FakeGit malware campaign reactivates, distributing SmartLoader via 17,610 malicious GitHub repositories
Threat actors return with updated infrastructure targeting developers and software users

Key Takeaways
- The FakeGit campaign has reactivated in October 2026, distributing SmartLoader malware through over 17,610 malicious GitHub repositories.
- The repositories impersonate legitimate software projects to deceive developers and users.
- SmartLoader is understood to function as a malware loader, potentially delivering additional payloads such as infostealers.
- The exact victim count and specific targeted industries have not been specified in the reporting.
Related Security News

Unpatched AhsayCBS Vulnerabilities Exploited in the Wild to Deploy Webshells and Cryptominers
Threat actors are exploiting two unpatched vulnerabilities in the AhsayCBS backup management platform. One vulnerability is rated critical severity and another medium severity. The exploitation has been observed in the wild and is being used to deploy webshells for persistent access and cryptocurrency miners for monetization. No patches are currently available, and the vulnerabilities remain unpatched. Affected organizations using AhsayCBS for backup management are at risk of persistent compromise and resource misuse.




