Attackers use 17,000 GitHub repos to spread SmartLoader malware
Researchers have identified over 17,000 GitHub repositories being used to distribute the SmartLoader malware in a renewed FakeGit campaign. The malicious repos, often using convincing README files with fake download links, deliver SmartLoader, which can distribute additional malware. The campaign escalated rapidly in October, pushing over 13,000 repos in just 34 hours. Security experts say current removal methods miss most malicious repos, letting attackers reactivate quickly.
- Over 17,000 malicious repos linked to FakeGit campaign
- SmartLoader malware distributed via deceptive README links
- Attackers reactivated dormant repos to scale operations
- Removal efforts fail to block most malicious content
- Experts recommend verifying repository owners and sources
Sources covering this
In this story
More in Cybersecurity
US and allies disrupt Chinese hacking tools targeting infrastructure
US authorities and international partners have seized domains and tools used by China's Integrity Technology Group to support…
AI-powered attacks target South Korean banks
A cyberattack campaign targeting South Korean financial institutions used AI-based tools to steal personal data, CrowdStrike reported.
Google promotes passkeys as a password alternative
Google is highlighting passkeys as a faster and safer alternative to traditional passwords for its accounts.
Malware found pre-installed on low-cost Android phones
Researchers have discovered malware embedded in the firmware of inexpensive Android smartphones, allowing attackers to remotely install…