FakeGit Campaign Uses 7,600 GitHub Repositories to Spread SmartLoader Malware
2026-07-21T07:24:10Z•51f9b110a69994b4b6586932e2884b74043733d3ca396d6d72352c5d0c417f95
ACR-StealerClickFixDigiCertFakeGitHollowGraphHuggingFace-breachMicrosoft-365NadMeshRubyGemsSleeperGemSmartLoaderViteVenomWebDAVautonomous-agentbotnetcalendar-C2code-signing-theftcredential-theftexfiltrationexposed-ai-servicesinfostealermalwarenpmsupply-chainwp2shell-WordPress-RCE','NGINX-CVE-2026-42533','7-Zip-CVE-2026-1
What happened
A batch of high-impact security stories: a large FakeGit campaign (≈7,600 malicious GitHub repos) distributing SmartLoader; an exposed WebDAV delivery server revealing an AI-assisted phishing toolkit and live infostealer campaigns; HollowGraph espionage implant using hijacked Microsoft 365 calendar events (dated 2050) for C2 and exfiltration; multiple supply‑chain incidents (SleeperGem malicious RubyGems, ViteVenom npm packages, malicious GitHub ZIPs, and code‑signing certificate theft linked to a GoldenEyeDog subgroup); and botnets hunting exposed AI services to harvest cloud keys (NadMesh).
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- 51f9b110a69994b4b6586932e2884b74043733d3ca396d6d72352c5d0c417f95
- Enrichment time
- 2026-07-21T07:24:10Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.