FakeGit Spreads Malware Through Fake GitHub Repositories

FakeGit Uses Thousands of GitHub Repositories to Spread Malware

Cybersecurity researchers have uncovered a large malware campaign using approximately 7,600 malicious GitHub repositories to target developers, businesses, and users of AI tools.

Known as FakeGit, the campaign uses counterfeit projects, lookalike developer profiles, professional-looking README files, and malicious ZIP downloads to spread SmartLoader malware. More than 800 repositories reportedly impersonated AI skills or Model Context Protocol (MCP) servers.

How the Attack Works

The malicious repositories are either fabricated or copied from legitimate projects. Their instructions direct users to download a ZIP file containing a hidden loader.

Once opened, the file launches an obfuscated script that installs SmartLoader. The malware can establish persistence and deliver additional threats, including the StealC information stealer.

StealC may collect:

  • Account credentials
  • Browser data and session cookies
  • Cryptocurrency wallet information
  • Developer secrets and authentication tokens
  • Other sensitive information stored on the device

Researchers also identified more than 600 related listings across public AI skill and MCP registries.

AI Agents Can Be Tricked Too

FakeGit includes a technique called “AgentBaiting,” which targets AI-assisted software discovery.

According to Island’s testing, an AI agent searching for a requested skill or MCP server could independently find a malicious repository, treat its README as legitimate documentation, and present the attacker’s installation instructions to the user.

This means an employee does not necessarily need to receive a phishing email or malicious link. A seemingly harmless request for an AI integration could lead an AI assistant to recommend a compromised project.

Why It Matters

GitHub repositories and public AI registries can appear trustworthy, but attackers can imitate legitimate developers, copy existing projects, and create convincing documentation.

The campaign reportedly generated more than 14 million GitHub Release downloads across approximately 200 repositories. However, download counts do not necessarily represent successful infections.

FakeGit does not appear to exploit a vulnerability in GitHub itself. Instead, it takes advantage of trust in open-source projects, public registries, and AI-generated recommendations.

How Businesses Can Respond

  • Maintain an approved list of AI skills, MCP servers, plugins, and open-source tools.
  • Never install software solely because an AI assistant recommends it.
  • Verify the developer, repository history, official website, and installation files.
  • Test new AI integrations in an isolated environment before deployment.
  • Limit the credentials and systems accessible to AI agents and development tools.
  • Use endpoint detection and application controls to identify unknown loaders and scripts.
  • If a suspicious tool was installed, isolate the device and revoke exposed credentials, tokens, and active sessions.

AI agents can accelerate routine work, but their recommendations must still be treated as unverified. Organizations need approval processes that stop unknown software before it reaches business systems.

Britec helps businesses strengthen endpoint security, manage technology risks, and safely adopt new tools.