# 109 Fake GitHub Repositories Deliver SmartLoader (LuaJIT) and StealC Infostealer via Cloned Open-Source Projects with Polygon Smart Contract C2

> Hexastrike Cybersecurity uncovered a campaign in which a single threat actor (or tightly controlled cluster) cloned legitimate open-source projects and republished 109 malicious GitHub repositories across 103 throwaway accounts. Victims download a ZIP that runs a batch launcher invoking a LuaJIT-based SmartLoader, which retrieves the StealC infostealer. The operation pioneers a Polygon smart contract for resilient C2 resolution alongside three IP-based fallback C2 servers, and remained active for at least seven weeks (ZIP timestamps Feb 19 - Apr 5, 2026).

- **Published:** 2026-05-05T12:00:00Z
- **Last reviewed:** 2026-05-05T12:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-0457
- **ID:** TL-2026-0457
- **Severity:** HIGH
- **Category:** MALWARE
- **Status:** MONITORING
- **Detections:** 9 · **IOCs:** 18 (full data via the Threadlinqs MCP server — Purple tier)

## Description

Hexastrike Cybersecurity disclosed on April 18, 2026 a large-scale GitHub abuse campaign in which an unidentified threat actor (or tightly coordinated cluster) cloned legitimate open-source projects, embedded malicious payloads, and republished them as 109 distinct repositories across 103 GitHub accounts. The campaign was active for at least seven weeks based on ZIP archive timestamps spanning February 19, 2026 through April 5, 2026, with continued activity observed as of April 12, 2026.

Victims acquire the malicious archive by browsing or searching for what appears to be a legitimate open-source project on GitHub. The actor cloned README content, project structure, and even commit history from genuine repositories (examples include forks of Pyrsistence-style libraries, founders kits, home-assistant integrations, and miscellaneous developer utilities) to lend credibility. Each repository ships a ZIP attachment in the Releases tab or repository root containing a Windows batch launcher (.bat / .cmd) and a packaged LuaJIT runtime plus an obfuscated Lua script. When the user extracts and runs the launcher, it invokes luajit.exe against the bundled script, which acts as SmartLoader: a LuaJIT-implemented stager that decodes embedded shellcode, performs lightweight environment fingerprinting, and downloads the StealC infostealer second stage.

C2 resolution is the campaign's most novel element. SmartLoader does not hardcode a C2 IP or domain at runtime. Instead it issues an eth_call JSON-RPC request to polygon.drpc.org against the Polygon mainnet smart contract at 0x1823A9a0Ec8e0C25dD957D0841e3D41a4474bAdc using function selector 0x3bc5de30. The contract returns the current C2 endpoint(s), which the operators rotate by submitting on-chain transactions. Three IP-based C2 servers have been observed acting as the resolved endpoints: 144.31.57.67, 144.31.57.65 (a /29 neighbor in the same hosting block), and 213.176.73.149. This dead-drop resolver pattern provides operational resilience: defenders cannot sinkhole or seize the resolver because it is a smart contract on a public blockchain, and the operators can pivot infrastructure without re-tooling implants.

SmartLoader's downloaded second stage is StealC, a well-documented infostealer first observed in early 2023 that targets browser cookies, saved credentials, autofill data, cryptocurrency wallet files, Discord and Telegram tokens, FTP client configurations, and document files. StealC exfiltrates collected data over HTTP POST to the C2 endpoint resolved via the Polygon contract.

Observed sample SHA-256 hashes include 2273702dfbcfd96a6ed7bdb42ba130291b653869256ec1325bc7fe30e8d9b70a and 87de3e5a8ef669589c421220cd392ae8027a8f8d3cd97d35ac339f87dcff12c8. Representative malicious repositories include stcitlab1/PyrsistenceSniper, Shonpersus/founders-kit, therajeshpatil/home-assistant-global-health-score, and deepanshugoel99/long.

The campaign expands the typical SmartLoader/StealC delivery beyond gaming-cheat and cracked-software lures into the developer ecosystem, broadening the victim profile to include security researchers, developers, DevOps engineers, and home automation hobbyists who routinely run code from GitHub. Detection should focus on the LuaJIT execution chain on workstations (rare in legitimate developer activity), eth_call traffic to public Polygon RPC endpoints from non-blockchain workloads, and outbound connections to the three identified C2 IPs.

## MITRE ATT&CK

- T1583 Acquire Infrastructure
- T1583.004 Acquire Infrastructure: Server
- T1585.001 Establish Accounts: Social Media Accounts
- T1608.001 Stage Capabilities: Upload Malware
- T1587.001 Develop Capabilities: Malware
- T1195.002 Supply Chain Compromise: Compromise Software Supply Chain
- T1189 Drive-by Compromise
- T1204.002 User Execution: Malicious File
- T1059.003 Command and Scripting Interpreter: Windows Command Shell
- T1059.011 Command and Scripting Interpreter: Lua
- T1027 Obfuscated Files or Information
- T1027.009 Obfuscated Files or Information: Embedded Payloads
- T1140 Deobfuscate/Decode Files or Information
- T1036.005 Match Legitimate Resource Name or Location
- T1553.005 Subvert Trust Controls: Mark-of-the-Web Bypass
- T1082 System Information Discovery
- T1083 File and Directory Discovery
- T1518 Software Discovery
- T1555.003 Credentials from Password Stores: Credentials from Web Browsers
- T1539 Steal Web Session Cookie
- T1552.001 Unsecured Credentials: Credentials In Files
- T1005 Data from Local System
- T1560 Archive Collected Data
- T1102 Web Service
- T1102.001 Web Service: Dead Drop Resolver
- T1071.001 Application Layer Protocol: Web Protocols
- T1105 Ingress Tool Transfer
- T1573.002 Encrypted Channel: Asymmetric Cryptography
- T1041 Exfiltration Over C2 Channel
- T1657 Financial Theft

## Sources

- [Cloned, Loaded, and Stolen: How 109 Fake GitHub Repositories Delivered SmartLoader and StealC](https://hexastrike.com/resources/blog/threat-intelligence/cloned-loaded-and-stolen-how-109-fake-github-repositories-delivered-smartloader-and-stealc/)
- [Malpedia entry - SmartLoader / StealC GitHub campaign](https://malpedia.caad.fkie.fraunhofer.de/library/6df81648-1d2a-4fac-927b-10d28be9e43c/)
- [Malpedia: SmartLoader family page](https://malpedia.caad.fkie.fraunhofer.de/details/win.smartloader)
- [Malpedia: StealC family page](https://malpedia.caad.fkie.fraunhofer.de/details/win.stealc)
- [MITRE ATT&CK T1195.002 Compromise Software Supply Chain](https://attack.mitre.org/techniques/T1195/002/)
- [MITRE ATT&CK T1059.011 Command and Scripting Interpreter: Lua](https://attack.mitre.org/techniques/T1059/011/)
- [MITRE ATT&CK T1102 Web Service (C2 over public services)](https://attack.mitre.org/techniques/T1102/)
- [Polygonscan contract 0x1823A9a0Ec8e0C25dD957D0841e3D41a4474bAdc](https://polygonscan.com/address/0x1823A9a0Ec8e0C25dD957D0841e3D41a4474bAdc)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-0457
