The FakeGit campaign exploits counterfeit GitHub repositories with copied projects and deceptively authentic developer profiles to distribute SmartLoader malware through fake AI tools and MCP servers.
Attackers can compromise developer environments through classic, easily exploitable bugs with minimal user interaction and steal all stored secrets and source code.
Around 290 fake GitHub repositories impersonate legitimate security and developer tools while distributing infostealers to compromise credentials and sensitive data from developers.
Attackers used a stolen OIDC token to distribute counterfeit TanStack packages on npm, enabling the exfiltration of cloud credentials and authentication tokens.
Malicious npm packages impersonate legitimate Rollup polyfills and enable North Korean actors to steal data and gain remote access to developer systems.
actions/checkout v7 fails workflows that use pull_request_target or workflow_run with unverified fork code — a step toward “Security by Default” philosophy.
At least 15 malicious plugins in the JetBrains Marketplace were designed to steal AI API keys from developers and gain access to internal corporate services.