Find notable cyber news and cases, enriched with sources, timelines, and signals.

FakeGit GitHub lure campaign

Campaign
First reported
Last updated
Happening score
H score 32
2 unique sources, 2 articles

Summary

Hide ▲

The FakeGit campaign is a GitHub lure operation using nearly 7,600 malicious repositories to distribute SmartLoader and StealC through copied projects, lookalike profiles, and convincing READMEs. More than 800 repositories posed as AI Skills or MCP servers, and Island said the campaign later expanded to more than 1,400 AI-related repositories and more than 600 listings in public registries and catalogs. Researchers also reported 14,084,688 cumulative download events across 335 Release assets in 211 GitFake repositories, while noting those counts are not infections. The operation used AgentBaiting to increase visibility to AI agents, and controlled tests showed ChatGPT, Gemini, Claude, and Claude Code could surface or clone malicious repositories before stopping or downloading files in limited testing.

Related Happenings

Operation Muck and Load GitHub malware-delivery cluster

Malware Activity
H score29 First: 23.07.2026 14:28 Last: 23.07.2026 14:28 Sources 1

About this happening: Operation Muck and Load has expanded a GitHub repository network into a malware-delivery channel, putting 200 repositories across 190 accounts behind the spread of W...

North Korean Contagious Interview PolinRider supply-chain campaign

Campaign
H score51 First: 04.07.2026 14:17 Last: 04.07.2026 14:17 Sources 1

About this happening: The Contagious Interview / PolinRider campaign is still active, with 108 unique packages and browser extensions published across npm, Packagist, Go, and Google Chrome....

PolinRider GitHub supply-chain campaign delivering BeaverTail and InvisibleFerret

Campaign
H score9 First: 23.06.2026 11:54 Last: 23.06.2026 11:54 Sources 1

About this happening: A North Korean supply-chain campaign dubbed PolinRider is injecting obfuscated JavaScript into compromised GitHub repositories, exposing developers to staged malware d...

Rust-based clipboard hijacker spreading via fake crypto tools

Malware Activity
H score13 First: 18.06.2026 18:00 Last: 18.06.2026 18:00 Sources 1

About this happening: A Rust-based clipboard hijacker is spreading through fake crypto tools and silently replacing copied wallet addresses, putting Windows and macOS users at risk of theft...

Ghost Networks crypto-clipper promotion campaign

Campaign
H score15 First: 17.06.2026 21:14 Last: 17.06.2026 21:14 Sources 1

About this happening: Unknown threat actor is running an active June 2026 campaign that fakes legitimacy to distribute a Rust-based clipboard hijacker. The operation uses bogus GitHub sta...

Timeline

  1. 22.07.2026 01:34 1 articles · 12d ago

    FakeGit expands into AI registries with AgentBaiting lures

    Campaign Scope Update

    Island said FakeGit expanded into more than 1,400 repositories tied to AI tools, agents, and workflows, while public registries and catalogs surfaced more than 600 skills and MCP server listings linked to the campaign. The lure set used AgentBaiting to increase visibility to AI agents, and controlled tests showed ChatGPT, Gemini, Claude, and Claude Code could surface or clone malicious repositories and download files before stopping.

    Show sources
  2. 20.07.2026 21:23 2 articles · 13d ago

    Researchers uncover FakeGit campaign flooding GitHub with malicious AI Skill and MCP server repositories

    Initial Disclosure

    Researchers identified nearly 7,600 malicious GitHub repositories tied to FakeGit, with more than 800 posing as AI Skills or Model Context Protocol (MCP) servers to deliver SmartLoader through copied projects, lookalike developer profiles, convincing READMEs, and malicious ZIP files. The campaign had also recorded more than 14 million downloads across GitHub Release assets in about 200 campaign repositories, and its lure set was built to deceive both users and AI agents into following attacker-controlled installation steps that can lead to SmartLoader and StealC.

    Show sources