Skip to content
Agentic AI Security Hub
Back to feed
Severity: HighIncidentSupply chain

Mass GitHub repository campaign masquerading as AI and MCP projects to distribute SmartLoader malware

Global

Live intelligence. Items are aggregated from public sources and summarised automatically. Always verify against the linked source before acting.

Researchers identified approximately 7,600 malicious GitHub repositories as part of the FakeGit campaign, with over 800 specifically impersonating AI tools and Model Context Protocol servers. The campaign leverages cloned legitimate projects, spoofed developer profiles, and deceptive documentation to distribute SmartLoader malware to developers seeking integrations.

What to do

Validate all third-party AI tools and MCP server dependencies against official sources and verify repository authenticity before integration.

#FakeGit campaign#GitHub supply chain#MCP targeting#AI impersonation#SmartLoader#malware distribution