FakeGit Malware Campaign Resurfaces with 17,610 Malicious GitHub Repos
Original source
FakeGit malware campaign returns with 17,610 malicious GitHub repos
BleepingComputer →The FakeGit malware campaign has reactivated, distributing the SmartLoader malware through over 17,610 fake GitHub repositories. These repositories use deceptive README files with download buttons that lead to ZIP archives containing the initial payload. The campaign resurfaced on October 4, with over 13,000 repositories pushed in just 34 hours. The majority of these repositories modify only the README file to point to the malicious ZIP. The campaign’s persistence is attributed to the difficulty in removing all malicious repositories and the ability to reuse existing ones by changing download links. Researchers advise verifying repository owners and using official sources for AI-related installations.
Read the full article
Continue reading at BleepingComputer →This is an AI-generated summary. Read the original for the full story.