Back to news

FakeGit Floods GitHub With Malware While Microsoft Patches 570 Flaws

A coordinated GitHub poisoning campaign and Microsoft's largest-ever patch release signal an accelerating threat environment for engineering and operations teams.

FakeGit Floods GitHub With Malware While Microsoft Patches 570 Flaws

What happened

Security researchers identified nearly 7,600 malicious GitHub repositories tied to a campaign called FakeGit, with more than 800 of them disguised as AI tools or Model Context Protocol servers to lure developers into downloading SmartLoader malware. The attackers built convincing facades using cloned legitimate projects, imitation developer profiles, and professionally written README files bundled with weaponized ZIP archives. Separately, Microsoft's July Patch Tuesday addressed at least 570 security vulnerabilities across Windows and related software — nearly triple the record set just one month prior. The company attributed the surge in discovered flaws partly to AI-assisted vulnerability research accelerating its internal security audits.

Why it matters for your business

The FakeGit campaign directly targets the developer supply chain by exploiting the trust engineers place in open-source repositories, particularly those branded around trending technologies like AI and MCP integrations. Any team pulling third-party packages or tools from GitHub without rigorous vetting is a potential entry point for SmartLoader, which can serve as a foothold for deeper compromise. The Microsoft patch volume underscores a separate but compounding risk: legacy and unpatched Windows environments are carrying an unprecedented vulnerability load that attackers can cross-reference against public disclosures. The practical takeaway is a two-front obligation — establish a formal dependency review process for all open-source code before it touches a build pipeline, and treat this month's Windows patch cycle as a critical maintenance event rather than a routine update.

What to watch next

The FakeGit campaign shows no signs of being a one-time operation; expect similar infrastructure-poisoning tactics to expand to other platforms such as npm, PyPI, and Docker Hub as attackers refine the playbook. On the Microsoft side, the AI-assisted vulnerability discovery trend suggests future patch cycles could remain unusually large, placing sustained pressure on enterprise patch management workflows. Security teams should also monitor for SmartLoader indicators of compromise, as the malware family's downstream payloads and command-and-control infrastructure have not yet been fully characterized.

Sources

Want this kind of clarity applied to your own systems?

HashWhales can review your website, infrastructure, security posture, and growth bottlenecks, then send a prioritized action plan.

Free AuditChat on WhatsApp