4.5 Million Fake GitHub Stars: A Shadowy Popularity Contest

2025-01-02

A new study reveals 4.5 million suspected fake stars on GitHub, primarily used to promote short-lived malware repositories disguised as pirated software, game cheats, or cryptocurrency bots. Researchers developed StarScout, a tool to detect anomalous starring behavior. The study shows a rapid surge in fake star activity since 2024. While fake stargazers don't differ significantly from average users in profile characteristics, their activity patterns are highly abnormal. While offering short-term promotional benefits, fake stars ultimately become a long-term burden. This research has significant implications for platform moderators, open-source practitioners, and supply chain security researchers.

Tech