Skip to main content
JS
Jacob Santos

Jacob Santos

Threat Hunter, Researcher and Builder

Sr. Threat Researcher | Trend AI
17
Articles
14
Threads
10+
Tools
10+
Talks
AI-Assisted Fake GitHub Repositories Fuel SmartLoader and LummaStealer Distribution
Trend AI Research Blog Mar 2025

AI-Assisted Fake GitHub Repositories Fuel SmartLoader and LummaStealer Distribution

Social EngineeringRATDefense Evasion

A sophisticated campaign used AI-generated content to create convincing fake GitHub repositories that distributed SmartLoader, which then delivered Lumma Stealer and other malicious payloads. The repositories featured AI-written README files, realistic code structures, and fabricated star counts to appear legitimate. This research documents how threat actors leverage generative AI to scale social engineering attacks on developer communities, including the full infection chain from repository discovery to credential theft.