#SmartLoader
FakeGit campaign uses 7,600 GitHub repos to push SmartLoader malware
FakeGit campaign uses 7,600 GitHub repos to push SmartLoader malware
A large-scale operation dubbed 'FakeGit' is pushing SmartLoader and StealC malware through 7,600 malicious GitHub repositories that accumulated more than 14 million downloads. [...]
www.bleepingcomputer.com
July 21, 2026 at 11:22 PM
A large-scale operation dubbed 'FakeGit' is pushing SmartLoader and StealC malware through 7,600 malicious GitHub repositories that accumulated more than 14 million downloads.
FakeGit campaign uses 7,600 GitHub repos to push SmartLoader malware
A large-scale operation dubbed 'FakeGit' is pushing SmartLoader and StealC malware through 7,600 malicious GitHub repositories that accumulated more than 14 million downloads.
www.bleepingcomputer.com
July 21, 2026 at 10:34 PM
FakeGit is using 7,600 GitHub repos and 14M download events to spread SmartLoader and StealC, with fake AI tools and MCP servers luring developers and AI agents. #FakeGit #SmartLoader #StealC
FakeGit campaign uses 7,600 GitHub repos to push SmartLoader malware
A large-scale campaign called FakeGit is using 7,600 malicious GitHub repositories to distribute SmartLoader and StealC, with more than 14 million recorded download events across public release assets. Researchers say the operation uses “agentbaiting” to lure AI agents and developers into trusting fake AI tools, while its roots appear tied to an earlier Lumma Stealer campaign linked to Water Kurita. #FakeGit #SmartLoader #StealC #LummaStealer #WaterKurita
www.hendryadrian.com
July 22, 2026 at 3:45 AM
Trend Micro researchers uncovered a campaign that uses fake GitHub repositories with AI-generated content to distribute SmartLoader, leading to Lumma Stealer and other malicious payloads. www.trendmicro.com/en_us/resear...
March 12, 2025 at 9:34 AM
AgentBaiting Campaign Uses 800 Fake AI Skills and MCP Servers to Deliver SmartLoader Malware
AgentBaiting Campaign Uses 800 Fake AI Skills and MCP Servers to Deliver SmartLoader Malware
Malware operators are increasingly using tools built to extend artificial intelligence as a delivery route. A newly documented campaign called AgentBaiting uses fraudulent AI Skills and Model Context Protocol, or MCP, servers to distribute SmartLoader malware through trusted-looking GitHub projects and public capability catalogs. The operation turns a routine search for an AI integration into a malware risk. Victims can be steered to ZIP archives presented as useful installers, then encouraged to extract and run files that have no connection to the advertised tool. Island researchers identified the campaign while tracking the wider FakeGit operation. Island said in a report shared with Cyber Security News (CSN) that it found about 7,600 malicious repositories created by roughly 6,600 profiles, including more than 800 posing as AI Skills or MCP servers. The campaign’s reach makes it more than a typical developer scam. The AI-focused wave built through March and peaked in April 2026, while malicious projects appeared more than 600 times across public AI registries and catalogs. The scale of the FakeGit operation (Source – Island.io) Researchers also measured more than 14 million downloads from release assets in approximately 200 campaign repositories. AgentBaiting Campaign Uses 800 Fake AI Skills and MCP Servers FakeGit builds credibility through copied projects, lookalike accounts, convincing documentation, and modest engagement numbers. One lure copied the name and positioning of a popular Claude Skills collection, then offered a confirmed SmartLoader ZIP archive as the download. The approach echoes earlier  fake GitHub malware delivery  activity that exploited familiar development workflows to gain trust. The fake Mann1988 – awesome-claude-skills repository imitates the original ComposioHQ – awesome-claude-skills project (Source – Island.io) The lures target both personal and business tasks, including email, messaging, analytics, build systems, cloud services, and developer tools. Their names make downloads appear relevant to daily work instead of suspicious. Island found that 62 malicious repositories were positioned for enterprise or developer-internal use, while nearly two-thirds of MCP lures claimed to connect cloud services, databases, or APIs. A repository named  45d5r/databricks-mcp-server  shows how the infection begins. Its documentation advertises an enterprise integration and provides a download button, but the linked archive contains a command launcher, a renamed LuaJIT-style runtime, and an obfuscated Lua program disguised as a text file. Running the launcher activates the concealed payload rather than installing an MCP server. Related variants can hide their console windows, locate their command server through a value stored in a Polygon smart contract, create scheduled-task persistence, and retrieve encrypted stages from GitHub. The FakeGit attack chain (Source – Island.io) The stages eventually inject StealC into another process, continuing the credential-theft threat covered in reporting on the  StealC infrastructure disruption . AI Discovery Becomes Risk AgentBaiting changes the threat because an AI agent can discover the malicious project without a victim receiving a direct link. During testing, researchers found that Claude Code, Gemini, and ChatGPT could independently surface campaign repositories when asked to find a Skill or MCP server. The results varied, but still exposed a dangerous gap. One tested agent recommended a benign option while also repeating malicious installation instructions as an alternative. In another test, Gemini returned a malicious Walmart MCP repository as its first result, while ChatGPT listed the same repository among public options and highlighted it as a starting point. Public registries can further expand that exposure. Island found more than 600 campaign listings across LobeHub, Glama, MCP.so, and MCP Market, with some reproducing attacker-written documentation and download instructions. That gives malicious repositories another layer of credibility, particularly as  MCP server security concerns  grow around AI integrations that can access business resources. Organizations should rely on a curated and reviewed catalog for Skills, MCP servers, and agent plug-ins instead of unrestricted discovery. Campaign-linked Skills and MCP servers (Source – Island.io) New capabilities should be tested in an isolated environment without browser sessions, cloud credentials, SSH keys, or production data. A supposed AI capability distributed as a Windows ZIP containing a launcher and hidden payload should be rejected. Teams should verify publishers as carefully as projects, since star counts, copied profiles, and registry listings do not establish legitimacy. They should monitor downloads, Git clones, shell commands, and changes to MCP or Skill configurations initiated by agents. Maintaining an inventory of each capability’s repository, commit, version, and package hash can speed investigation. If SmartLoader execution is suspected, security teams should isolate the endpoint and revoke active browser sessions, OAuth grants, API tokens, cloud credentials, and developer credentials. Password resets alone may not be enough because StealC can steal live sessions, browser data, email and remote-access credentials, screenshots, and host details. Indicators of Compromise (IoCs):- Type Indicator Description GitHub repository hfgwyge/yu-ai-agent Fake AI agent repository File name yu-ai-agent-1.0-beta.3.zip SmartLoader package SHA-256 216a2c99fd42c00f9323d8b16dd19f622f7f4778b2b1d7cf07a3de5621f2 Package hash GitHub repository Mann1988/awesome-claude-skills Fake Claude Skills repository File name awesome-skills-claude-3.3.zip SmartLoader package SHA-256 91e5dbfaf45edf25fbc2168f92083e05dfa427afa7633e991392e33cc743 Package hash GitHub repository h4vzz/awesome-ai-agent-skills Fake AI agent Skills repository File name agentaiawesomeskills2.0.zip SmartLoader package SHA-256 498fe8fb806cd0e6685f97fc7d74de769dae5a28cdc821557b7585ad5ad Package hash GitHub repository StanLeyJ03/mcp-for-security Fake security MCP repository File name for-security-mcp-3.3.zip SmartLoader package SHA-256 62744baa8077bb8be237647fd78e3bea2ca0932bf4be3d5618600f971185 Package hash GitHub repository xbim08/awesome-claude-code-plugins Fake Claude Code plug-ins repository File name pluginsclaudeawesomecode2.4.zip SmartLoader package SHA-256 1da8df487d30b988f3c350c065206726aaa13f079a07151cd42ab557999 Package hash GitHub repository DomingosNgongo/walmart-mcp Fake Walmart MCP repository File name mcp-walmart-2.2.zip SmartLoader package SHA-256 c15693106682f2ddb26649cab6e1962a64537627cde4c5d3c79d5a0be8c7 Package hash GitHub repository 45d5r/databricks-mcp-server Fake Databricks MCP repository File name serverdatabricksmcp1.6.zip SmartLoader package SHA-256 66afc7d87d10dbe392898c4e5c613e0442fabb396415c2bef3a5ef2ac758 Package hash GitHub repository MauManto/jenkins-mcp-server Fake Jenkins MCP repository File name mcp-server-jenkins-3.2.zip SmartLoader package SHA-256 a33f40cab1ab7f971d3464af3e7595918107332b9e83342007571842b9e Package hash GitHub repository waynestimulative605/docker-mcp-gateway Fake Docker MCP gateway repository File name gateway-docker-mcp-v1.6-alpha.5.zip SmartLoader package SHA-256 3c858facbad66f5479e2c4add171421dc1b6488b36f33e7cff073aba585 Package hash GitHub repository lucaducapuca/alibabacloud-bigdata-skills Fake Alibaba Cloud Skills repository File name alibabacloud-skills-bigdata-v1.7.zip SmartLoader package SHA-256 fc1278f419e611bf40ca414099bfd9ad98a31ffb054371e8cb65a84849b Package hash Note:   IP addresses and domains are intentionally defanged (e.g.,  [.] ) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM . Strengthen Your SOC by Accelerating Threat Detection & Rapid Investigations. ->  Integrate ANY.RUN With Your SOC  Now . The post AgentBaiting Campaign Uses 800 Fake AI Skills and MCP Servers to Deliver SmartLoader Malware appeared first on Cyber Security News .
cybersecuritynews.com
July 21, 2026 at 12:42 PM
SmartLoader Attack Uses Trojanized Oura MCP Server to Deploy StealC
Infostealer
thehackernews.com/2026/02/smar...
SmartLoader Attack Uses Trojanized Oura MCP Server to Deploy StealC Infostealer
SmartLoader campaign spreading StealC via a trojanized Oura MCP server using fake GitHub forks to steal credentials and crypto funds.
thehackernews.com
February 18, 2026 at 12:03 PM
FakeGit campaign uses 7,600 GitHub repos to push SmartLoader malware

A large-scale operation dubbed 'FakeGit' is pushing SmartLoader and StealC malware through 7,600 malicious GitHub repositories that accumulated more than 14 million downloads. [...]
#hackernews #news
FakeGit campaign uses 7,600 GitHub repos to push SmartLoader malware
A large-scale operation dubbed 'FakeGit' is pushing SmartLoader and StealC malware through 7,600 malicious GitHub repositories that accumulated more than 14 million downloads. [...]
www.bleepingcomputer.com
July 22, 2026 at 9:16 PM
FakeGit uses trojanized GitHub Skills and MCP servers to deliver SmartLoader malware and StealC, with AI agents tricked into discovering and executing attacks automatically.
Save What Matters
Curate Feeds | Make Collections | Customize Email Briefs
briefly.co
July 20, 2026 at 7:55 PM
AI-Powered Deception: Fake GitHub Repositories Spread SmartLoader and Lumma Stealer

Attackers are using AI-generated content to disguise malicious repositories, tricking developers into downloading malware.

securityonline.info/ai-powered-d...
AI-Powered Deception: Fake GitHub Repositories Spread SmartLoader and Lumma Stealer
Learn how SmartLoader is being spread through deceptive GitHub repositories, targeting users with gaming and software tools.
securityonline.info
March 13, 2025 at 7:46 AM
SmartLoader hackers clone Oura MCP project to spread StealC malware
SmartLoader hackers clone Oura MCP project to spread StealC malware
Hackers used a fake Oura MCP server to trick users into downloading malware that installs the StealC info-stealer.
securityaffairs.com
February 17, 2026 at 7:34 PM
SmartLoader Malware via Github Repository as Legitimate Projects Infection Users Computer
SmartLoader Malware via Github Repository as Legitimate Projects Infection Users Computer
Cybersecurity researchers have uncovered a sophisticated malware distribution campaign utilizing GitHub repositories disguised as legitimate software projects. The SmartLoader malware has been strategically deployed across multiple repositories, capitalizing on users’ trust in the popular code-sharing platform to infiltrate systems worldwide. The malicious campaign targets users searching for game cheats, software cracks, and automation tools by positioning fraudulent repositories at the top of search results. SmartLoader distribution site being displayed at the top of Google search results (Source – ASEC) These repositories appear authentic, complete with professionally crafted README files, project documentation, and realistic file structures that mirror legitimate open-source projects. The threat actors behind this operation have demonstrated remarkable attention to detail, making their malicious repositories virtually indistinguishable from genuine software projects. Each compromised repository contains carefully constructed compressed files hosting the SmartLoader payload. When users download and execute these files, they unknowingly initiate a multi-stage infection process that establishes persistent access to their systems. ASEC analysts identified this widespread distribution method as particularly concerning due to its exploitation of developer and gaming communities’ trust in GitHub as a reliable source for software tools. Technical Infection Mechanism and Payload Deployment The SmartLoader infection process begins when users execute the Launcher.cmd file, which serves as the initial attack vector. This malicious batch file loads an obfuscated Lua script through luajit.exe , a legitimate Lua interpreter that has been weaponized for malicious purposes. Files inside the compressed file (Source – ASEC) The malware package consists of four core components: java.exe (the legitimate Lua loader), Launcher.cmd (malicious batch file), lua51.dll (Luajit runtime interpreter), and module.class (obfuscated Lua script). Once activated, SmartLoader establishes persistence by copying essential files to the %AppData%\ODE3 directory and registering itself in the Windows Task Scheduler as “SecurityHealthService_ODE3”. The malware immediately captures screenshots and system information, transmitting this data to command-and-control servers through Base64-encoded communications. The malware’s most dangerous capability lies in its role as a loader for additional payloads. Analysis revealed that SmartLoader downloads and executes secondary malware including Rhadamanthys infostealer, which targets sensitive information from email clients, FTP applications, and online banking services. The malware performs process injection into legitimate Windows processes such as openwith.exe , dialer.exe , and dllhost.exe to evade detection. Communication with C2 servers occurs through encrypted channels, with the malware receiving JSON-formatted commands containing configuration parameters and task lists. This infrastructure allows threat actors to dynamically update malware behavior and deploy additional payloads based on the infected system’s characteristics. This campaign highlights the critical importance of verifying software sources and examining repository credibility, commit history, and author authenticity before downloading any GitHub-hosted applications, particularly those related to game modifications or software cracks . Boost your SOC and help your team protect your business with free top-notch threat intelligence:  Request TI Lookup Premium Trial . The post SmartLoader Malware via Github Repository as Legitimate Projects Infection Users Computer appeared first on Cyber Security News .
cybersecuritynews.com
August 14, 2025 at 1:20 PM
Fake AI Skills and MCP servers trick Claude, Gemini and ChatGPT into recommending malware installs. https://intel.threadlinqs.com/threat/TL-2026-1595 #ThreatIntel #SmartLoader #Stealc #Lumma
July 21, 2026 at 10:57 PM
SmartLoader Attack Uses Trojanized Oura MCP Server to Deploy StealC Infostealer #cybersecurity #hacking #news #infosec #security #technology #privacy thehackernews.com/20...
February 17, 2026 at 1:44 PM
1/ ASEC has recently discovered the massive distribution of SmartLoader malware through GitHub repositories.

Upon searching for keywords such as game hacks, software crack, and automation tool,
August 17, 2025 at 7:11 PM
AI-Assisted Fake GitHub Repositories Fuel SmartLoader and LummaStealer Distribution

The Rise of AI-Driven Cyber Threats Cybercriminals are evolving their tactics, now leveraging AI-generated fake GitHub repositories to distribute malware. A recent campaign uncovered by security researchers reveals…
AI-Assisted Fake GitHub Repositories Fuel SmartLoader and LummaStealer Distribution
The Rise of AI-Driven Cyber Threats Cybercriminals are evolving their tactics, now leveraging AI-generated fake GitHub repositories to distribute malware. A recent campaign uncovered by security researchers reveals how threat actors are disguising malicious software as game cheats, cracked software, and system tools, tricking unsuspecting users into downloading harmful payloads. This campaign specifically delivers SmartLoader, which then installs Lumma Stealer, a notorious information-stealing malware used for credential theft, cryptocurrency wallet hijacking, and other malicious activities.
undercodenews.com
March 11, 2025 at 7:25 AM
this is the specific trojan. it's crazy i wouldntve found it if it didn't visibly run ~\AppData\Local\ODE3.exe in a blank terminal window and i didnt randomly decide to google it one day instead of continuing to assume it was some legit program i downloaded
Distribution of SmartLoader Malware via Github Repository Disguised as a Legitimate Project - ASEC
Distribution of SmartLoader Malware via Github Repository Disguised as a Legitimate Project ASEC
asec.ahnlab.com
August 30, 2025 at 3:54 PM
🚨 AgentBaiting abuses fake AI tools and MCP servers to spread SmartLoader and StealC malware, making AI supply chain security more critical than ever.

🌐 threatexposure.io/blog/attack-...

#AttackSurfaceManagement #AISecurity #SupplyChainSecurity #StealC #SmartLoader

Try it for FREE. 🆓
Supply Chain Cybersecurity | Online Reports - Threatexposure.io
Reduce cyber supply chain risk with full reports for third-party risk management, continuous vendor monitoring, security ratings, and threat intelligence.
threatexposure.io
July 24, 2026 at 7:17 AM
Your AI agent trusts every skill it loads. NVIDIA just shipped a scanner that doesn't. https://intel.threadlinqs.com/threat/TL-2026-1828 #ThreatIntel #CVE_2025_59536 #CVE_2026_21852 #SmartLoader
August 3, 2026 at 6:00 AM
The #SmartLoader #malware family uses #Polygon smart contracts to obtain their command & control server, so that means it's rather easy to track their infraestructure by monitoring changes to the smart contracts. E.g.: polygonscan.com/address/0x18...
Address: 0x1823A9a0...a4474bAdc | PolygonScan
Contract: Unverified | Balance: $0 across 0 Chains | Transactions: 7 | As at Jan-26-2026 03:42:00 PM (UTC)
https://polygonscan.com/address/0x1823A9a0Ec8e0C25dD957D0841e3D41a4474bAdc#events#events
January 26, 2026 at 3:46 PM