[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fJM1WI7CX0heX1jOtMzjyvJO8d6uSfzexxtJiGIREVP0":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":21,"created_at":22,"published_at":23,"article":24,"tags":28,"podcasts":47},"27d92f6b-23c0-4b8d-adaf-69b46dd5ebf9","fakegit-campaign-uses-17000-malicious-github-repos-to-spread-malware","da738b6f-c8c9-4ae6-a11d-02009916470f","FakeGit Campaign Uses 17,000+ Malicious GitHub Repos to Spread Malware","The FakeGit campaign exploits developer trust in GitHub as a legitimate platform by seeding thousands of malicious repositories designed to mimic real projects, tricking developers into downloading SmartLoader malware. Attackers leverage repository forks and release assets to evade traditional takedown efforts, making the threat persistent and difficult to contain. This matters because developers routinely pull code from GitHub without rigorous vetting, creating a direct path for malware to enter software supply chains and enterprise environments. The shift from StealC to SmartLoader as a dropper demonstrates that adversaries are iterating rapidly, increasing the potential for multi-stage infections across downstream systems.","**Immediate actions:**\n- Audit all third-party code dependencies and GitHub repositories currently used in your build pipelines for signs of tampering or unexpected forks.\n- Block or flag downloads from newly created or low-reputation GitHub repositories at the network or endpoint level.\n\n**Long-term improvements:**\n- Implement a formal Software Composition Analysis (SCA) tool to continuously scan open-source dependencies for malicious or suspicious code.\n- Establish a verified allowlist of approved external repositories and enforce it through CI\u002FCD pipeline policy controls.\n- Train developers to verify repository authenticity by checking star counts, commit history, contributor profiles, and cryptographic signatures before use.\n\n**Detection measures:**\n- Enable endpoint detection rules to flag execution of known dropper behaviors associated with SmartLoader and StealC malware families.\n- Monitor outbound network traffic from developer workstations and build servers for connections to known malicious C2 infrastructure.\n- Integrate threat intelligence feeds covering malicious GitHub repository indicators into your SIEM for proactive alerting.",[12,13,14,15,16,17,18,19,20],"CIS Control 2: Inventory and Control of Software Assets","CIS Control 7: Continuous Vulnerability Management","CIS Control 14: Security Awareness and Skills Training","NIST SP 800-161: Supply Chain Risk Management","NIST SP 800-218: Secure Software Development Framework (SSDF)","NIST CSF DE.CM-3: Personnel activity monitoring","NIST SA-12: Supply Chain Protection","SLSA Framework: Supply-chain Levels for Software Artifacts","OWASP Top 10: A08:2021 Software and Data Integrity Failures","published","2026-10-08T18:20:38.599614+00:00","2026-10-08T18:20:38.285+00:00",{"id":7,"url":25,"slug":26,"title":27},"https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Ffakegit-malware-campaign-returns-with-17-610-malicious-github-repos\u002F","fakegit-malware-campaign-returns-with-17-610-malicious-github-repos-91772b","FakeGit malware campaign returns with 17,610 malicious GitHub repos",[29,35,41],{"id":30,"name":31,"slug":32,"description":33,"color":34},"05757c8d-6b93-4194-b35d-7359e7d33b0e","Vulnerability Management","vulnerability-management","Missing scans, no risk prioritization","#fb923c",{"id":36,"name":37,"slug":38,"description":39,"color":40},"7261eb8f-acd4-4d93-a489-7fdd652ec0ea","Security Awareness","security-awareness","Phishing, social engineering, human error","#22c55e",{"id":42,"name":43,"slug":44,"description":45,"color":46},"f0c2a0af-58aa-4128-87c9-6acd30f2dc48","Supply Chain","supply-chain","Third-party risk, compromised dependencies","#8b5cf6",[]]