According to BleepingComputer, the FakeGit malware campaign has resurfaced with more than 17,610 malicious GitHub repositories. Those repositories are being used to distribute SmartLoader, a malware loader that in this campaign delivers the StealC infostealer.
The latest wave began earlier this month, and the scale of the repo count points to a large, possibly automated operation. The report does not list individual repository names or attribute the campaign to a specific threat group, but it identifies the payload chain as SmartLoader leading to StealC.
Because the source is a single report, there are no conflicting accounts to compare. The key detail is the sheer number of malicious repos, which suggests that GitHub remains a reliable distribution channel for malware disguised as legitimate code.