Executive Summary
In July 2026, cybersecurity researchers uncovered a large-scale operation named 'FakeGit,' involving approximately 7,600 malicious GitHub repositories. Over 800 of these repositories masqueraded as AI skills or Model Context Protocol (MCP) servers, distributing the SmartLoader malware. The campaign utilized copied projects, convincing documentation, and malicious ZIP files to deceive users into downloading the malware. Once executed, SmartLoader established persistence, retrieved command-and-control addresses via Polygon smart contracts, and delivered additional payloads like the StealC information stealer. This operation accumulated over 14 million downloads across GitHub Release assets in about 200 repositories. (bleepingcomputer.com)
The FakeGit campaign introduced a novel technique termed 'AgentBaiting,' designed to increase the visibility of malicious repositories to AI agents. By appearing in public AI registries and catalogs, these repositories were more likely to be discovered and recommended by AI agents, thereby enhancing the campaign's reach and effectiveness. (bleepingcomputer.com)
Why This Matters Now
The FakeGit campaign highlights the evolving threat landscape where attackers exploit AI agents to disseminate malware, emphasizing the need for enhanced security measures in AI-driven environments.
Attack Path Analysis
The FakeGit campaign involved creating malicious GitHub repositories to distribute SmartLoader malware. Attackers leveraged these repositories to trick users into downloading and executing malicious payloads, leading to system compromise. Once executed, SmartLoader established persistence and downloaded additional payloads, including the StealC information stealer. The malware then communicated with command and control servers to exfiltrate sensitive data from compromised systems.
Kill Chain Progression
Initial Compromise
Description
Attackers created 7,600 malicious GitHub repositories posing as legitimate AI tools and MCP servers, tricking users into downloading and executing SmartLoader malware.
MITRE ATT&CK® Techniques
Compromise Software Dependencies and Development Tools
Search Open Websites/Domains: Code Repositories
Exfiltration to Code Repository
Application Layer Protocol: Web Protocols
Command and Scripting Interpreter: PowerShell
Command and Scripting Interpreter: Windows Command Shell
Command and Scripting Interpreter: Visual Basic
Command and Scripting Interpreter: Python
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Ensure all system components and software are protected from known vulnerabilities
Control ID: 6.2
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA – ICT Risk Management Framework
Control ID: Article 5
CISA ZTMM 2.0 – Data
Control ID: Pillar 3
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Computer Software/Engineering
Direct supply chain attack targeting GitHub repositories and AI development tools, compromising developer environments with SmartLoader malware through poisoned repositories.
Information Technology/IT
AI agents and coding assistants vulnerable to agentbaiting attacks, requiring enhanced egress filtering and zero trust segmentation for development infrastructure protection.
Financial Services
StealC credential theft targeting financial data requires immediate secret rotation and enhanced anomaly detection for regulatory compliance under PCI standards.
Health Care / Life Sciences
HIPAA-regulated environments face data exfiltration risks from compromised AI tools, demanding encrypted traffic monitoring and strict access controls implementation.
Sources
- FakeGit campaign uses 7,600 GitHub repos to push SmartLoader malwarehttps://www.bleepingcomputer.com/news/security/fakegit-campaign-uses-7-600-github-repos-to-push-smartloader-malware/Verified
- FakeGit Campaign Uses 7,600 GitHub Repositories to Spread SmartLoader Malwarehttps://thehackernews.com/2026/07/fakegit-campaign-uses-7600-github.htmlVerified
- AI agents tricked into recommending malicious GitHub repositorieshttps://www.helpnetsecurity.com/2026/07/21/github-repos-malware-campaign-fakegit-ai-agents/Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Aviatrix Zero Trust CNSF is pertinent to the FakeGit campaign as it would likely limit the malware's ability to move laterally and exfiltrate data, thereby reducing the attack's overall impact.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: The CNSF would likely limit the malware's ability to communicate with unauthorized external repositories, reducing the risk of initial compromise.
Control: Zero Trust Segmentation
Mitigation: Zero Trust Segmentation would likely limit the malware's ability to escalate privileges by restricting unauthorized internal communications.
Control: East-West Traffic Security
Mitigation: East-West Traffic Security would likely limit the malware's ability to move laterally by enforcing strict controls on internal traffic.
Control: Multicloud Visibility & Control
Mitigation: Multicloud Visibility & Control would likely limit the malware's ability to establish command and control channels by monitoring and controlling outbound communications.
Control: Egress Security & Policy Enforcement
Mitigation: Egress Security & Policy Enforcement would likely limit the malware's ability to exfiltrate data by enforcing strict controls on outbound data transfers.
By limiting lateral movement and data exfiltration, Aviatrix Zero Trust CNSF would likely reduce the overall impact of the attack, minimizing potential financial and reputational damage.
Impact at a Glance
Affected Business Functions
- Software Development
- AI Model Deployment
- Data Analysis
- IT Infrastructure
Estimated downtime: 7 days
Estimated loss: $500,000
Potential exposure of sensitive data including intellectual property, proprietary code, and confidential client information.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to restrict lateral movement and limit the spread of malware within the network.
- • Deploy Egress Security & Policy Enforcement to monitor and control outbound traffic, preventing unauthorized data exfiltration.
- • Utilize Multicloud Visibility & Control to gain comprehensive insights into network traffic and detect anomalous activities across cloud environments.
- • Apply Inline IPS (Suricata) to identify and block known exploit patterns and malicious payloads in real-time.
- • Establish Threat Detection & Anomaly Response mechanisms to promptly detect and respond to suspicious behaviors indicative of compromise.



