FakeGit Campaign Uses 7,600 GitHub Repositories to Spread SmartLoader Malware
Summary
Researchers have identified the FakeGit campaign, which utilizes almost 7,600 malicious GitHub repositories to distribute SmartLoader malware. Over 800 of these repositories impersonate AI skills or Model Context Protocol (MCP) servers, employing tactics like copied projects and deceptive README files.
IFF Assessment
The FakeGit campaign's use of AI-related lures to distribute malware represents a new tactic for threat actors, making it harder for defenders to distinguish legitimate AI resources from malicious ones.
Defender Context
Defenders should be aware of sophisticated social engineering tactics that leverage the growing interest in AI. Users need to be cautious about downloading code or dependencies from unverified sources, even on platforms like GitHub, and thoroughly vet AI-related projects and repositories.