Researchers Document "FakeGit" Campaign Using 7,600 Malicious GitHub Repositories to Deliver SmartLoader Malware

A scale-significant GitHub impersonation campaign hits AI-tooling users — defender inventory work this week.

Share
Editorial line-art of identical fake repository folders fanning out from a cloned developer profile — the FakeGit campaign delivering SmartLoader.

Key Takeaways

  • Researchers on July 20, 2026 documented a campaign named "FakeGit" involving nearly 7,600 malicious GitHub repositories that deliver the SmartLoader malware family, with more than 800 of the repositories reportedly posing as artificial intelligence (AI) skills or Model Context Protocol (MCP) servers.
  • The campaign reportedly relies on copied projects, lookalike developer profiles, convincing READMEs, and malicious ZIP archives to lead users — and, researchers say, AI agents searching for tooling — from what looks like routine setup into SmartLoader's execution chain.
  • Several material facts are unconfirmed: the named threat operator behind FakeGit, whether GitHub has removed the repositories, and whether the campaign overlaps prior AI-services-hunting activity tracked in The CyberSignal's earlier NadMesh coverage — leaving defenders to act on inventory and verification rather than a single indicator to block.

Researchers say nearly 7,600 lookalike GitHub repositories — 800-plus of them impersonating AI skills and MCP servers — funnel users and AI agents toward SmartLoader, a supply-chain impersonation story defenders depending on GitHub should inventory this week.

SAN FRANCISCO, CALIF. — Security researchers on July 20, 2026 documented a campaign they call "FakeGit" that reportedly spans nearly 7,600 malicious GitHub repositories built to deliver the SmartLoader malware family. According to the reporting, more than 800 of those repositories pose as artificial intelligence (AI) skills or Model Context Protocol (MCP) servers, borrowing the names and workflows of familiar consumer and enterprise tools so that a malicious download appears to be ordinary setup. The finding, attributed to researchers at Island and first reported by The Hacker News, frames FakeGit less as an intrusion than as an impersonation operation running at scale on a platform millions of developers trust by default.

For defenders, the relevant detail is not a novel exploit but the breadth of the lure surface and the population it targets. FakeGit reportedly uses copied projects, lookalike developer profiles, convincing READMEs, and malicious ZIP archives — no platform compromise required. It also arrives pointed at AI-tooling users, a fast-growing and under-inventoried category, which places it alongside a lengthening 2026 thread of supply-chain research in which the malicious-skill marketplace and MCP registry surface has become its own exposure.

At a Glance
FieldDetails
Campaign"FakeGit" (as named in reporting)
DocumentedJuly 20, 2026
Attributed toResearchers at Island (via The Hacker News)
ScaleNearly 7,600 malicious GitHub repositories
AI / MCP subsetMore than 800 posing as AI skills or MCP servers
Delivered malwareSmartLoader (reportedly followed by StealC)
Reported luresCopied projects, lookalike developer profiles, READMEs, malicious ZIPs
Named threat operatorNot confirmed
GitHub removal statusNot confirmed

What Researchers Documented

The account, published by The Hacker News and drawn from research by Island, describes a campaign built on volume and mimicry rather than a single technical flaw. Researchers reportedly counted nearly 7,600 malicious GitHub repositories, created through roughly 6,600 profiles, each dressed to look like a legitimate project. The repositories are said to be either wholly fabricated or copied from real projects, using lookalike developer profiles and convincing READMEs so that a visitor — or an automated tool — has a credible reason to trust them. The operator behind the campaign is not named in the reporting.

The delivered payload is SmartLoader, a loader family reportedly used to establish persistence and pull secondary payloads, including the StealC information stealer. According to the reporting, the counterfeit repositories serve a malicious ZIP archive that triggers a loader chain ending in SmartLoader's execution. The CyberSignal is not reproducing that chain; the defender-relevant point is the delivery model, not the internals. As Island put it, per the research writeup, the campaign "did not need to breach anything" — it published convincing repositories and let ordinary discovery do the rest.

The 800-Repository AI / MCP Impersonation Angle

The detail that separates FakeGit from a routine typosquatting run is its focus on AI tooling. Of the nearly 7,600 repositories, more than 800 reportedly pose as AI skills or Model Context Protocol (MCP) servers — the plug-in style components that let AI assistants call external tools and data. The impersonated targets reportedly span consumer and enterprise integrations alike, chosen to meet demand already forming around agent capabilities.

Researchers describe an AI-specific twist they call AgentBaiting: because an AI agent tasked with finding a skill or MCP server may surface one of these repositories on its own, the agent can read the attacker-authored README as legitimate documentation and carry its instructions forward without a human ever clicking a link. Island reported that tests found agents from major vendors susceptible to surfacing campaign repositories, and that more than 600 campaign listings were flagged across public registries. That mirrors the poisoned-component risk documented in prior supply-chain research into AI-assistant tooling, where the trusted registry itself became the delivery surface.

Continuation Context: AI-Agent Supply Chain

FakeGit reads as the latest entry in a 2026 pattern: the connective tissue of modern development — repositories, packages, extensions, and now agent tooling — is a first-class target, and untrusted content reaching that tissue is the recurring trigger. GitHub has hosted a run of scale-defined campaigns this year, from the Megalodon workflow-backdoor operation spanning thousands of repositories to research on a worm that steered AI coding agents across GitHub repositories. The through-line is that scale plus trust, not novelty, is what makes these campaigns effective.

What FakeGit adds is a second, non-human audience. Earlier campaigns aimed to socially engineer developers; this one is reportedly built to deceive both people and the AI agents acting on their behalf. That matters because an agent's discovery-and-install workflow can move faster than a human evaluating an unfamiliar repository — collapsing the pause in which a suspicious project might otherwise be caught.

Defender Posture for Organizations Depending on GitHub

For teams whose developers and pipelines depend on GitHub, the practical work this week is inventory and verification, not a scramble for a patch — there is no single vulnerability to close. The first step is to build and maintain a catalog of reviewed skills, MCP servers, and agent plugins, so that additions are drawn from a vetted list rather than discovered ad hoc through search. A curated allowlist is the control that most directly interrupts an impersonation campaign whose entire premise is that discovery equals trust.

The second step is verification at the source: confirm both the publisher and the underlying project before a repository is cloned, installed, or granted to an agent, treating a plausible README and a familiar name as necessary but not sufficient. New agent capabilities warrant sandboxed evaluation before broad rollout, and agentic discovery-and-install pathways deserve monitoring. That governance posture echoes the developer-trust lessons of the TeamPCP internal-repository breach tied to a VS Code extension: the tooling around the code is now as much a trust decision as the code itself.

GitHub's Response and What to Watch For

A central open item is the platform's response. As of this reporting, it is not confirmed whether GitHub has removed the identified repositories or issued campaign-specific guidance, and the campaign is described as ongoing. For defenders, that absence is itself information: without a confirmed takedown to rely on, the responsible posture is to act on the inventory and verification steps above rather than assume the malicious repositories are already gone.

The developments worth watching are a confirmed platform response — removals, publisher-verification changes, or guidance for AI-tooling users — and any corroborating research from other vendors. The scale-and-registry shape of FakeGit also resembles prior CI/CD supply-chain findings such as the Cordyceps research spanning hundreds of GitHub repositories, so independent confirmation and any overlap analysis will help defenders size the population genuinely at risk.

Open Questions

Several questions material to defenders remain unresolved. The named threat operator behind FakeGit has not been established in the reporting, which leaves attribution and any actor-specific defensive guidance open. It is likewise not confirmed whether GitHub has removed the roughly 7,600 repositories, a status that directly affects whether the exposure is receding or persisting.

Reported download figures — including a headline count in the millions across a subset of campaign repositories — come from the researchers' telemetry and are best read as reported rather than independently confirmed totals. It is also not confirmed whether FakeGit overlaps the AI-services-hunting activity The CyberSignal covered earlier in the NadMesh reporting, an overlap that, if established, would reshape how the two are tracked. The CyberSignal will update as authoritative detail emerges.


The CyberSignal Analysis

The facts above come from the researchers' account and its reporting; what follows is The CyberSignal's editorial reading of what defenders should take from them. None of the judgments below are new reported facts.

Signal 01 — Scale and Trust, Not Novelty, Are the Weapon

The durable read of FakeGit is that its power comes from volume and borrowed credibility, not a clever exploit. Nearly 7,600 lookalike repositories turn GitHub's own trust-by-default into the delivery mechanism, so the defensive answer is not signature-based blocking but structurally distrusting discovery. Our reading: treat any repository reached by search rather than by a vetted reference as unverified until publisher and project are independently confirmed.

Signal 02 — AI Agents Are Now Part of the Attack Surface

The 800-plus AI-skill and MCP impersonations, and the AgentBaiting behavior researchers describe, mark a real expansion: an autonomous agent that discovers and installs tooling can be led into the same trap as a hurried developer, only faster. Defenders should govern agent discovery-and-install pathways as a privileged activity — constrained to a reviewed catalog, sandboxed on first use, and logged — not treat agents as safe consumers of public registries.

Signal 03 — Inventory Now, Do Not Wait for a Takedown

With no confirmed GitHub removal and the campaign described as ongoing, waiting for a platform fix would leave the controllable exposure — which skills, servers, and plugins your developers and agents actually pull — untouched. The teams that come out of this well will be the ones that stood up a vetted catalog and a publisher-verification habit this week, treating any eventual takedown as confirmation of a posture they already held.


Sources

TypeSource
ReportingThe Hacker News — FakeGit Campaign Uses 7,600 GitHub Repositories to Spread SmartLoader Malware
PrimaryIsland — AgentBaiting: How 800 Fake AI Skills and MCP Servers Delivered Malware
RelatedThe CyberSignal — OpenClaw Skill-Marketplace Malicious-Skills Research
RelatedThe CyberSignal — Trapdoor npm/PyPI/crates Supply-Chain AI-Assistant Poisoning
RelatedThe CyberSignal — Megalodon GitHub CI/CD Workflow Backdoor Across 5,561 Repositories
RelatedThe CyberSignal — Microsoft GitHub Repos Miasma Worm and AI Coding Agents
RelatedThe CyberSignal — GitHub TeamPCP Internal-Repository Breach via VS Code Extension
RelatedThe CyberSignal — Cordyceps CI/CD GitHub 300-Repos Disclosure