The record
Written from the 2 reports below. Nothing here is unsourced.
- Security researchers have disclosed a large supply-chain campaign dubbed FakeGit built on nearly 7,600 malicious GitHub repositories impersonating popular AI tools, MCP servers, and enterprise software, distributed via repository pages and Releases.
- The payloads deliver SmartLoader and StealC info-stealers and, in some variants, Lumma, targeting developer credentials and browser data; one strand also weaponizes compromised GitHub Actions to attack cPanel and WebHost Manager servers for host-level credential theft.
- The scale is significant: BleepingComputer reports more than 14 million downloads before the repositories were flagged.
- What distinguishes this campaign is AgentBaiting, a technique that lures autonomous AI agents into executing malicious code pulled from poisoned registries, turning trusted AI workflow automation into an infection vector.
- Coverage is unified on the threat but split in emphasis: The Hacker News highlights the AI-agent angle, while BleepingComputer focuses on raw download volume and cPanel targeting.
- What to watch next is whether platform holders tighten publisher verification for repositories and MCP registries, and whether downstream enterprises pivot to allow-listed AI catalogs with isolated test environments.
What to watch next
- Watch for GitHub and AI registry publisher-verification updates.
- Monitor cPanel/WHM environments for unauthorized credential use.
- Check enterprise AI agents for execution of unverified MCP skills.
- Track takedown velocity of remaining FakeGit repositories.
What changed2
Every report on this story, newest first. Times are when each outlet published.
BleepingComputer[1]
FakeGit campaign uses 7,600 GitHub repos to push SmartLoader malwareThe Hacker News[2]
FakeGit Campaign Uses 7,600 GitHub Repositories to Spread SmartLoader Malware
Why it matters5
Who is affected first and what likely follows, with a direction and a horizon. Extracted from the reports, never invented.
- Downstream users of poisoned AI tool registries credential theft· immediate
- cPanel and WebHost Manager servers server compromise· immediate
- Organizations deploying autonomous AI agents code execution via agent· days
- GitHub as a registry/supply chain trust degradation· weeks
- Affected organizations secret rotation required· days
Coverage2
Filed from India ×2, United States ×1
Named United States · Anthropic · ChatGPT · Claude · Claude Code · Derp.ca · Docker · FakeGit · Gemini · GitHub · Gmail · Google · Island
The 2 reports are listed beside the record.
Ask this story
Answers cite the reports above, or say they can't.

