Executive Summary
The FakeGit campaign represents a significant escalation in the abuse of trusted open-source platforms for malware distribution. Leveraging over 7,600 malicious GitHub repositories, threat actors have orchestrated a sophisticated supply chain attack to propagate the SmartLoader malware. These repositories, often indistinguishable from legitimate projects due to the use of AI-generated documentation and code samples, serve as lures for unsuspecting users seeking popular tools, gaming cheats, cracked software, or system utilities. Upon execution, SmartLoader acts as a dropper, deploying secondary payloads such as Lumma Stealer, a notorious infostealer. The campaign’s scale, automation, and exploitation of both human and AI-driven code discovery workflows underscore the urgent need for enhanced vigilance and robust countermeasures across the software supply chain.
Threat Actor Profile
The FakeGit campaign is attributed to a threat group tracked as Water Kurita by Trend Micro. This actor is characterized by its adept use of generative AI to automate the creation of convincing repository content, including README files and code samples. Water Kurita demonstrates a deep understanding of both social engineering and the technical nuances of open-source ecosystems, exploiting the inherent trust in platforms like GitHub. The group’s operations are financially motivated, with a focus on credential theft, cryptocurrency wallet exfiltration, and the resale of sensitive data. Notably, the campaign leverages Malware-as-a-Service (MaaS) offerings, particularly Lumma Stealer, to maximize reach and impact. The actor’s tactics, techniques, and procedures (TTPs) reflect a blend of automation, opportunism, and adaptability, targeting both individual users and organizations globally.
Technical Analysis of Malware/TTPs
The FakeGit campaign’s infection chain is multi-staged and highly automated. Attackers create thousands of repositories on GitHub, each mimicking legitimate or trending projects. AI-generated documentation and code samples enhance credibility, often referencing popular software, AI skills, or integrations for platforms like Gmail, WhatsApp, Docker, and Jenkins. The repositories’ "Releases" sections host ZIP archives (e.g., Release.zip, Software.zip) containing a consistent set of malicious components: lua51.dll (the LuaJIT runtime), luajit.exe (the loader executable), userdata.txt (an obfuscated Lua script), and Launcher.bat (a batch file to initiate execution).
Upon user interaction, the batch file executes luajit.exe with the malicious script, triggering SmartLoader. This loader establishes communication with a command-and-control (C2) server, such as pasteflawwed[.]world, and retrieves additional payloads. These payloads, including Lumma Stealer or StealC, are often disguised as benign executables (e.g., search.exe) and may be artificially inflated to sizes exceeding 1GB to evade detection by security solutions.
SmartLoader exhibits advanced evasion techniques, such as environmental checks for security software using commands like findstr /I "opssvc wrsa" and findstr "AvastUI AVGUI bdservicehost nsWscSvc ekrn SophosHealth". It also manipulates browser debugging ports to facilitate credential theft. The final payload, typically Lumma Stealer, is executed via encrypted scripts (often AutoIt within Excel files), enabling the exfiltration of credentials, cryptocurrency wallets, two-factor authentication tokens, and personally identifiable information (PII) to remote C2 infrastructure.
A notable evolution in TTPs is the exploitation of AI agents (e.g., Anthropic Claude, Google Gemini, OpenAI ChatGPT) tasked with code discovery or plugin installation. These agents can inadvertently recommend or install malicious repositories, further automating the infection process and expanding the attack surface.
Exploitation in the Wild
The FakeGit campaign has been observed actively targeting a broad spectrum of victims. Individuals seeking free or cracked software, gaming mods, or AI skills are particularly at risk, as are organizations whose employees or automated agents download tools from unverified repositories. The campaign’s global reach is facilitated by the ubiquity of GitHub and the automation of repository creation and promotion, including impersonation of security researchers on social media platforms.
The impact of exploitation includes widespread credential theft, compromise of cryptocurrency wallets, unauthorized access to sensitive organizational data, and the potential for downstream attacks via resale of stolen information. The campaign’s reliance on social engineering, trusted platforms, and AI-driven workflows has enabled it to bypass traditional security controls and achieve significant scale.
Victimology and Targeting
FakeGit is an opportunistic campaign with a global footprint. There is no evidence of sector-specific targeting; instead, the threat actors focus on users and organizations engaged in open-source software consumption, particularly those seeking unauthorized or convenience-enhancing tools. The campaign also targets AI agents and automated workflows, reflecting an awareness of emerging trends in software development and deployment. Victims span individuals, small businesses, and large enterprises, with the common denominator being the download and execution of files from unverified GitHub repositories.
Mitigation and Countermeasures
To defend against the FakeGit campaign and similar supply chain threats, organizations and individuals should implement a multi-layered security strategy. All code and tools sourced from GitHub or other open repositories must be rigorously verified for authenticity, including scrutiny of publisher reputation and project history. Unknown files should be analyzed in sandboxed environments prior to execution, and network controls should be configured to block known malicious domains and restrict downloads from untrusted sources.
User and developer education is paramount; training should emphasize the risks of downloading cracked, unofficial, or poorly vetted software, as well as the dangers of social engineering and AI-assisted deception. Endpoint protection solutions must be capable of detecting obfuscated scripts, batch execution chains, and anomalous file behaviors such as size inflation. Organizations leveraging AI agents for code discovery or plugin installation should maintain curated catalogs of reviewed and approved skills, plugins, and integrations, and monitor agentic pathways for suspicious activity.
Regular threat intelligence updates and proactive monitoring of open-source ecosystems are essential to identify and respond to emerging campaigns. Incident response plans should be updated to address supply chain and social engineering vectors, ensuring rapid containment and remediation in the event of compromise.
References
Trend Micro: AI-Assisted Fake GitHub Repositories Fuel SmartLoader and LummaStealer Distribution
The Hacker News: FakeGit Campaign Uses 7,600 GitHub Repositories to Spread SmartLoader Malware
Reddit: FakeGit Campaign Uses 7600 GitHub Repositories to Spread SmartLoader Malware
SecurityOnline.info: Fake GitHub Repositories Spread SmartLoader and Lumma Stealer
GBHackers: 109 Fake GitHub Repos Spread SmartLoader, StealC Malware
No CVE assigned as of report date; campaign leverages social engineering and trusted platforms rather than exploiting a specific software vulnerability.
About Rescana
Rescana is a leader in third-party risk management (TPRM), providing organizations with advanced tools to assess, monitor, and mitigate cyber risks across their digital supply chains. Our platform empowers security teams to gain actionable insights, automate risk assessments, and ensure compliance with evolving threat landscapes. For more information or to discuss how Rescana can support your organization’s cybersecurity posture, we are happy to answer questions at info@rescana.com.



