FakeGit Campaign Uses 7,600 GitHub Repositories to Spread SmartLoader Malware
2026-07-21T01:24:04Z•7ffcb90de49b1736de6efac8f32618aa7bea70ef99e16f29f7dbf77a7126f798
AI-assisted-attacksC2botnetcloud-credentialscode-signing-theftcredential-theftespionagemalwarephishingsoftware-vulnerabilitiessupply-chainzero-day
What happened
A large batch of high-impact security stories: a widespread FakeGit campaign (≈7,600 malicious GitHub repos) distributing SmartLoader; multiple supply-chain abuse incidents (malicious RubyGems and npm/Vite packages, SleeperGem, ViteVenom); exposed delivery infrastructure revealing AI-assisted phishing/WebDAV lures and droppers; espionage implants (HollowGraph using Microsoft 365 calendar events for C2/exfiltration, GoSerpent, OtterCookie-aligned payloads); credential/secret theft campaigns (ACR Stealer, NadMesh botnet harvesting cloud keys and Kubernetes tokens); several serious product flaws—
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- 7ffcb90de49b1736de6efac8f32618aa7bea70ef99e16f29f7dbf77a7126f798
- Enrichment time
- 2026-07-21T01:24:04Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.