14,084,688 — that is the cumulative count recorded by GitHub’s public download counters for 335 release assets tied to the FakeGit operation, a campaign that researchers say spread SmartLoader and StealC through roughly 7,600 malicious repositories.
Scope of the FakeGit operation
Security researchers at Island describe FakeGit as a large-scale, long-running campaign that used 7,600 malicious GitHub repositories to push SmartLoader and the StealC information stealer. The operation mimicked well-known consumer and enterprise tools — including Gmail, WhatsApp, Databricks, Jenkins, and Docker — and baked convincing artifacts into the projects: copied descriptions, fabricated star and fork counts, and real developer account names. README files directed visitors to ZIP archives presented as installers or project releases, but those ZIPs contained disguised Lua payloads that trigger SmartLoader.
AgentBaiting: using AI discovery to amplify reach
Island researchers identified a deliberate technique they call “AgentBaiting.” The goal is to make malicious repositories more visible to AI agents and to increase the chance an agent will recommend a repository or follow its installation instructions. Island’s tests found ChatGPT, Gemini, and Claude surfaced malicious repositories when given related tasks; in some cases the agents relayed the README installation instructions as if they were legitimate guidance. The campaign also placed links into public AI registries and catalogs — researchers found more than 600 listings for skills and MCP servers tied to FakeGit — increasing discoverability. Examples of registries and marketplaces that contained listings include LobeHub, Glama, MCP.so, and MCP Market.
How SmartLoader and StealC operate
According to Island’s analysis, the attack chain typically begins with a README-driven download of a ZIP archive that contains a Lua payload. That payload launches SmartLoader, which then establishes persistence by creating scheduled tasks. SmartLoader resolves its command-and-control address via a Polygon smart contract, fetches additional encrypted stages from GitHub, and ultimately delivers the StealC information stealer. Researchers noted the FakeGit campaign appears to continue an earlier operation that used Lumma Stealer and has been linked by Trend Micro to a tracked actor named “Water Kurita.”
Impact metrics, test results, and caveats
Island reported that GitHub’s public download counters for 335 unique release assets across 211 GitFake repositories showed 14,084,688 cumulative download events. Oleg Zaytsev, Lead Security Researcher at Island, clarified that the figure “included repeated requests and automated activity, so it should not be interpreted as infections.” Island’s broader tallies also show the operation produced more than 1,400 repositories related to AI tools, agents, and workflows that linked to SmartLoader or StealC downloads; in March the group introduced an AI focus and in April created roughly 300 AI-linked GitHub repositories.
In controlled tests, Island told BleepingComputer that Claude Code cloned malicious repositories and downloaded the malicious files onto the test machine but then detected suspicious indicators and stopped before execution. The researchers emphasized that those tests were limited and were not designed to establish a reliable detection rate; they said the outcomes cannot be interpreted as conclusive proof that coding agents will consistently detect the threat during execution.
What this means for security teams, developers, and open-source maintainers
- Security teams: Island recommends maintaining approved catalogs of skills and MCP servers, testing new capabilities in isolated environments, and verifying publishers and repositories independently. Where SmartLoader execution is suspected, Island advises rotating all secrets on impacted environments immediately.
- Developers and integrators: Because FakeGit repositories included convincing project documentation and real developer account names, teams should validate the provenance of tools before following README instructions or downloading binaries from unfamiliar releases.
- Open-source maintainers and registry operators: The campaign’s insertion of listings into public catalogs — researchers could not determine whether those listings were submitted manually or indexed automatically — shows how registry integrity can materially affect discoverability and credibility of malicious content.
FakeGit combines low-cost deception — forged stars, copied descriptions, plausible READMEs — with a new vector: trying to manipulate AI discovery and recommendation behavior. Island’s data shows the approach can produce large download counts and penetrate public catalogs, even if those counters do not equate to infections. The remaining question is whether AI agents and catalog operators will reliably inoculate themselves against this kind of “AgentBaiting” before more automated discovery turns into automated compromise.
Source: BleepingComputer — FakeGit campaign uses 7,600 GitHub repos to push SmartLoader malware




