Malicious GitHub activity dubbed FakeGit has spread across nearly 7,600 repositories, with more than 800 impersonating AI skills or Model Context Protocol (MCP) servers. The campaign uses copied projects, lookalike developer profiles, convincing READMEs, and malicious ZIP files to lure victims into downloading SmartLoader. SmartLoader then establishes persistence and can deploy StealC to steal credentials, sessions, and other sensitive data. Source
Read the full article at the source.
Comments (0)
No comments yet. Be the first to comment!