Executive Summary
In July 2026, cybersecurity researchers uncovered the 'FakeGit' campaign, involving nearly 7,600 malicious GitHub repositories. Over 800 of these repositories masqueraded as artificial intelligence (AI) skills or Model Context Protocol (MCP) servers, distributing the SmartLoader malware. Attackers employed tactics such as cloning legitimate projects, creating deceptive developer profiles, and crafting convincing README files to lure users into downloading malicious ZIP files. Once executed, SmartLoader established persistence on compromised systems and deployed secondary payloads like StealC, an information stealer capable of harvesting extensive data.
This incident underscores the evolving threat landscape where attackers exploit trusted platforms and emerging technologies. The 'AgentBaiting' technique, wherein AI agents inadvertently discover and propagate malicious repositories, highlights the need for enhanced vigilance in AI-assisted operations. Organizations must implement robust security measures to detect and mitigate such sophisticated supply chain attacks.
Why This Matters Now
The 'FakeGit' campaign exemplifies the increasing sophistication of supply chain attacks, particularly those leveraging AI technologies. As AI becomes more integrated into development workflows, the risk of AI agents inadvertently facilitating malware distribution grows. Immediate attention is required to fortify AI systems against such manipulations and to safeguard the integrity of software supply chains.
Attack Path Analysis
The FakeGit campaign began with attackers creating nearly 7,600 malicious GitHub repositories, many posing as AI tools, to distribute SmartLoader malware. Upon execution, SmartLoader exploited system vulnerabilities to escalate privileges, enabling deeper system access. The malware then moved laterally within networks, targeting additional systems to expand its foothold. It established command and control channels to receive instructions and deploy secondary payloads like StealC. Sensitive data was exfiltrated from compromised systems to attacker-controlled servers. The campaign's impact included data breaches, system compromises, and potential financial losses.
Kill Chain Progression
Initial Compromise
Description
Attackers created nearly 7,600 malicious GitHub repositories, many posing as AI tools, to distribute SmartLoader malware.
MITRE ATT&CK® Techniques
Supply Chain Compromise: Compromise Software Dependencies and Development Tools
Phishing: Spearphishing Link
User Execution: Malicious File
Command and Scripting Interpreter: JavaScript
Ingress Tool Transfer
Application Layer Protocol: Web Protocols
Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder
Screen Capture
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Ensure all system components and software are protected from known vulnerabilities
Control ID: 6.2
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA – ICT Risk Management Framework
Control ID: Article 5
CISA ZTMM 2.0 – Asset Management
Control ID: 3.1
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Computer Software/Engineering
FakeGit supply-chain attacks targeting 7,600 GitHub repositories with SmartLoader malware critically threaten software development pipelines and AI model deployment security.
Information Technology/IT
Malicious AI skills and MCP servers delivering SmartLoader exploit IT infrastructure dependencies, requiring enhanced egress filtering and repository validation controls.
Artificial Intelligence
Fake AI repositories and Model Context Protocol servers specifically target AI development workflows, compromising machine learning model integrity and deployment security.
Financial Services
Supply-chain compromises through malicious GitHub repositories threaten financial software dependencies, requiring zero trust segmentation and enhanced threat detection capabilities.
Sources
- FakeGit Campaign Uses 7,600 GitHub Repositories to Spread SmartLoader Malwarehttps://thehackernews.com/2026/07/fakegit-campaign-uses-7600-github.htmlVerified
- Hundreds of GitHub repos found posing as real software to push malwarehttps://www.techradar.com/pro/security/hundreds-of-github-repos-found-posing-as-real-software-to-push-malwareVerified
- 109 Fake GitHub Repositories Used to Deliver SmartLoader and StealC Malwarehttps://www.cryptika.com/109-fake-github-repositories-used-to-deliver-smartloader-and-stealc-malware/Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Aviatrix Zero Trust CNSF is pertinent to the FakeGit campaign as it would likely limit the attacker's ability to move laterally and exfiltrate data by enforcing strict workload segmentation and controlled egress policies.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: The CNSF would likely limit the malware's ability to communicate with external command and control servers, reducing the risk of further malicious actions.
Control: Zero Trust Segmentation
Mitigation: Zero Trust Segmentation would likely constrain the malware's ability to access sensitive resources, even with escalated privileges.
Control: East-West Traffic Security
Mitigation: East-West Traffic Security would likely restrict unauthorized lateral movement, limiting the malware's ability to spread across the network.
Control: Multicloud Visibility & Control
Mitigation: Multicloud Visibility & Control would likely detect and limit unauthorized command and control communications, reducing the risk of further compromise.
Control: Egress Security & Policy Enforcement
Mitigation: Egress Security & Policy Enforcement would likely limit unauthorized data exfiltration, reducing the risk of data breaches.
The CNSF would likely reduce the overall impact of such attacks by limiting the attacker's ability to move laterally and exfiltrate data.
Impact at a Glance
Affected Business Functions
- Software Development
- Artificial Intelligence Integration
- Data Security
Estimated downtime: 7 days
Estimated loss: $500,000
Potential exposure of sensitive data due to StealC malware, including credentials and personal information.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to restrict lateral movement within networks.
- • Deploy Egress Security & Policy Enforcement to monitor and control outbound traffic, preventing unauthorized data exfiltration.
- • Utilize Multicloud Visibility & Control to detect and respond to anomalous activities across cloud environments.
- • Apply Inline IPS (Suricata) to identify and block known exploit patterns and malicious payloads.
- • Establish Threat Detection & Anomaly Response mechanisms to promptly detect and mitigate suspicious behaviors.



