Mmastodon TechnologyCybersecurity first seen 4 h ago, last 4 h ago, peak #10
FakeGit campaign returns with 17,000 malicious GitHub repos spreading StealC
Original: 🤖 FakeGit campaign is back: 17,610 malicious GitHub repos distribute SmartLoader, which drops the StealC infostealer. Re
A revived FakeGit operation has flooded GitHub with 17,610 malicious repositories posing as cracked or pirated software. Victims who download and run the fake tools receive the SmartLoader payload, which deploys the StealC infostealer to harvest passwords and other sensitive data. Security researchers warn developers and regular users alike to avoid unofficial software downloads on the platform.
Why now: The scale of the renewed campaign and the risk to anyone downloading software from GitHub is prompting fresh security warnings.
GitHubFakeGitSmartLoaderStealC
Evidence
- 🤖 FakeGit campaign is back: 17,610 malicious GitHub repos distribute SmartLoader, which drops the StealC infostealer. Repos pose as cracked/pirated software to lure developers into running the payload. 🔗 https://www. bleepingcomputer.com/news/secu… · cloud@infosec.exchange · 1
API: https://socialmediatrends-api.osmike.com/v1/trends/1513913