FakeGit Campaign Uses 7,600 GitHub Repositories to Spread SmartLoader Malware

2026-07-21T01:24:04Z7ffcb90de49b1736de6efac8f32618aa7bea70ef99e16f29f7dbf77a7126f798
AI-assisted-attacksC2botnetcloud-credentialscode-signing-theftcredential-theftespionagemalwarephishingsoftware-vulnerabilitiessupply-chainzero-day

What happened

A large batch of high-impact security stories: a widespread FakeGit campaign (≈7,600 malicious GitHub repos) distributing SmartLoader; multiple supply-chain abuse incidents (malicious RubyGems and npm/Vite packages, SleeperGem, ViteVenom); exposed delivery infrastructure revealing AI-assisted phishing/WebDAV lures and droppers; espionage implants (HollowGraph using Microsoft 365 calendar events for C2/exfiltration, GoSerpent, OtterCookie-aligned payloads); credential/secret theft campaigns (ACR Stealer, NadMesh botnet harvesting cloud keys and Kubernetes tokens); several serious product flaws—

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
7ffcb90de49b1736de6efac8f32618aa7bea70ef99e16f29f7dbf77a7126f798
Enrichment time
2026-07-21T01:24:04Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · FakeGit Campaign Uses 7,600 GitHub Repositories to Spread SmartLoader Malware · Baitaphish