FakeGit Campaign Uses 7,600 GitHub Repositories to Spread SmartLoader Malware
20:23 · July 20, 2026 · Hacker News AI Section

Cybersecurity researchers have discovered nearly 7,600 malicious GitHub repositories, out of which more than 800 pose as artificial intelligence (AI) skills or Model Context Protocol (MCP) servers to deliver a malware family known as SmartLoader as part of an ongoing campaign codenamed FakeGit. "FakeGit uses copied projects, lookalike developer profiles, convincing READMEs, and malicious ZIP
Summary
Cybersecurity researchers have identified a large-scale operation, tracked as FakeGit, that has published nearly 7,600 malicious GitHub repositories created by roughly 6,600 accounts. More than 800 of these repositories impersonate AI skills or Model Context Protocol (MCP) servers for tools such as Gmail, WhatsApp, Databricks, Jenkins, and Docker. The repositories deliver SmartLoader, a loader that establishes persistence and deploys secondary payloads, notably the StealC information stealer.
The campaign relies on copied or fabricated projects, lookalike developer profiles, and detailed README files that guide users or agents toward a malicious ZIP archive. That archive triggers a LuaJIT-based loader chain, which executes an obfuscated Lua script to install SmartLoader. The repositories have accumulated more than 14 million downloads from GitHub Release assets, with many listings also appearing on public MCP and skill registries such as LobeHub, Glama, and MCP.so.
A notable development is AgentBaiting, in which AI agents from Anthropic Claude, Google Gemini, and OpenAI ChatGPT independently locate the counterfeit repositories during routine searches for skills or MCP servers. The agents can interpret the attacker-supplied README instructions and relay them to users without any direct human interaction or supplied links. Prompts that request free cinematic prompt skills or enterprise MCP servers have been shown to surface the malicious entries.
Defensive recommendations focus on maintaining curated catalogs of vetted skills and MCP servers, testing new agent capabilities inside sandboxed environments, verifying both publishers and project provenance, and monitoring agent-driven discovery paths to interrupt the chain before execution.
Why it matters
Directly addresses AI-specific security risks and privacy threats via malware in AI tooling ecosystems, with actionable recommendations applicable to Dutch teams using GitHub, MCP servers, or agentic AI. Aligns with EU data protection needs due to data-stealing payloads.







