TGViewer
SITREP - Independent OSINT Channel SITREP - Independent OSINT Channel @sitreports · 23K subscribers
Post #39545 85
🔍 FakeGit reactivates at scale on GitHub

FakeGit has resumed activity with 17,610 malicious GitHub repositories distributing SmartLoader, with over 13,000 repos pushed in 34 hours and a peak of 2,999 per hour. Researchers found 97% of sampled commits only modified README files, and 88% redirected download buttons to ZIP archives installing SmartLoader. At least 700 accounts appear tied to legitimate developers. FakeGit has been active in similar form since January.

The campaign’s persistence comes from reuse, not rebuild: existing repos are simply re-pointed to fresh payload locations, while copies remain in forks, release assets, issue attachments, and separate hosting repos. This makes file-by-file takedowns and URL-based blocking structurally weak.

🛰️ Open sources - closed narratives
@sitreports
More from @sitreports
  1. Oct 9, 2026📡 Ransomware disrupts Japan’s IDCF Cloud IDC Frontier says a ransomware attack hit its ID…
  2. Oct 9, 2026🔍 Cisco flags five critical NX-OS flaws on Nexus switches Cisco has issued advisories for…
  3. Oct 9, 2026🔍 Low-cost Android phones found shipping with firmware-level malware Bitdefender’s Midnig…
  4. Oct 9, 2026🔍 UAC-0099 deploys ASHVEIN RAT against Ukrainian government staff UAC-0099 is targeting U…
  5. Oct 9, 2026📡 Ukrainian strike disables Yandex cloud zone Yandex says its ru-central1-b availability…
  6. Oct 9, 2026🔍 Shai-Hulud hits AI tooling via Tensorlake SDK A malicious release of Tensorlake’s SDK v…
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →