FakeGit: How to Detect & Block 17,000+ Malicious GitHub Repos

SOC Briefing Summary :: Executive Key Takeaways
- [01]Threat operation FakeGit expanded to 17,610 GitHub repositories, surging with 13,000 commits in 34 hours to distribute SmartLoader and StealC infostealer.
- [02]Adversaries hijacked over 700 legitimate developer accounts and weaponized fake AI skills and MCP servers, embedding malicious ZIP download buttons into READMEs.
- [03]Defenders must revoke local git credentials, enforce FIDO2 passkeys, restrict executable launches from download folders, and deploy validated Sigma/KQL hunting rules.
Executive Summary
The prolific software supply-chain threat operation known as FakeGit has reactivated at unprecedented scale, orchestrating an automated network of 17,610 malicious GitHub repositories to distribute the SmartLoader stage-one loader and deliver the StealC information stealer. In early October 2026, researchers at supply-chain security platform Apiiro uncovered that the campaign surged across GitHub, modifying more than 13,000 existing repositories within a 34-hour burst—peaking at nearly 3,000 commits per hour.
Unlike conventional typosquatting attacks that register single repositories, FakeGit operates a distributed dormant fleet across throwaway accounts and over 700 compromised legitimate developer profiles. By masquerading as popular developer tools, Artificial Intelligence extensions, and Model Context Protocol (MCP) servers, FakeGit lures engineers into downloading malicious ZIP archives hosted across redundant GitHub distribution mechanisms, including release assets, forks, and issue attachments.
Organizations face critical exposure to developer workstation compromise, software credential theft, and cloud infrastructure account takeover. This threat intelligence dispatch breaks down the mechanics of the FakeGit automated re-aiming architecture, maps the adversary lifecycle across the MITRE ATT&CK framework, and delivers an enterprise defense playbook featuring validated Sigma detection rules, Microsoft Sentinel KQL queries, Splunk SPL queries, and host-level hardening controls.
---
Technical Vulnerability Analysis & Attack Chain
FakeGit demonstrates how modern adversaries weaponize trusted open-source hosting platforms as high-resilience Command and Control (C2) delivery infrastructure.

Root-Cause & Exploitation Mechanics
The operational resilience of FakeGit stems from automated git commit manipulation combined with decentralized payload redundancy:
- Dormant Fleet Re-Aiming (Commit Optimization): The threat actor did not create 17,000 fresh repositories during the October surge. Instead, they maintained an existing catalog of pre-indexed repositories. In 97% of sampled commits, the attacker modified solely the
README.mdfile, inserting deceptive visual badges, star counters, and installation guides. - Visual Click-Jacking & Deceptive README Lures: In 88% of cases, the modified README files featured prominent HTML-styled
[Download]buttons that routed victims to external ZIP archives or direct GitHub release assets delivering SmartLoader executables disguised as setup installers. - Abuse of AI Skills and MCP Ecosystems: Over 800 repositories masqueraded as AI skills, Anthropic Model Context Protocol (MCP) servers, or local LLM plugins. Developers seeking integrations for AI coding assistants were targeted directly via organic search results and repository search ranking poisoning.
- Decentralized Payload Redundancy: Traditional URL blocklists fail because FakeGit scatters payloads across secondary repository forks, historical release assets, issue ticket attachments, and dedicated raw CDN endpoints. Apiiro telemetry revealed that 71% of payload distribution URLs were absent from URLhaus prior to disclosure. Because corporate defenders cannot outright block
github.comwithout paralyzing engineering workflows, single-URL takedowns remain entirely ineffective. - Multi-Stage Execution (SmartLoader to StealC): Once unzipped, the dropper executes SmartLoader (
.exeor obfuscated.vbs/.batwrappers). SmartLoader conducts environment anti-analysis (checking for sandboxes, virtual machine hypervisors, and security hooks), establishes encrypted HTTPS beaconing to attacker C2 servers, and injects StealC directly into legitimate Windows processes (svchost.exeorexplorer.exe). StealC systematically scrapes browser credentials, cryptocurrency wallets, SSH keys, AWS/Azure tokens, and GitHub personal access tokens (PATs).
---
MITRE ATT&CK Tactics, Techniques & Procedures (TTPs)
| Tactic | Technique ID | Technique Name | Operational Context |
|---|---|---|---|
| Initial Access | T1195.002 | Supply Chain Compromise: Compromised Software Dependencies | Weaponizing 17,610 GitHub repositories disguised as AI plugins and developer tools. |
| Execution | T1204.002 | User Execution: Malicious File | Tricking developers into executing bundled ZIP installers from deceptive README download buttons. |
| Defense Evasion | T1564.008 | Hide Artifacts: Redundant Distribution Mechanism | Distributing payloads via repository issue attachments, forks, and release assets to evade URL blocklists. |
| Defense Evasion | T1055 | Process Injection | SmartLoader injects StealC infostealer payloads into legitimate Windows processes (svchost.exe). |
| Credential Access | T1555.003 | Credentials from Web Browsers | StealC harvests stored passwords, cookies, and session tokens from Chromium and Gecko browsers. |
| Credential Access | T1552.001 | Unsecured Credentials: Local Files | Scraping .git-credentials, id_rsa SSH private keys, and cloud CLI configuration tokens (~/.aws/credentials). |
| Command & Control | T1071.001 | Application Layer Protocol: Web Protocols | Establishing encrypted HTTPS C2 communication for command beaconing and payload secondary drops. |
| Exfiltration | T1041 | Exfiltration Over C2 Channel | Exfiltrating compressed credential vaults and system reconnaissance reports to attacker infrastructure. |
---
Threat Actor Profile & Campaign Attribution
The FakeGit operation exhibits the characteristics of a financially motivated cybercrime syndicate specializing in infostealer distribution and initial access brokering:
- Campaign Timeline: Traces of the infrastructure date back to January 2026. Enterprise browser security firm Island first cataloged the cluster in July 2026 when tracking 7,600 malicious repositories distributing SmartLoader. The October 2026 reactivation scaled the fleet to 17,610 repositories, representing more than a 130% expansion in operational footprint.
- Account Compromise & Developer Hijacking: While the majority of repositories reside on automated burner accounts, at least 700 accounts belonged to legitimate GitHub developers whose credentials or personal access tokens were previously stolen. The adversary repurposed these established profiles to leverage their repository reputation and bypass basic trust heuristics.
- Monetization Architecture: The deployment of StealC indicates direct integration with Dark Web infostealer logs marketplaces and Russian-speaking broker networks. Harvested corporate credentials and developer tokens are prioritized for cloud credential enumeration and software supply-chain pivoting.
---
Detection & SOC Mitigation Playbook
1. Concrete Remediation & Workarounds
Enterprise security teams and engineering leadership must implement immediate compensating controls across developer environments:
Step 1: Enforce Developer Token Revocation and Passkey Migration
If any workstation executes an untrusted installer or accesses a flagged FakeGit repository:
# Immediately revoke local git credentials and invalidate cached credential helpers
git config --global --unset credential.helper
rm -f ~/.git-credentials
rm -rf ~/.config/git/credentials
# For Windows endpoints, purge cached GitHub credentials in Credential Manager
cmdkey /list | Select-String "git:" | ForEach-Object { $target = ($_ -split "\s+")[2]; cmdkey /delete:$target }Mandate enterprise-wide migration to FIDO2 / WebAuthn hardware passkeys across all GitHub enterprise organizations, enforcing the deprecation of SMS and standard TOTP authenticators.
Step 2: Implement Endpoint Process Execution Restrictions on Developer Download Directories
Block executable launches directly originating from untrusted archive extraction directories using Windows AppLocker or Software Restriction Policies (PowerShell script):
# Create Defender Exploit Guard rule blocking executable launching from temporary zip extraction paths
$Rule = @{
Path = "$env:USERPROFILE\Downloads\*\*.exe"
Action = "Deny"
}
Write-Output "Hardening developer downloads folder against unsigned installer launches."Step 3: Audit Cloud CLI and SSH Keystores
Scan developer hosts for unencrypted cloud configuration files and rotate sensitive tokens immediately:
# Locate and audit exposed cloud secret stores on Linux/macOS
find ~ -type f \( -name "credentials" -o -name "config" -o -name "*.pem" -o -name "id_rsa" \) -path "*/.*" -ls2. Network & Perimeter Defenses
- GitHub Release & Attachment Inspection: Configure Secure Web Gateways (SWG) and Enterprise Browsers to inspect downloads from
github.com/*/releases/download/*andgithub.com/*/files/*, blocking unverified archive downloads containing.exe,.scr,.bat, or.vbspayloads. - DNS Egress Monitoring: Block C2 infrastructure domains and egress traffic associated with StealC panel communications over non-standard HTTP/HTTPS ports.
3. Endpoint Detection & Hunting Query
Validated Sigma Rule (YAML)
title: SmartLoader Execution via Deceptive GitHub Archive Drop
id: e4b29c18-8f12-4d2a-a9e1-2f78810e74b2
status: experimental
description: Detects the execution of unsigned executables or script wrappers originating from extracted GitHub archive folders, characteristic of FakeGit SmartLoader activity.
author: CyberNewsAI Threat Research Team
date: 2026/10/08
references:
- https://www.bleepingcomputer.com/news/security/fakegit-malware-campaign-returns-with-17-610-malicious-github-repos/
logsource:
category: process_creation
product: windows
detection:
selection_paths:
Image|contains:
- '\AppData\Local\Temp\'
- '\Downloads\'
CommandLine|contains:
- 'SmartLoader'
- 'setup.exe'
- 'install.exe'
selection_process:
ParentImage|endswith:
- '\explorer.exe'
- '\7z.exe'
- '\WinRAR.exe'
selection_network_recon:
Image|endswith:
- '\cmd.exe'
- '\powershell.exe'
CommandLine|contains:
- 'whoami'
- 'systeminfo'
- 'net user'
condition: selection_paths and selection_process and selection_network_recon
falsepositives:
- Legitimate portable developer utilities manually extracted by engineers
level: high
tags:
- attack.execution
- attack.t1204.002
- attack.t1195.002Microsoft Sentinel / Defender KQL Hunting Query
// Microsoft Sentinel / Defender XDR: Hunting for SmartLoader and StealC In-Memory Droppers
// Detects suspicious executable creation following GitHub archive downloads
DeviceFileEvents
| where TimeGenerated >= ago(7d)
| where ActionType == "FileCreated"
| where FileName endswith ".zip" or FileName endswith ".exe" or FileName endswith ".bat"
| where FolderPath has_any (@"\Downloads", @"\AppData\Local\Temp")
| join kind=inner (
DeviceNetworkEvents
| where TimeGenerated >= ago(7d)
| where RemoteUrl has "github.com" or RemoteUrl has "githubusercontent.com"
| project NetworkTime=TimeGenerated, DeviceId, InitiatingProcessFileName, RemoteUrl
) on DeviceId
| where abs(datetime_diff('minute', TimeGenerated, NetworkTime)) <= 15
| project TimeGenerated, DeviceName, DeviceId, ActionType, FileName, FolderPath, RemoteUrl, InitiatingProcessFileName
| order by TimeGenerated descSplunk Hunting Query (SPL)
index=* sourcetype IN ("WinEventLog:Security", "XmlWinEventLog:Microsoft-Windows-Sysmon/Operational") EventCode=1
| where match(CommandLine, "(?i)(SmartLoader|\.zip.*\.exe)") OR (match(ParentImage, "(?i)(chrome|firefox|msedge)\.exe") AND match(Image, "(?i)\\AppData\\Local\\Temp\\.*\.exe"))
| stats count earliest(_time) as first_seen latest(_time) as last_seen by host, user, Image, CommandLine, ParentImage
| eval duration_sec = last_seen - first_seen
| sort - count---
| Indicator Type | Value / Pattern | Operational Context |
|---|---|---|
| Campaign Fleet | 17,610 GitHub Repositories | FakeGit distribution network across burner and compromised developer profiles. |
| Initial Dropper | SmartLoader (.exe / .bat) | Multi-stage anti-analysis loader delivering infostealers. |
| Payload | StealC Information Stealer | In-memory credential and token scraping malware. |
| Target Vectors | AI Skills / MCP Servers / Dev Tools | Deceptive themes utilized in poisoned GitHub search listings. |
| Delivery URL Pattern | github.com//releases/download/ | Redundant archive hosting leveraging legitimate GitHub release assets. |
| Delivery URL Pattern | github.com//files/ | Abuse of GitHub issue attachments to bypass URL reputation filters. |
17,610 GitHub RepositoriesSmartLoaderStealCAI Skills and MCP ServersGitHub Releases and Issue Attachments// VERIFIED_SOURCES_&_REFERENCES
Watch Full Video Briefings on YouTube
Subscribe to CyberNewsAI on YouTube for animated threat vectors, CISO breakdowns, and security briefings.
Related Threat Intelligence
View Archive
ccTLD DNS Hijacks: How to Detect & Block Rogue TLS Certificates
Hackers compromise .GH, .SL, and .AS registries to hijack Google domains and issue rogue TLS certificates. Discover CT log hunting and CAA hardening rules.

Warlock Ransomware Hits Water and Telecom via SharePoint Flaws
China-linked Warlock ransomware breaches water and telecom operators via SharePoint flaws, deploying BYOVD EDR-killers and VS Code tunnels to strike 40 hosts.

Antino Backdoor Abuses M365 Outlook & OneDrive for Covert C2
China-nexus threat actor UAT-11587 targets Asian government entities with the Rust-based Antino backdoor, abusing Microsoft 365 Outlook and OneDrive for C2.