Yaamlabs
Threat intel

FakeGit returns: 17,610 GitHub repos push SmartLoader

The FakeGit campaign re-aimed 13,000+ fake GitHub repos in 34 hours to deliver SmartLoader and StealC. How the lure works and how to check your machines.

By Yaali. October 9, 2026, 6 min read, Threat intel, DevOps, Windows.

Cover illustration of rows of floating code repository cards with one cracked open, with the Yaamlabs logo and the text: 17,610 fake GitHub repos deliver StealC malware, 13,000+ repos re-pointed in 34 hours

On October 4, the FakeGit malware campaign came back to life on GitHub. Researchers at software supply-chain security firm Apiiro counted 17,610 malicious repositories, and found that more than 13,000 of them were updated in just 34 hours, at a peak of 2,999 an hour. Each one tells the visitor to download a ZIP archive, and that archive installs SmartLoader, a loader that ends with the StealC information stealer on the machine.

Anyone on your team who downloads tools, AI agent skills or Model Context Protocol (MCP) servers from GitHub on a Windows machine is in scope. StealC takes saved passwords and live browser sessions, so one developer laptop can hand over GitHub, cloud and SaaS access without anyone typing a password into a fake page.

Five-step FakeGit chain: a cloned GitHub repository with a Download button, a ZIP with a launcher, renamed LuaJIT runtime and disguised Lua script, a hidden loader that reads its server address from a Polygon smart contract, scheduled tasks under LOCALAPPDATA, and StealC loaded in memory

How it works

The repositories are copies of real projects or plausible inventions, with a modest star count and a README stripped down to install steps and a large Download button. Island, the enterprise browser company that named the campaign in July, found that more than 800 of the 7,600 repositories it tracked then posed as AI skills or MCP servers, including lookalikes of popular collections such as awesome-claude-skills. Others were framed as business tooling: a Splunk SOC dashboard, Salesforce document generation, Jenkins, Docker and Databricks connectors.

The ZIP holds three or four small files. In the sample Island describes, application.cmd contains one line, start luau.exe ico64.txt. The luau.exe file is a renamed LuaJIT runtime (a fast interpreter for the Lua scripting language), and ico64.txt is a roughly 300 KB Lua script, heavily obfuscated and squeezed onto a single line. Hexastrike, which analysed an earlier wave of 109 repositories in April, saw the same structure under other names (loader.exe, unit.exe, boot.exe, java.exe), sometimes with a separate lua51.dll, and scripts ending in .txt or .log. Nothing in the archive looks like an installer, and the runtime itself is not malicious, which is why it slips past many file checks.

Once the script runs, it hides its console window and reads its command and control (C2) server address from a Polygon blockchain smart contract. The operator can move the C2 by changing one value on the chain, with no new malware build and no domain to block. SmartLoader then creates scheduled tasks that start copies of itself from a folder under %LOCALAPPDATA%, pulls further encrypted stages from GitHub, and loads StealC into memory. StealC collects browser passwords, cookies and active sessions, extension data, email and remote access credentials, screenshots and host details.

What attackers are doing

The October wave changed what was already there instead of building new repositories. In the commits Apiiro sampled, 97% touched only the README and 88% pointed the Download button at a SmartLoader ZIP. Apiiro's summary: "Nobody had to create a single new repo. The fleet was already there. It just got re-aimed." Most accounts are throwaway ones, but Apiiro identified at least 700 that appear to belong to legitimate developers.

Takedowns have not kept up. Apiiro found that 71% of the fleet was missing from URLhaus, the public malicious URL feed, before its report. Payloads also sit in places a single report does not cover: forks, older files, release assets, issue attachments and separate repositories used only to host downloads. A DNS blocklist cannot block one file on GitHub without blocking GitHub.

Island measured more than 14 million downloads by July across about 200 repositories with release assets. That figure counts download events, not confirmed infections, and it misses the thousands of repositories that embed the ZIP directly. Island also listed more than 600 campaign entries on MCP directories (LobeHub, Glama, MCP.so and MCP Market) and showed that AI assistants, Claude Code among them, sometimes recommended a malicious repository when asked for a skill or MCP server.

What to do

There is no patch for this. The controls are about what runs on developer machines and how fast you cut off stolen sessions.

Four prioritised actions: block LuaJIT-style launchers, hunt for the scheduled tasks and LOCALAPPDATA copies, treat a hit as account compromise and revoke sessions and tokens, and source skills and MCP servers from vendor repositories

Block the launch pattern. Use application control (Windows Defender Application Control or AppLocker) to stop unsigned executables running from Downloads, %TEMP% and %LOCALAPPDATA%. Tell developers that a legitimate MCP server or skill ships as source code with a manifest, never as a ZIP containing a .cmd file and an .exe.

If you cannot enforce that today, add EDR (endpoint detection and response) alerts for cmd.exe running start with an executable and a .txt or .log argument, for lua51.dll loaded from outside Program Files, and for blockchain JSON-RPC traffic (Polygon or Ethereum eth_call requests) from processes that are not browsers. Block public blockchain RPC endpoints at the proxy if no business system needs them.

Check whether you were hit. Run schtasks /query /fo LIST /v on Windows endpoints and look for tasks whose action points into %LOCALAPPDATA% and passes a .txt or .log file to an executable. Two or more such tasks created minutes apart is a strong sign. Search EDR file events for ZIPs that held a .cmd or .bat file next to a LuaJIT binary, and match download history against Island's published list of repositories and ZIP SHA-256 hashes. Search proxy logs for downloads of ZIPs from github.com or raw.githubusercontent.com by machines outside your developer baseline.

Clean up as an account compromise. Isolate the endpoint and reimage it. Deleting the GitHub repository or the original ZIP does nothing, because the scheduled tasks run a cached copy under %LOCALAPPDATA% and can download the next stage again. Then, from a clean device, revoke browser sessions, OAuth grants, personal access tokens, SSH keys and cloud and developer credentials for every account used on that machine. A password reset alone leaves StealC's stolen session cookies working. Apiiro recommends moving affected GitHub accounts to passkeys.

Control where agent capabilities come from. Keep a reviewed list of approved skills, MCP servers and agent plugins, installed only from the vendor's own repository or an official registry. Check the publisher's account history, not just the project page, and test new capabilities in a sandbox with no browser sessions, SSH keys or cloud credentials.

Developer machines are part of the attack surface

A developer laptop with a logged-in browser holds more live access than most servers. Campaigns like FakeGit work because downloading a tool from GitHub feels like routine work rather than running an unknown program. Endpoint rules, egress filtering and session revocation built for phishing apply here too; they just need to cover the engineering team as well.

We hunt for scheduled task persistence, blockchain C2 lookups and stolen session reuse in security operations, and set up application control and egress rules for developer fleets in safeguarding and hardening. If you think someone downloaded one of these repositories, open the chat and Yaali, our AI agent, will pass the details to an engineer.


Sources: BleepingComputer, FakeGit returns with 17,610 repos, Apiiro, Island, AgentBaiting, Island IOC list, Hexastrike, BleepingComputer, FakeGit uses 7,600 repos, WindowsForum.

Read next

Back to the blog, or tell us about your system in the chat. Yaali, our AI agent, answers first and brings in an engineer.