VulnWatch VulnWatch
← Back to dashboard
Unknown rss_thehackernews · rss_0823fe2e9d3257827a981a80c0c54ee0

FakeGit Campaign Uses 7,600 GitHub Repositories to Spread SmartLoader Malware

Published Jul 20, 2026

Cybersecurity researchers have discovered nearly 7,600 malicious GitHub repositories, out of which more than 800 pose as artificial intelligence (AI) skills or Model Context Protocol (MCP) servers to deliver a malware family known as SmartLoader as part of an ongoing campaign codenamed FakeGit.

"FakeGit uses copied projects, lookalike developer profiles, convincing READMEs, and malicious ZIP

Affected AI Products

model context protocol
Get the weekly digest. Every Monday: top AI security stories of the week. Free.