What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

FakeGit is a malware campaign that uses GitHub repositories as bait. Security firm Apiiro reported in October 2026 that it had found 17,610 live lure repositories. The repositories look like ordinary software projects, but their README files send visitors to a ZIP archive that can install an information stealer. GitHub hosting does not make a download safe. If a repository’s download link leads to an unexplained ZIP, do not open it.

What FakeGit is

FakeGit is a pattern of deceptive repositories rather than a single piece of software. Each lure usually copies or imitates a legitimate project, then replaces or adds to its README with a friendly installation guide and a download badge. The badge points to a ZIP archive hosted in the repository or somewhere linked from it. Someone who expects a tool, plugin, or library and runs the downloaded file can end up installing malware instead.

The numbers, and what each one counts

The headline figure is a point-in-time count, not a live census of GitHub. Apiiro’s October 2026 investigation distinguishes between two totals, and they should not be mixed:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Figure What it counts Source and date
17,610 Live FakeGit lure repositories Apiiro, October 2026
18,864 Repositories involved, including download hosts and forked copies Apiiro, October 2026
79% of the fleet Repositories re-pushed on October 4–5, 2026, in waves, with most sampled changes altering only the README Apiiro, October 2026
More than 13,000 Repositories pushed within 34 hours BleepingComputer, October 8, 2026, summarizing the same episode
71% of the fleet Repositories missing from Apiiro’s URLhaus snapshot taken before its report Apiiro, October 2026
More than 800 of nearly 7,600 Repositories posing as AI skills or MCP servers in an earlier snapshot Island findings reported by The Hacker News, July 20, 2026

These are named-source figures from specific investigations, not independently verified population estimates. The July figure describes an earlier snapshot and a particular lure type. It does not mean that all 17,610 current repositories use that disguise.

#1 Best Overall

How an infection happens

Apiiro describes a chain that starts with a README and ends with a payload. The steps below reflect its technical analysis. Not every repository carries the same payload, and not every download leads to an infection.

  1. The visitor finds a repository that looks like a real project, often one copied from a legitimate codebase.
  2. The README presents an installation guide and a download badge, and the badge links to a ZIP archive.
  3. The ZIP contains a LuaJIT loader chain and SmartLoader, which Apiiro describes as the component that installs the next stage.
  4. In the cases Apiiro examined, the next stage can include StealC, an information stealer that targets saved data such as credentials and session information.

Because the infection depends on someone running the downloaded file, the lure works best on people who are trying to install something quickly, such as a developer adding a tool to a project.

Why removing one repository does not end the campaign

Apiiro calls the tactic RePointing. The operator keeps a repository available and changes where its download button points. Copies of the payload also appear in forks, older ZIP files, release assets, issue attachments, and separate repositories set up to host downloads. If one link is taken down, the README can be pointed at a backup.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

This is why a single removal or blocklist entry is not proof that the wider campaign is contained. Apiiro found that 71% of the fleet was absent from its URLhaus snapshot before its report, and listed files could still be downloadable from other locations.

Apiiro also reports repositories linked to accounts that appear to belong to legitimate developers, including injected lure commits in repositories those developers did not own. The report separates throwaway-looking accounts, suspected account takeovers, and a smaller set with stronger evidence of compromise. Do not assume that every account named in a lure has been compromised.

AI skills and MCP servers

Island’s July 2026 research, as reported by The Hacker News on July 20, 2026, described a related pattern it called AgentBaiting. An AI agent searching for a skill or MCP server may find a malicious repository and follow its README instructions. In that earlier snapshot, more than 800 of nearly 7,600 malicious repositories posed as AI skills or MCP servers.

The lesson is about verification. A README, search ranking, star count, or registry-like listing does not establish that a skill or server is genuine. Apiiro recommends installing AI skills and MCP servers only from official registries or vendor repositories, and checking the repository owner before running anything.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How to check a repository before you download

  • Confirm the owner is the project’s real maintainer or organization, and check that the link on the official project website points to the same repository.
  • Prefer releases published from the project’s own repository, and be cautious of a bare ZIP in the file tree that the README calls the installer.
  • Be wary of a repository that looks like a popular project but has recent README changes, few commits, or a download link to an unrelated host.
  • For AI skills and MCP servers, install from the official registry or vendor repository, not from a link found in search results or another agent’s output.

None of these checks is conclusive alone. Together they reduce the chance of running a copied or re-pointed download.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

If you only viewed a suspicious page

If you visited a suspicious repository but did not download or run anything, leave the page and do not download the ZIP. You can report the repository through GitHub’s reporting channels. A report may not remove every copy, so do not treat it as the end of the matter.

If you downloaded or ran the file

Treat the situation as a malware and account-security incident. Apiiro’s advice is to revoke active GitHub sessions and access tokens, then move your account to passkeys. BleepingComputer also reports checking repository ownership and using official sources. The reporting available does not provide a complete consumer cleanup procedure or device-specific indicators, so do not assume a single fix is enough.

  1. Disconnect the affected device from work networks and avoid using it to change sensitive credentials until it has been assessed.
  2. Revoke active sessions and personal access tokens in your GitHub account settings, and check for tokens or SSH keys you do not recognise.
  3. Set up passkeys on your GitHub account. If your accounts support hardware security keys, a FIDO2 key is one option for passkey-style sign-in. A key does not scan for or remove malware.
  4. Change passwords for accounts that may have been exposed, starting from a clean device, and enable two-factor authentication on email and banking accounts.

For work devices or developer credentials, involve your organization’s security team or a qualified incident responder. They can check for SmartLoader or StealC activity, and decide which credentials and repositories need rotation.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Bottom line for developers

The FakeGit campaign shows that a familiar platform does not make a download trustworthy. Verify the owner, prefer official releases and registries, and treat a README that asks you to run a ZIP as a warning sign. The count of 17,610 is Apiiro’s observation at a point in time, and the fleet may change quickly.

Whether the repositories you see are safe depends on checking the source, not on whether GitHub hosts them.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.