Full Report
More than 17,000 fake repositories on GitHub are distributing the SmartLoader malware after the FakeGit campaign reactivated earlier this month to push the StealC infostealer. [...]
Analysis Summary
# Tool/Technique: FakeGit Campaign (SmartLoader Distribution)
## Overview
FakeGit is an automated, large-scale malware distribution campaign that leverages thousands of fraudulent or compromised GitHub repositories. The campaign uses social engineering—primarily through professional-looking README files—to trick developers and AI researchers into downloading "SmartLoader," which subsequently deploys information stealers like StealC.
## Technical Details
- **Type:** Malware Distribution Campaign / Downloader
- **Platform:** Windows (Targeting developers, AI practitioners)
- **Capabilities:** Automation of repository creation/updates, social engineering, payload delivery, evasion of repository takedowns.
- **First Seen:** Identified as "FakeGit" in July 2024; active since at least January 2024.
## MITRE ATT&CK Mapping
- **[TA0001 - Initial Access]**
- [T1195.002 - Supply Chain Compromise: Compromise Software Supply Chain]
- [T1566.003 - Phishing: Spearphishing via Service]
- **[TA0002 - Execution]**
- [T1204.002 - User Execution: Malicious File]
- **[TA0005 - Defense Evasion]**
- [T1553.004 - Subvert Trust Controls: Install Root Certificate (potential)]
- [T1027 - Obfuscated Files or Information]
- **[TA0011 - Command and Control]**
- [T1105 - Ingress Tool Transfer]
## Functionality
### Core Capabilities
- **Mass Scale Repository Management:** Capable of pushing over 13,000 repositories in under 34 hours, peaking at nearly 3,000 repos per hour.
- **Social Engineering (Lures):** Mimics legitimate AI skills, Model Context Protocol (MCP) servers, and popular software tools.
- **README Poisoning:** 97% of campaign commits involve modifying the `README.md` file to include a "Download" button.
- **Payload Delivery:** Distributes a ZIP archive containing **SmartLoader**, which acts as a bridge to pull down final stage payloads (e.g., StealC).
### Advanced Features
- **Persistence via Redundancy:** Utilizes forks, older file versions, release assets, and issue attachments to host payloads, ensuring that if one URL is blocked, the attacker can quickly "re-aim" the lure to a spare copy.
- **Account Hijacking:** Leverages at least 700 legitimate developer accounts alongside thousands of throwaway accounts to lend credibility to malicious repositories.
## Indicators of Compromise
- **File Names:** Commonly packaged as ZIP archives (e.g., `Project_Name.zip`, `MCP_Server_Package.zip`).
- **Network Indicators:**
- `github[.]com/[AccountName]/[RepoName]` (Path-based indicators vary widely).
- Check for unusual outbound traffic to known StealC C2 domains (Refer to specific StealC intelligence for current IPs).
- **Behavioral Indicators:**
- Fast-paced creation of multiple GitHub repositories with identical README structures.
- Execution of unsigned or suspiciously named loaders (SmartLoader) originating from the Downloads folder/browser-extracted directories.
## Associated Threat Actors
- **FakeGit Operator:** (Specific group name currently tracking under the campaign moniker "FakeGit").
## Detection Methods
- **Signature-based detection:** Identify the hash of the SmartLoader executable contained within the downloaded ZIPs.
- **Behavioral detection:**
- Monitor for processes attempting to download and execute secondary payloads immediately after a GitHub ZIP extraction.
- Heuristic detection for README files containing high-contrast "Download" buttons pointing to external or non-source-code assets.
- **Audit Logs:** Monitor GitHub audit logs for rapid, automated repository creation or mass README modifications across an organization's developer accounts.
## Mitigation Strategies
- **Verification:** Always verify a repository's owner, star count (watch for fake stars), and creation date before downloading assets.
- **Official Sources:** Use official registries (e.g., PyPI, npm) or verified vendor repositories for AI skills and MCP servers rather than random GitHub search results.
- **Account Security:** Enforce the use of **Passkeys** or hardware MFA to prevent the account hijacking used to fuel this fleet.
- **Session Management:** If SmartLoader is executed, revoke all active GitHub sessions and Personal Access Tokens (PATs) immediately.
## Related Tools/Techniques
- **SmartLoader:** The primary stage-one loader used in this campaign.
- **StealC:** The primary information stealer currently being pushed by FakeGit.
- **Stargazer Labyrinth:** A similar technique involving the "ghost" distribution of malware via GitHub.