ConciseSignal
Following

Attackers use 17,000 GitHub repos to spread SmartLoader malware

Researchers have identified over 17,000 GitHub repositories being used to distribute the SmartLoader malware in a renewed FakeGit campaign. The malicious repos, often using convincing README files with fake download links, deliver SmartLoader, which can distribute additional malware. The campaign escalated rapidly in October, pushing over 13,000 repos in just 34 hours. Security experts say current removal methods miss most malicious repos, letting attackers reactivate quickly.

Why it mattersThe widespread abuse of GitHub repositories by malware campaigns poses a significant supply-chain risk for developers and organizations relying on open-source code. Current defenses are insufficient, allowing attackers to persist with minimal disruption.

Sources covering this

BleepingComputerFakeGit malware campaign returns with 17,610 malicious GitHub repos5:10 PM →

In this story

Concise Signal DailyEnterprise AI, security & business tech.Weekdays, 7am Eastern · Sample issue

More in Cybersecurity