FakeGit is the campaign name reported by The Hacker News on July 20, 2026, in which nearly 7,600 malicious GitHub repositories were created to distribute SmartLoader malware. What stands out is not only the scale, but also how the attackers copied legitimate projects, built developer profiles that looked trustworthy, and used convincing README files to turn routine source-code downloads into the starting point for infection.
Among these fake repositories, more than 800 were disguised as AI skills or Model Context Protocol (MCP) servers. This is a notable signal for the software development community, because AI agent tools, plugins, and MCP servers are being widely tested in everyday workflows.
The campaign began with trust in open source code
According to The Hacker News, FakeGit did not simply place malware on GitHub and wait for victims to download it. The campaign used copied projects, developer accounts that looked authentic, plausible project descriptions, and malicious archive files to lead users to SmartLoader. This approach exploits a very common assumption: if a repository has a familiar interface, a clear README, and is hosted on a major platform, users are more likely to treat it as trustworthy.
SmartLoader acts as a malware loader. When users download and run the malicious component, the loader can open the way for follow-on payloads, from data theft to additional remote-control tooling. With a campaign spread across thousands of repositories, the risk is no longer limited to a single software package; it becomes a broader software supply-chain hygiene problem.

Why development teams are attractive targets
Developers often have access to source code, API keys, deployment tokens, CI/CD systems, and internal environments. A fake tool package executed on a developer workstation can create consequences far beyond a typical malware infection on a personal computer.
FakeGit targeting AI skills and MCP increases the risk further. These components are often tested quickly, installed from public repositories, and connected to agents or automation environments. If source-review processes are not strict enough, malicious code can enter the workflow before security teams have time to detect it.
Warning signs to check before downloading a repository
Organizations should check account age, commit history, consistency between the project name and source code, installer contents, bundled archive files, and any command that asks to run immediately after download. Repositories with polished README files but thin development history, unclear binary releases, or requests to disable protection mechanisms should be treated as risk signals.
For AI agent and MCP projects, teams should apply least privilege: run them in isolated environments, avoid granting real tokens during first tests, do not connect them directly to production data, and record every permission the tool requests. Manual review remains necessary, but it should be combined with dependency scanning, static analysis, and policies that block execution of unknown files.
Lessons for supply-chain security
FakeGit shows that supply-chain attacks do not have to begin with the compromise of a well-known project. Attackers can create thousands of copies that look real enough, exploit user haste, and take advantage of the pressure to test new tools. As AI agents make it easier to add tools, software provenance controls must be placed ahead of experimentation speed.
For enterprises, effective defense should combine approved repository catalogs, token-control policies, sandboxes for new tools, and behavioral monitoring on developer machines. For individuals, the most important principle is not to run code from an unfamiliar repository before carefully reviewing its structure, history, and installation commands.
VNCyberS compiled from The Hacker News















