{"id":245083,"date":"2026-10-09T02:36:52","date_gmt":"2026-10-09T07:36:52","guid":{"rendered":"https:\/\/lifeboat.com\/blog\/2026\/10\/fakegit-malware-campaign-returns-with-17610-malicious-github-repos"},"modified":"2026-10-09T02:36:52","modified_gmt":"2026-10-09T07:36:52","slug":"fakegit-malware-campaign-returns-with-17610-malicious-github-repos","status":"publish","type":"post","link":"https:\/\/lifeboat.com\/blog\/2026\/10\/fakegit-malware-campaign-returns-with-17610-malicious-github-repos","title":{"rendered":"FakeGit malware campaign returns with 17,610 malicious GitHub repos"},"content":{"rendered":"<p><a class=\"aligncenter blog-photo\" href=\"https:\/\/lifeboat.com\/blog.images\/fakegit-malware-campaign-returns-with-17610-malicious-github-repos.jpg\"><\/a><\/p>\n<p>More than 17,000 fake repositories on GitHub are distributing the SmartLoader malware after the FakeGit campaign reactivated earlier this month to push the StealC infostealer.<\/p>\n<p>The operator uses mostly throwaway accounts, but researchers identified at least 700 accounts that appear to belong to legitimate developers.<\/p>\n<p>The malicious repositories use convincing README instructions with a download button pointing to a ZIP archive containing the initial payload, SmartLoader, that is used to distribute other malware.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>More than 17,000 fake repositories on GitHub are distributing the SmartLoader malware after the FakeGit campaign reactivated earlier this month to push the StealC infostealer. The operator uses mostly throwaway accounts, but researchers identified at least 700 accounts that appear to belong to legitimate developers. The malicious repositories use convincing README instructions with a download [\u2026]<\/p>\n","protected":false},"author":427,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[34],"tags":[],"class_list":["post-245083","post","type-post","status-publish","format-standard","hentry","category-cybercrime-malcode"],"_links":{"self":[{"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/posts\/245083","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/users\/427"}],"replies":[{"embeddable":true,"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/comments?post=245083"}],"version-history":[{"count":0,"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/posts\/245083\/revisions"}],"wp:attachment":[{"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/media?parent=245083"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/categories?post=245083"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/tags?post=245083"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}