Tag: GitHub Repositories

FakeGit Campaign Uses 7,600 GitHub Repositories to Spread SmartLoader Malware
News

FakeGit Campaign Uses 7,600 GitHub Repositories to Spread SmartLoader Malware

As part of an ongoing campaign known as FakeGit, cybersecurity researchers have found over 7,600 malicious GitHub repositories, of which more than 800 pose as Model Context Protocol (MCP) servers or artificial intelligence (AI) talents to distribute a malware family known as SmartLoader. According to a report shared with The Hacker News by Oleg Zaytsev, principal security researcher at Island, FakeGit employs malicious ZIP files, lookalike developer profiles, replicated projects, and persuasive READMEs to spread SmartLoader malware. The ultimate objective of these assaults is to use the access provided by SmartLoader to create persistence and propagate secondary payloads, like StealC, an information stealer that can extract a variety of data from infected systems. It's important ...
Hackers Use GitHub Repositories to Host Amadey Malware and Data Stealers, Bypassing Filters
News

Hackers Use GitHub Repositories to Host Amadey Malware and Data Stealers, Bypassing Filters

As part of a campaign seen in April 2025, threat actors are using public GitHub repositories to host malicious payloads and disseminate them via Amadey. In a report released today, Cisco Talos researchers Chris Neal and Craig Jackson claimed that the MaaS [malware-as-a-service] operators hosted payloads, tools, and Amadey plug-ins using fictitious GitHub accounts, perhaps in an effort to get around web filtering and for convenience. According to the cybersecurity firm, the attack chains use a malware loader named Emmenhtal (also known as PEAKLIGHT) to distribute Amadey, which downloads several custom payloads from open GitHub repositories run by the threat actors. The action is tactically similar to an email phishing operation that distributed SmokeLoader via Emmenhtal in Februar...