Executive Summary
The FakeGit malware campaign resurfaced in October 2024 with over 17,610 malicious GitHub repositories distributing SmartLoader malware and StealC infostealer. Threat actors exploited legitimate developer accounts and created convincing fake repositories with README files containing download buttons that delivered malicious ZIP archives. In just 34 hours starting October 4, attackers pushed over 13,000 repositories at a peak rate of 2,999 per hour, targeting AI skills repositories and MCP servers listed in public registries to maximize credibility and infection rates.
This incident highlights the growing trend of supply chain attacks targeting developer platforms and AI infrastructure. As organizations increasingly adopt AI-powered development tools and automated deployment pipelines, attackers are exploiting trust relationships in code repositories to bypass traditional security controls and distribute malware at scale.
Why This Matters Now
Supply chain attacks through trusted platforms like GitHub are escalating rapidly, with attackers now targeting AI development ecosystems. Organizations must urgently implement repository verification and egress controls as traditional blocklisting proves insufficient against campaign resilience tactics.
Attack Path Analysis
FakeGit operators compromised developer trust through 17,610 malicious GitHub repositories containing SmartLoader malware disguised as legitimate AI tools and MCP servers. Attackers exploited GitHub's trusted platform status to bypass security controls, delivered malware through convincing README download buttons, established persistence via distributed backup copies across forks and releases, maintained command and control through SmartLoader to deploy StealC infostealer, exfiltrated stolen credentials and sensitive data, and achieved sustained impact by surviving takedown attempts through repository redundancy and rapid re-pointing of download links.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
Attackers created 17,610 fake GitHub repositories masquerading as legitimate AI skills and MCP servers, using convincing README files with download buttons pointing to ZIP archives containing SmartLoader malware
MITRE ATT&CK® Techniques
Supply Chain Compromise: Compromise Software Dependencies and Development Tools
Phishing: Spearphishing Link
User Execution: Malicious File
Masquerading: Match Legitimate Name or Location
Exfiltration Over Web Service: Exfiltration to Cloud Storage
Credentials from Password Stores: Credentials from Web Browsers
Hide Artifacts: NTFS File Attributes
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Software Development Security Controls
Control ID: 6.3.2
NYDFS 23 NYCRR 500 – Third-Party Service Provider Security Policy
Control ID: 500.11
DORA – ICT Third-Party Risk Management
Control ID: Article 11
CISA ZTMM 2.0 – Data Categorization and Security
Control ID: DA.L2
NIS2 Directive – Supply Chain Security
Control ID: Article 21.2.d
ISO 27001:2022 – Information Security Policy for Supplier Relationships
Control ID: A.15.1.1
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Computer Software/Engineering
Supply chain attacks via 17,610 malicious GitHub repos distributing SmartLoader malware directly compromise software development workflows and code repositories.
Information Technology/IT
FakeGit campaign targeting AI skills and MCP servers creates significant lateral movement risks across IT infrastructure through compromised developer accounts.
Financial Services
StealC infostealer payload threatens sensitive financial data exfiltration while compromised GitHub credentials enable unauthorized access to proprietary trading systems.
Computer/Network Security
Security firms face reputational damage as FakeGit exploits trust in open-source repositories while evading traditional blocklist-based detection mechanisms.
Sources
- FakeGit malware campaign returns with 17,610 malicious GitHub reposhttps://www.bleepingcomputer.com/news/security/fakegit-malware-campaign-returns-with-17-610-malicious-github-repos/Verified
- Never deleted, only re-pointed: How FakeGit survived and thrivedhttps://apiiro.com/blog/never-deleted-only-re-pointedVerified
- FakeGit campaign uses 7,600 GitHub repos to push SmartLoader malwarehttps://www.bleepingcomputer.com/news/security/fakegit-campaign-uses-7-600-github-repos-to-push-smartloader-malware/Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF would likely constrain the FakeGit campaign's lateral spread and data exfiltration by implementing workload segmentation and controlled egress paths. While initial developer workstation compromise may still occur, the attack's blast radius and persistence capabilities would be significantly reduced through identity-aware access controls and east-west traffic enforcement.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: Initial workstation compromise may still occur through social engineering, but CNSF visibility controls would likely provide earlier detection of anomalous network behavior patterns from infected endpoints attempting to establish persistent communication channels.
Control: Zero Trust Segmentation
Mitigation: SmartLoader's ability to establish broad system persistence would likely be constrained through workload isolation, limiting the malware's access to sensitive system resources and reducing its capability to deploy additional payloads across segmented network boundaries.
Control: East-West Traffic Security
Mitigation: Lateral movement between developer workstations and internal systems would likely be significantly constrained through microsegmentation policies, reducing the attacker's ability to expand their foothold across the development environment using compromised credentials.
Control: Multicloud Visibility & Control
Mitigation: Command and control communications would likely face increased scrutiny through enhanced visibility controls, making it more difficult for attackers to maintain persistent communication channels and deploy additional payloads without detection.
Control: Egress Security & Policy Enforcement
Mitigation: Data exfiltration attempts would likely be constrained through controlled egress policies, limiting the volume and types of data that could be transmitted externally and blocking connections to known malicious infrastructure.
While individual developer workstations may remain compromised, the overall impact to organizational infrastructure would likely be contained through network segmentation, limiting the campaign's ability to compromise critical development systems and reducing the scope of supply chain contamination.
Impact at a Glance
Affected Business Functions
- Software Development
- Source Code Management
- AI/ML Development
- DevOps Operations
Estimated downtime: 1 days
Estimated loss: N/A
Potential compromise of developer accounts, source code repositories, authentication tokens, and credentials from infected systems. Risk of supply chain contamination affecting downstream software projects and end users.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Cloud Native Security Fabric (CNSF) controls to detect and block initial malware delivery through real-time inspection of download traffic and payload analysis
- • Deploy Egress Security & Policy Enforcement to prevent StealC infostealer from exfiltrating stolen credentials by blocking unauthorized outbound connections to attacker infrastructure
- • Enable Multicloud Visibility & Control to detect anomalous GitHub repository creation patterns and suspicious automation indicative of large-scale fake repository campaigns
- • Implement Zero Trust Segmentation to limit the impact of compromised developer workstations by restricting lateral movement and privileged access to critical repositories and systems
- • Deploy Threat Detection & Anomaly Response capabilities to baseline normal developer behavior and alert on indicators of compromise such as unusual repository access patterns or credential theft activities



