FakeGit campaign returns with 17,610 malicious GitHub repositories
The malware operation has resumed at scale, making it harder for GitHub takedowns to remove every copy at once.
FakeGit is back with a larger GitHub abuse campaign, using 17,610 malicious repositories to spread SmartLoader, which then delivers other malware such as StealC. Apiiro says the operation restarted on October 4 and packed more than 13,000 new repos into 34 hours, with a peak rate of 2,999 repos per hour. The researchers found that 97% of sampled commits changed only the README, while 88% sent the download button to a ZIP that installs SmartLoader. They also say takedown is hard because many copies are hidden in forks, release assets, issue attachments, and backup files, so deleting one link does not stop the campaign.
Why it matters
For people using GitHub-hosted project pages, the main risk is that a trusted-looking download path can now lead to SmartLoader and then other malware, including StealC. Because copies are spread across forks, release assets, issue attachments and other download locations, removing one repository or file does not end the campaign; defenders have to look for many linked copies at once.
Keep or strike?
Does this story matter, or is it hype? Mark it before you see what everyone else did.
Sources
- BleepingComputer