Skip to content
Security & Trust

Apiiro: a 17,610-repo GitHub malware fleet was re-aimed, not rebuilt

Apiiro says FakeGit restarted on October 4. In a sample of commits, nearly all changes touched only a README

W
WebPulse Newsroom
AI-assisted · 4 min read
Share on X LinkedIn
Apiiro: a 17,610-repo GitHub malware fleet was re-aimed, not rebuilt
In brief
  • Apiiro reports FakeGit resumed on October 4 and now uses 17,610 GitHub repositories. In its commit sample, 97% of changes touched only a README.
  • URLhaus was missing 71% of the fleet before Apiiro's report, and DNS blocking cannot isolate single files on GitHub, so takedowns lag.
  • Install AI skills and MCP servers only from official sources, and be ready to revoke sessions and tokens quickly.

An attacker who owns the fleet only has to change the arrow

Defenders like lists. A list of bad domains, bad files or bad repositories feels like control. FakeGit shows the limit of that habit. When one operator owns thousands of repositories, pointing them somewhere new is cheap. A list has to catch up after every change.

Apiiro, a software supply-chain security company, reports that the FakeGit campaign resumed on October 4. It now uses 17,610 repositories on GitHub. BleepingComputer covered the report on October 8.

17,610
Repositories in the FakeGit fleet
Source: Apiiro report, as covered by BleepingComputer (October 8, 2026)

The pace is what stands out. Over 34 hours, the operator put more than 13,000 repositories to work. The peak was 2,999 in a single hour. Apiiro's own summary is that the fleet "was already there" and was simply "re-aimed".

How the lure works

Each repository has a convincing README, the page visitors read first. It carries a Download button. The button leads to a ZIP file holding SmartLoader. That is the first-stage payload, used to deliver other malware.

In this wave, the goal is to deliver StealC, an infostealer. That is a program built to take data from infected machines.

Re-aiming costs almost nothing, because the edit is tiny. Apiiro looked at a sample of commits. In that sample, 97% changed only the README. Also in that sample, 88% sent the Download button to a ZIP that installs SmartLoader.

97%
Sampled commits that changed only the README
Source: Apiiro report, as covered by BleepingComputer (October 8, 2026)

Where reputation matters, and where we cannot say

The operator mostly relies on throwaway accounts. Not all of them are disposable, though. The researchers spotted 700 or more profiles that seem to be run by genuine developers. In that narrow group, an owner's good name may be doing real work for the attacker.

The sources leave a gap here. They do not say how many re-aimed repositories had any earlier history. They also do not say whether those repositories were harmless before. So the evidence shows an operator-owned fleet being redirected. It does not show established projects being flipped at scale.

Why takedowns lag

Apiiro says the campaign survives because removals follow lists that cover only part of the fleet. Before Apiiro's report, URLhaus was missing 71% of the fleet. URLhaus is one blocklist, so this figure says nothing about every blocklist.

71%
Fleet missing from URLhaus before Apiiro's report
Source: Apiiro report, as covered by BleepingComputer (October 8, 2026)

DNS blocking has a second limit. It works on whole domain names. GitHub serves everyone's code from one domain. Blocking it to stop one file would stop legitimate work as well.

The malicious ZIP files are also scattered. Copies turn up in forks, in earlier file versions, in release downloads and in files attached to issues. Some sit in repositories that exist only to host downloads. When one copy is deleted, the lure can point to another. Removing links one at a time is ineffective against that spread.

Some of the lures were dressed as AI tools

FakeGit did not start this month. Similar activity with various payloads has been seen since at least January. The name dates to July, when Island reported 7,600 fake repositories pushing SmartLoader. Island said 800 of them posed as AI skills or MCP servers. That is roughly one in ten. MCP servers are add-ons that connect AI assistants to other tools.

The sources do not say the October wave targets AI tooling. They do not say the target is widening, either. They also do not say how many organisations were infected.

Here is our argument. An add-on that promises to save time is easy to install without much checking. A lure shaped like a helpful tool fits that habit. Apiiro's advice points the same way: install AI skills and MCP servers only from official registries or vendor repositories.

What to ask your teams

Apiiro also advises checking who owns a repository before using it. If someone may have run SmartLoader, treat it as a possible takeover of that person's GitHub account. End active sessions, cancel access tokens and switch to passkeys, which replace passwords with device-based sign-in.

Four questions follow for leaders.

Who approves AI skills and MCP servers before they run on a developer machine, and is there a list of what is installed? Do we rely on URL or DNS blocklists to catch malware hosted on GitHub? If a laptop is compromised, how fast can we cancel its sessions and tokens? Which accounts still use passwords instead of passkeys?

Lists record where malware was. A README edit decides where it points next. Plan for the second.

Produced by the WebPulse Newsroom with AI assistance from the original reporting credited below, and checked against that source by our editorial review. How we use AI.
Original reporting: BleepingComputer.

Share this insight