7,600 Fake GitHub Repos Spread SmartLoader Malware


Researchers uncovered 7,600 fake GitHub repositories spreading SmartLoader malware through cloned projects and AI tool lures.

Cybersecurity researchers have uncovered a large-scale malware campaign that uses thousands of fake GitHub repositories to lure developers into downloading malicious software. The operation, dubbed FakeGit, has created nearly 7,600 repositories, many of which closely imitate legitimate open-source projects to distribute a malware loader known as SmartLoader.

The campaign was disclosed by researchers at Island in July 2026, who found that more than 800 of the repositories were disguised as AI skills or Model Context Protocol (MCP) servers. By taking advantage of the growing popularity of AI development tools and MCP ecosystems, the attackers increase the chances of developers unknowingly downloading malware instead of legitimate software.

According to Oleg Zaytsev, Lead Security Researcher at Island, the attackers don’t simply create fake repositories. They clone legitimate GitHub projects, copy README files and documentation, and build convincing developer profiles to make the repositories appear genuine. Victims who download the projects are often directed to external ZIP archives that contain SmartLoader rather than the advertised application.

Once executed, SmartLoader provides attackers with an initial foothold on the victim’s system and downloads additional malware. Researchers observed it delivering StealC, an information-stealing malware capable of collecting browser credentials, session cookies, cryptocurrency wallet data, and other sensitive information. The secondary malware can then be used to establish persistence and carry out further malicious activity on compromised systems.

The campaign extends well beyond GitHub itself. Researchers identified more than 600 malicious listings across public MCP and AI skill registries, including LobeHub, Glama, MCP.so, and MCP Market. Publishing fake projects on trusted AI marketplaces gives the repositories additional credibility and increases the likelihood that developers will discover them during routine searches.

Researchers say the campaign highlights a growing challenge for the software development community. As developers increasingly rely on AI-assisted tools and public MCP registries to discover new projects, malicious repositories can appear alongside legitimate ones, making it easier for attackers to exploit trust rather than technical vulnerabilities.

Island recommends that developers carefully verify the authenticity of repositories before downloading software, inspect developer profiles and project histories, and be especially cautious of projects that distribute executable ZIP files instead of source code. Organizations should also monitor endpoints for unusual network activity and deploy endpoint security solutions capable of detecting malware loaders before they deliver additional payloads.

Rather than exploiting flaws in GitHub itself, the FakeGit campaign relies on deception. By cloning popular open-source projects and creating convincing developer identities, the attackers are able to trick users into infecting their own systems a reminder that even trusted platforms can become effective delivery channels when social engineering is involved.

Related articles :


Reports are sourced from official documents, law-enforcement updates, and credible investigations.

Discover additional reports, market trends, crime analysis and Harm Reduction articles on DarkDotWeb to stay informed about the latest dark web operations.