Threat reportMalwareTL-2026-0457

109 Fake GitHub Repositories Deliver SmartLoader (LuaJIT) and StealC Infostealer via Cloned Open-Source Projects with Polygon Smart Contract C2

highMONITORING

109 Fake GitHub Repositories Deliver SmartLoader (LuaJIT) (TL-2026-0457), also tracked as Cloned-Loaded-Stolen GitHub Campaign, is a high-severity malware campaign, first published 2026-05-05. It has no confirmed attribution, affects GitHub GitHub Repository Hosting, maps to 30 MITRE ATT&CK techniques (T1005, T1027, T1027.009), and is covered by 9 detection rules and 18 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
0None referenced
Techniques
30MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
18Indicators of compromise

Key facts for TL-2026-0457

Threat ID
TL-2026-0457
Also known as
Cloned-Loaded-Stolen GitHub Campaign, SmartLoader GitHub Cloning Operation
Severity
HIGH
Status
MONITORING
Category
MALWARE
First published
Last reviewed
Attribution confidence
NONE
Motivation
FINANCIAL
Target sectors
technology, software-development, devops, security-research, education, home-automation, open-source-community
Target regions
Global, North America, Europe, Asia
Detection rules
9
Indicators of compromise
18

Malware and tooling in 109 Fake GitHub Repositories Deliver SmartLoader (LuaJIT)

Malware and tooling: SmartLoader, Stealc

How 109 Fake GitHub Repositories Deliver SmartLoader (LuaJIT) works

Hexastrike Cybersecurity uncovered a campaign in which a single threat actor (or tightly controlled cluster) cloned legitimate open-source projects and republished 109 malicious GitHub repositories across 103 throwaway accounts. Victims download a ZIP that runs a batch launcher invoking a LuaJIT-based SmartLoader, which retrieves the StealC infostealer. The operation pioneers a Polygon smart contract for resilient C2 resolution alongside three IP-based fallback C2 servers, and remained active for at least seven weeks (ZIP timestamps Feb 19 - Apr 5, 2026).

Hexastrike Cybersecurity disclosed on April 18, 2026 a large-scale GitHub abuse campaign in which an unidentified threat actor (or tightly coordinated cluster) cloned legitimate open-source projects, embedded malicious payloads, and republished them as 109 distinct repositories across 103 GitHub accounts. The campaign was active for at least seven weeks based on ZIP archive timestamps spanning February 19, 2026 through April 5, 2026, with continued activity observed as of April 12, 2026.

Victims acquire the malicious archive by browsing or searching for what appears to be a legitimate open-source project on GitHub. The actor cloned README content, project structure, and even commit history from genuine repositories (examples include forks of Pyrsistence-style libraries, founders kits, home-assistant integrations, and miscellaneous developer utilities) to lend credibility. Each repository ships a ZIP attachment in the Releases tab or repository root containing a Windows batch launcher (.bat / .cmd) and a packaged LuaJIT runtime plus an obfuscated Lua script. When the user extracts and runs the launcher, it invokes luajit.exe against the bundled script, which acts as SmartLoader: a LuaJIT-implemented stager that decodes embedded shellcode, performs lightweight environment fingerprinting, and downloads the StealC infostealer second stage.

C2 resolution is the campaign's most novel element. SmartLoader does not hardcode a C2 IP or domain at runtime. Instead it issues an eth_call JSON-RPC request to polygon.drpc.org against the Polygon mainnet smart contract at 0x1823A9a0Ec8e0C25dD957D0841e3D41a4474bAdc using function selector 0x3bc5de30. The contract returns the current C2 endpoint(s), which the operators rotate by submitting on-chain transactions. Three IP-based C2 servers have been observed acting as the resolved endpoints: 144.31.57.67, 144.31.57.65 (a /29 neighbor in the same hosting block), and 213.176.73.149. This dead-drop resolver pattern provides operational resilience: defenders cannot sinkhole or seize the resolver because it is a smart contract on a public blockchain, and the operators can pivot infrastructure without re-tooling implants.

SmartLoader's downloaded second stage is StealC, a well-documented infostealer first observed in early 2023 that targets browser cookies, saved credentials, autofill data, cryptocurrency wallet files, Discord and Telegram tokens, FTP client configurations, and document files. StealC exfiltrates collected data over HTTP POST to the C2 endpoint resolved via the Polygon contract.

Observed sample SHA-256 hashes include 2273702dfbcfd96a6ed7bdb42ba130291b653869256ec1325bc7fe30e8d9b70a and 87de3e5a8ef669589c421220cd392ae8027a8f8d3cd97d35ac339f87dcff12c8. Representative malicious repositories include stcitlab1/PyrsistenceSniper, Shonpersus/founders-kit, therajeshpatil/home-assistant-global-health-score, and deepanshugoel99/long.

The campaign expands the typical SmartLoader/StealC delivery beyond gaming-cheat and cracked-software lures into the developer ecosystem, broadening the victim profile to include security researchers, developers, DevOps engineers, and home automation hobbyists who routinely run code from GitHub. Detection should focus on the LuaJIT execution chain on workstations (rare in legitimate developer activity), eth_call traffic to public Polygon RPC endpoints from non-blockchain workloads, and outbound connections to the three identified C2 IPs.

MITRE ATT&CK techniques used in TL-2026-0457

Collection

T1005 Data from Local System; T1560 Archive Collected Data

Defense Evasion

T1027 Obfuscated Files or Information; T1027.009 Obfuscated Files or Information: Embedded Payloads; T1036.005 Match Legitimate Resource Name or Location; T1140 Deobfuscate/Decode Files or Information

Exfiltration

T1041 Exfiltration Over C2 Channel

Execution

T1059.003 Command and Scripting Interpreter: Windows Command Shell; T1059.011 Command and Scripting Interpreter: Lua; T1204.002 User Execution: Malicious File

Command and Control

T1071.001 Application Layer Protocol: Web Protocols; T1102 Web Service; T1102.001 Web Service: Dead Drop Resolver; T1105 Ingress Tool Transfer; T1573.002 Encrypted Channel: Asymmetric Cryptography

Discovery

T1082 System Information Discovery; T1083 File and Directory Discovery; T1518 Software Discovery

Initial Access

T1189 Drive-by Compromise; T1195.002 Supply Chain Compromise: Compromise Software Supply Chain

Credential Access

T1539 Steal Web Session Cookie; T1552.001 Unsecured Credentials: Credentials In Files; T1555.003 Credentials from Password Stores: Credentials from Web Browsers

defense-impairment

T1553.005 Subvert Trust Controls: Mark-of-the-Web Bypass

Resource Development

T1583 Acquire Infrastructure; T1583.004 Acquire Infrastructure: Server; T1585.001 Establish Accounts: Social Media Accounts; T1587.001 Develop Capabilities: Malware; T1608.001 Stage Capabilities: Upload Malware

Impact

T1657 Financial Theft

Affected products and versions in 109 Fake GitHub Repositories Deliver SmartLoader (LuaJIT)

  • GitHub — GitHub Repository Hosting
    Vulnerable versions: abused-platform
  • Microsoft — Windows
    Vulnerable versions: 10; 11; Server 2019; Server 2022
  • LuaJIT Project — LuaJIT Runtime
    Vulnerable versions: abused-as-execution-host
  • Polygon Labs — Polygon PoS Mainnet
    Vulnerable versions: abused-as-c2-resolver

Remediation for 109 Fake GitHub Repositories Deliver SmartLoader (LuaJIT)

Immediate actions

  • Block outbound connections to 144.31.57.67, 144.31.57.65, and 213.176.73.149 at perimeter and EDR network controls
  • Block or alert on outbound traffic to polygon.drpc.org and other public Polygon RPC endpoints (drpc.org, alchemy.com, infura.io, ankr.com, blockpi.network, polygon-rpc.com) from non-blockchain workstations
  • Hunt for processes named luajit.exe spawned from %TEMP%, %APPDATA%, Downloads, or Desktop directories
  • Hunt for cmd.exe / batch (.bat, .cmd) executions invoking luajit.exe with .lua arguments
  • Block download or execution of ZIPs from the listed malicious GitHub repositories and report them to GitHub Trust & Safety for takedown

Workarounds

  • Deny execution of *.bat and *.cmd files originating from Mark-of-the-Web (downloaded) ZIP archives via Group Policy or AppLocker
  • Configure browsers to display file extensions and warn on extraction of executables from ZIPs flagged with MOTW
  • Sandbox developer workstations or use ephemeral VMs/devcontainers when evaluating unfamiliar GitHub repositories

Longer-term hardening

  • Deploy EDR with behavioral detection covering LuaJIT execution chains and JSON-RPC eth_call patterns from non-developer endpoints
  • Restrict execution of unsigned Lua/LuaJIT runtimes via WDAC, AppLocker, or similar application-control policies
  • Educate developers and IT staff about typosquatted or cloned GitHub repositories and verify upstream provenance (commit signatures, author history, star/fork pedigree) before running release ZIPs
  • Subscribe to threat-intel feeds tracking SmartLoader and StealC infrastructure rotations to receive updated IOC lists
  • Monitor on-chain activity against the Polygon C2 contract 0x1823A9a0Ec8e0C25dD957D0841e3D41a4474bAdc to anticipate infrastructure pivots

Weaknesses (CWE) in 109 Fake GitHub Repositories Deliver SmartLoader (LuaJIT)

CWE-829, CWE-494, CWE-1357, CWE-506

Timeline of 109 Fake GitHub Repositories Deliver SmartLoader (LuaJIT)

  • Earliest observed malicious ZIP archive timestamp across the 109 cloned repositories, marking the campaign's earliest known staging activity.
  • Polygon C2 contract 0x1823A9a0Ec8e0C25dD957D0841e3D41a4474bAdc and IP C2 144.31.57.67 observed serving SmartLoader resolution requests.
  • Repository count surpasses 50 cloned projects across 50+ throwaway GitHub accounts, expanding lures beyond gamer/cracked-software themes into developer utilities and home-automation projects.
  • Latest observed malicious ZIP archive timestamp, indicating ongoing operator activity through early April 2026.
  • Hexastrike Cybersecurity confirms campaign still active with operational C2 infrastructure and reachable Polygon resolver contract.
  • Hexastrike Cybersecurity publishes 'Cloned, Loaded, and Stolen' public report disclosing 109 repositories, 103 accounts, IOCs, and Polygon C2 mechanism. Malpedia mirrors the entry.
  • Initial GitHub Trust & Safety takedown wave removes a subset of the disclosed 109 repositories; some throwaway accounts remain to host successor variants.
  • Threadlinqs Intelligence publishes TL-2026-0457 with full IOCs, MITRE mapping, detections, and simulation coverage.
  • As of 2026-05-29, this remains a live concern: the SmartLoader/StealC GitHub-cloning operation is one wave of a long-running Vietnamese-operator campaign (600+ ZIPs, 16 LuaJIT obfuscator generations, ~25 accounts still active in 2026). Only a subset of the 109 repos was taken down; the un-seizable Polygon dead-drop C2, persistence, and StealC v2.9 MaaS all persist, so successors can resurge.

Sources cited for 109 Fake GitHub Repositories Deliver SmartLoader (LuaJIT)

Detection coverage for TL-2026-0457

As of 2026-05-05, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0457 across Splunk SPL, Microsoft KQL and Sigma, covering 18 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
18 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats