FakeGit 캠페인이 7,600개의 GitHub 저장소를 통해 SmartLoader 악성코드를 전파하고 있다.
사이버 보안 연구자들이 7,600개의 악성 GitHub 저장소를 발견했다. 이 중 800개 이상은 인공지능(AI) 기술이나 모델 컨텍스트 프로토콜(MCP) 서버로 위장하여 SmartLoader라는 악성 코드 패밀리를 전파하고 있다. FakeGit은 복사된 프로젝트, 유사한 개발자 프로필, 설득력 있는 README 및 악성 ZIP 파일을 사용하여 공격을 수행한다.
The FakeGit campaign uses 7,600 GitHub repositories to spread SmartLoader malware.
Cybersecurity researchers have discovered nearly 7,600 malicious GitHub repositories, with over 800 posing as artificial intelligence (AI) skills or Model Context Protocol (MCP) servers to spread a malware family known as SmartLoader. The FakeGit campaign employs copied projects, lookalike developer profiles, persuasive READMEs, and malicious ZIP files to execute its attacks.