The FakeGit campaign exploits counterfeit GitHub repositories with copied projects and deceptively authentic developer profiles to distribute SmartLoader malware through fake AI tools and MCP servers.
Around 290 fake GitHub repositories impersonate legitimate security and developer tools while distributing infostealers to compromise credentials and sensitive data from developers.