FakeGit campaign uses tactics such as copying projects and creating lookalike developer profiles to appear legitimate. It also includes convincing README files and malicious ZIP files to carry out its malicious activities. The campaign's use of fake repositories and disguised malware highlights the ongoing threat of malicious activity on platforms like GitHub.
This is an AI-generated brief aggregated by HackerFeeds for convenience and grounded in the source’s own summary; the related CVE, threat-group and country data is from HackerFeeds’ own indexes. The original article is the authoritative source — all rights belong to The Hacker News.

