A sprawling repository-abuse campaign linked to FakeGit used roughly 7,600 GitHub repos and more than 14 million downloads to push SmartLoader and StealC, showing how platform trust can become malware transport.
A malware campaign used deceptive GitHub repositories and AI-facing registry surfaces to make a loader look like a useful project, showing how quickly trusted setup paths can be turned against developers and agents.
A reported campaign abused AI tool listings, GitHub-style trust cues, and MCP workflows to move SmartLoader first and StealC second, turning documentation into part of the attack path.
Cybercriminals spent months faking legitimacy to infiltrate developer circles and steal sensitive data through a poisoned AI health app server.