FakeGit Campaign: Exploiting GitHub and Model Context Protocol MCP to Deploy SmartLoader
The "FakeGit" campaign is a large-scale supply chain and social engineering operation leveraging approximately 7,600 malicious GitHub repositories and 6,600 unique accounts to distribute the SmartLoader malware. By masquerading as legitimate AI skills and Model Context Protocol (MCP) servers, the attackers manipulate AI agents to recommend malicious repositories to developers. The technical payload utilizes Cloud Server-Side Request Forgery (SSRF) to deploy SmartLoader, which subsequently installs the StealC information stealer. This operation specifically targets users integrating AI-driven workflows for platforms like Gmail and WhatsApp, aiming for high-value credential and sensitive data theft through the exploitation of the emerging AI agent ecosystem and the perceived trust of the GitHub platform.