Severity: ElevatedAction: Be aware

FakeGit malware campaign returns with 17,610 malicious GitHub repos

More than 17,000 fake repositories on GitHub are distributing the SmartLoader malware after the FakeGit campaign reactivated earlier this month to push the StealC infostealer.

Excerpt from the primary source: BleepingComputer

Who is affected

Home users · Developers · Security professionals

Affected technology: GitHub

What you should do · Be aware

No immediate action is required, but be alert to related scams or suspicious messages.

Automated guidance based on this story's classification. Check the linked advisories for specifics.

Sources

We link to original and authoritative sources. Headlines and excerpts belong to their publishers.

Original reporting

FakeGit malware campaign returns with 17,610 malicious GitHub repos BleepingComputer · bleepingcomputer.com · Oct 8, 2026 · Primary source
Severity: ElevatedAction: Be aware

Blinder Tunnel Campaign Targets Iraqi Infrastructure

Analysis of Blinder Tunnel, an Iran-nexus campaign using fake Dubai Airports recruitment lures and GitHub C2 malware to target critical infrastructure.

Severity: HighAction: Be aware

Shai-Hulud Attack Nips Cyber-Firm CrowdSec's GitHub Data

Threat actors stole the contents of 170 private repositories using an OAuth token stolen from a former employee's computer through the TanStack npm supply chain attack.

FakeGit malware campaign returns with 17,610 malicious GitHub repos | CybersecurityNews.us