FakeGit Campaign Uses 7,600 GitHub Repositories to Spread SmartLoader Malware
Cybersecurity researchers have discovered nearly 7,600 malicious GitHub repositories, out of which more than 800 pose as artificial intelligence (AI) skills or Model Context Protocol (MCP) servers to deliver a malware family known as SmartLoader as part of an ongoing camp…
Intelligence analysis by Llama

FakeGit uses copied projects, lookalike developer profiles, convincing READMEs, and malicious ZIP files to deliver SmartLoader malware. The end goal of these attacks is to leverage the access afforded by SmartLoader to establish persistence and push secondary payloads, such as StealC, an information stealer capable of harvesting a wide range of data from compromised systems.
Imagine you're using a tool to help you with a task, but the tool is actually a trick to get you to download a bad program. This is what's happening with the FakeGit campaign. The bad guys are creating fake tools that look real, but actually contain a virus. The virus can then steal your information or do other bad things.
Analysis
A $60B Vote of Confidence
The FakeGit campaign is a significant threat to the security of GitHub users, with nearly 7,600 malicious repositories discovered so far. These repositories are designed to meet demand already forming around AI capabilities, borrowing the names and workflows of familiar consumer and enterprise tools. The counterfeit repositories serve as a conduit for a ZIP archive, which is then used to trigger a LuaJIT loader chain, leading to the execution of an obfuscated Lua script responsible for dropping SmartLoader. Then the loader proceeds to deploy StealC.
Why Cursor?
AgentBaiting escalates this threat further, as it opens the door to a scenario where an AI agent can be baited to discover a FakeGit repository without having to supply a malicious link. The technique once again demonstrates how routine AI-assisted discovery operations can be turned into an alley for malicious code execution, a problem that gets exacerbated when the malicious skills or MCP servers are listed on public registries like LobeHub, Glama, MCP.so, and MCP Market, giving them a false sense of legitimacy.
The Road Ahead
To counter the threat, it's advised to build a catalog of reviewed Skills, MCP servers, and agent plugins, evaluate new agent capabilities in a sandboxed environment first before broader rollout, verify both the publisher and the project to ensure credibility, and monitor agentic pathways. The defenses that matter are the ones that interrupt this chain before execution.
Key points
- Nearly 7,600 malicious GitHub repositories discovered
- Over 800 repositories pose as AI skills or MCP servers
- Malware family known as SmartLoader used to deliver secondary payloads
- AgentBaiting technique allows AI agents to discover malicious repositories without human intervention
- Public registries like LobeHub, Glama, MCP.so, and MCP Market used to give malicious skills and MCP servers a false sense of legitimacy
If the security community can develop effective defenses against AI-powered malware, it could lead to a significant reduction in the number of successful attacks. Additionally, the development of more robust verification processes for AI skills and MCP servers could help to prevent the spread of malware.
If the FakeGit campaign is not addressed effectively, it could lead to a significant increase in the number of successful attacks, resulting in the theft of sensitive information and potentially even financial losses.



