// 2 ZERO-DAY · 3 CVE · 1 ADVISORY IN THE LAST 24H→
The FakeGit campaign returned on October 4, 2026 with 17,610 GitHub repositories. SmartLoader delivers StealC, leveraging legitimate accounts and AI agents.

The FakeGit campaign resumed operations on October 4, 2026. In just 34 hours it reactivated over 13,000 GitHub repositories, peaking at 2,999 in a single hour, for a total of 17,610 malicious repositories. The mechanism mirrors the July wave—convincing READMEs, Download buttons pointing to ZIP archives containing the LuaJIT-based SmartLoader that installs the StealC infostealer—but with a critical difference: no new repositories were created. The fleet already existed.

This "resilience through re-aiming," documented by Apiiro researchers, exposes a structural limit in current defenses. When targeted removal fails to destroy the payload and merely changes its pointer, content-based detection becomes a game of cat and mouse that the defender loses by definition.

Key Takeaways
  • FakeGit resumed activity on October 4, 2026 with 17,610 malicious GitHub repositories, over 13,000 of which were pushed in 34 hours with a peak of 2,999 per hour.
  • At least 700 involved accounts belong to legitimate developers, boosting the superficial credibility of the repositories.
  • 97% of sampled commits touched only the README, and 88% pointed the Download button to a ZIP containing SmartLoader.
  • The campaign exploits the AgentBaiting technique: AI agents such as Claude Code can autonomously discover and propose these repositories, extending the attack surface beyond human downloads.

The Mechanism: Why Modifying a README Is Enough

According to the Apiiro report cited by BleepingComputer, 97% of analyzed commits modified only the README file. 88% pointed the "Download" button to a ZIP archive containing SmartLoader. This pattern reveals a modular distribution architecture: the repository acts as a storefront, the payload resides elsewhere, and the commit merely updates the pointer.

SmartLoader is a loader written in LuaJIT that, once executed, retrieves the command-and-control (C2) server address by querying a smart contract deployed on Polygon, the blockchain network. It then establishes persistence via scheduled tasks and downloads the final payload, the StealC infostealer, according to the Island report from July 2026 cited by BleepingComputer.

Multi-location payload distribution is what makes the campaign resistant to takedown. Malicious archives were found in forks, older files, release assets, issue attachments, and separate repositories dedicated to hosting downloads. As Apiiro researchers noted: "Delete one file and the operator can point the bait to a backup copy."

"No one had to create a single new repository. The fleet was already there. It was just re-aimed."
— Apiiro researchers, cited by BleepingComputer

The Visibility Numbers: URLhaus and Traditional Blocklists Are Lagging

71% of the October fleet was absent from URLhaus before the Apiiro report, according to the same source. This has an immediate technical corollary: a domain-level DNS blocklist cannot block a single file on GitHub without blocking the entire platform. The granularity of traditional defense shatters against the reputation and centralization of the service.

The previous July 2026 wave, documented by Island and reported by The Hacker News and BleepingComputer, had already demonstrated the phenomenon's scale: 7,600 repositories, 800 of them disguised as AI skills or MCP (Model Context Protocol) servers, with over 600 listings on public registries such as LobeHub, Glama, MCP.so, and MCP Market. Cumulative downloads across 335 unique assets in 211 repositories reached 14,084,688 events, according to GitHub's public counters. Island specified, however, that this figure includes repeated and automated requests: it is not indicative of actual infection counts.

AgentBaiting: When the Attacker No Longer Needs to Propagate the Malware

The technique dubbed AgentBaiting by Island introduces a propagation vector that does not depend on human curiosity or deception. In controlled tests, Claude Code—Anthropic's AI agent designed to operate in development environments—cloned malicious repositories and downloaded infected files onto the test machine. The agent subsequently detected suspicious indicators before execution, but the autonomous discovery path was completed.

The mechanism is linear: a user asks an AI agent to find a skill or MCP server to extend their workflow capabilities. The agent searches public repositories, finds the FakeGit repository with a well-crafted README, and proposes it. As Oleg Zaytsev of Island observed: "FakeGit didn't have to breach anything. It published convincing repositories, borrowed real developer identities, spread its listings on public registries, and let discovery do the rest."

With AgentBaiting, that discovery no longer requires a person: an agent searching for a skill or MCP server can find the bait, read the attacker's README, and carry out its instructions.

What to Do Now

  • Verify origin before installation: do not rely on a GitHub repository's star or fork count as a trust signal; check the author's historical activity, profile consistency, and presence of verifiable credentials.
  • Inspect download pointers: when a README offers a direct button or link to a ZIP, verify the destination URL before downloading; FakeGit repositories point to domains or paths that do not match the project's standard structure.
  • Audit installed skills and MCP servers: for organizations using AI agents, inventory active extensions and verify their provenance against approved catalogs; do not assume a listing on public registries implies security validation.
  • Rethink threat intelligence policies: DNS blocklists and URLhaus feeds have measurable latency against campaigns that reactivate existing repositories; integrate author provenance checks and anomalous commit patterns into supply chain controls.

The Outstanding Question: Who Controls the Fleet?

The dossier does not clarify how operators gained control of the at least 700 legitimate accounts identified by Apiiro. It is undocumented whether compromise occurs via credential stuffing, targeted phishing, account purchases on illicit markets, or other techniques. This gap has operational consequences: without knowing the acquisition vector, it is difficult to estimate how quickly the fleet could expand beyond the 17,610 repositories already counted.

Attribution of the previous campaign to "Water Kurita" by Trend Micro, cited by Island, referred to an operation involving Lumma Stealer and has not been extended with certainty to the current wave using StealC. No infrastructure overlaps link the current actor to that specific group at this time.

The actual infection scope also remains unknown. The 14 million cumulative downloads recorded on GitHub's public counters include repeated and automated requests, as explicitly warned by Island: they are not verified infections. No estimate is available for the conversion rate from download to payload execution.

Why This Changes the Supply Chain Perimeter

The lesson of the FakeGit reactivation is not merely technical. It is architectural: when a platform distributes content from millions of publishers, ex post content verification is insufficient if the publisher can change content instantly and the payload survives removal of the individual pointer.

Defenses must shift from the question "is this file malicious?" to "does this publisher have the intent and authority to distribute this code?" The second question is harder, requires more data, and cannot be delegated to a hash or a signature. But it is the only one that accounts for a campaign that does not need to create anything new to become operational again.

For developers using AI agents, the consequence is immediate: the trust perimeter expands from the code they write to the code agents choose autonomously. And that perimeter, today, is largely uncharted.

Did FakeGit create new repositories or reuse existing ones?

According to Apiiro researchers, no new repositories were created. The campaign reactivated and modified an existing fleet of 17,610 repositories, primarily updating READMEs to point to payloads still available in forks, release assets, older files, or separate repositories.

Does AgentBaiting mean AI agents are vulnerable?

AgentBaiting exploits the ability of AI agents to autonomously search for skills and MCP servers on public repositories. Island's tests showed that Claude Code can find and download malicious repositories, though it subsequently detected anomalies before execution. The risk is not a vulnerability in the agent software per se, but the combination of automated discovery with repositories that appear legitimate.

Why don't traditional blocklists work against FakeGit?

71% of the fleet was absent from URLhaus before the report. Moreover, a domain-level DNS blocklist cannot block a single file hosted on GitHub without blocking the entire platform. The payload also persists in multiple copies (forks, releases, attachments) that make targeted removal ineffective.

Sources

Information verified against cited sources and current as of publication.

Sources


Sources and references
  1. bleepingcomputer.com
  2. unit42.paloaltonetworks.com
  3. blog.netmanageit.com
  4. thehackernews.com
  5. schema.org