The FakeGit malware campaign has resumed operations, using more than 17,610 counterfeit repositories on GitHub to spread the SmartLoader malware, according to a new report from software supply-chain security platform Apiiro. The campaign reactivated on October 4 to push the StealC infostealer, the researchers said. The operation relies mostly on disposable accounts, though investigators identified at least 700 accounts that appear to belong to legitimate developers.

Apiiro researchers reported that FakeGit published more than 13,000 repositories in a span of 34 hours, with activity peaking at 2,999 repositories per hour. In the commits the researchers sampled, 97 percent modified only the README file, and 88 percent pointed a download button at a ZIP archive that installs SmartLoader. The researchers said the fleet of repositories was already in place and was simply redirected toward new payloads rather than newly created.

The malicious repositories present README instructions with a download button that leads to a ZIP archive containing the initial payload, SmartLoader, which is then used to deliver additional malware. Apiiro found the malicious archives distributed across forks, older files, release assets, issue attachments, and separate download-hosting repositories. The researchers said that deleting a single file allows the operator to redirect the lure to a spare copy, such as a fork, an older ZIP, a release asset, or an issue attachment.

Similar activity involving various payloads has been observed since at least January, and the FakeGit name was tied to the operation in July. At that time, researchers at enterprise browser platform Island published a report on 7,600 fake GitHub repositories distributing SmartLoader. Island noted that 800 of those repositories masqueraded as AI skills or MCP servers that appeared in public AI registries and catalogs.

According to Apiiro, the campaign has survived because repository removal efforts rely on lists that cover only a fraction of the malicious repositories. The researchers said 71 percent of the fleet was absent from URLhaus before their report, and they noted that a domain-level DNS blocklist cannot block a single file on GitHub without blocking GitHub itself. Blocklisted payloads and backup copies also remain accessible, allowing attackers to change download links while keeping the same repositories active.

Apiiro recommends that users verify a repository's owner and obtain AI skills and MCP servers only from official registries or vendor repositories. If SmartLoader execution is suspected, the researchers advise treating the incident as a potential GitHub account compromise, revoking active sessions and access tokens, and switching to passkeys. The campaign's persistence highlights the difficulty of removing malicious content from a platform where files can be duplicated across many locations.

More cybersecurity news from TechManNews.