Six Million (Suspected) Fake Stars on GitHub: A Growing Spiral of Popularity Contests, Spams, and Malware
Hao He, Haoqin Yang, Philipp Burckhardt, Alexandros Kapravelos, Bogdan Vasilescu, Christian Kästner
Abstract
GitHub, the de facto platform for open-source software development, provides a set of social-media-like features to signal high-quality repositories. Among them, the star count is the most widely used popularity signal, but it is also at risk of being artificially inflated (i.e., faked), decreasing its value as a decision-making signal and posing a security risk to all GitHub users. In this paper, we present a systematic, global, and longitudinal measurement study of fake stars in GitHub. To this end, we build StarScout, a scalable tool able to detect anomalous starring behaviors across all GitHub metadata between 2019 and 2024. Analyzing the data collected using StarScout, we find that: (1) fake-star-related activities have rapidly surged in 2024; (2) the accounts and repositories in fake star campaigns have highly trivial activity patterns; (3) the majority of fake stars are used to promote short-lived phishing malware repositories; the remaining ones are mostly used to promote AI/LLM, blockchain, tool/application, and tutorial/demo repositories; (4) while repositories may have acquired fake stars for growth hacking, fake stars only have a promotion effect in the short term (i.e., less than two months) and become a liability in the long term. Our study has implications for platform moderators, open-source practitioners, and supply chain security researchers.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 410602e4-ddb6-4bd5-8034-e6bb60c4bb35Cited by top-tier papers4
- ConfuGuard: Using Metadata to Detect Active and Stealthy Package Confusion Attacks Accurately and at ScaleWenxin Jiang, Berk Çakar, Mikola Lysenko, James C DavisICSE 2026 · 2 citations
- Inequality in the Age of PseudonymityAviv Yaish, Nir Chemaya, Dahlia Malkhi, Lin William CongAAAI 2026 · 1 citation
- “Write in English, Nobody Understands Your Language Here”: A Study of Non-English Trends in Open-Source RepositoriesMasudul Hasan Masud Bhuiyan, Manish Kumar Bala Kumar, Cristian-Alexandru StaicuICSE 2026 · 1 citation
- MalTotal: Cost-Effective and Language-Agnostic Malicious Code Poisoning Detection for Millions of RepositoriesJian Zhao, Shenao Wang, Qingyang Wu, Yanjie Zhao et al.ISSTA 2026
Builds on5
- Selecting third-party libraries: the practitioners' perspectiveEnrique Larios Vargas, Maurício Finavaro Aniche, Christoph Treude, Magiel Bruntink et al.FSE 2020 · 81 citations
- Committed to Trust: A Qualitative Study on Security & Trust in Open Source Software ProjectsDominik Wermke, Noah Wöhler, Jan H. Klemmer, Marcel Fourné et al.S&P 2022 · 54 citations
- Exposing the Hidden Layer: Software Repositories in the Service of Seo ManipulationMengying Wu, Geng Hong, Wuyuao Mai, Xinyi Wu et al.ICSE 2025 · 1 citation
- Ethical Frameworks and Computer Security Trolley Problems: Foundations for ConversationsTadayoshi Kohno, Yasemin Acar, Wulf LohUSENIX Security 2023
- SoK: Taxonomy of Attacks on Open-Source Software Supply ChainsPiergiorgio Ladisa, Henrik Plate, Matias Martinez, Olivier BaraisS&P 2023
Related papers
- "This Is Damn Slick!" Estimating the Impact of Tweets on Open Source Project Popularity and New ContributorsHongbo Fang, Hemank Lamba, James D. Herbsleb, Bogdan VasilescuICSE 2022 · 18 citations
- The Effectiveness of Security Interventions on GitHubFelix Fischer, Jonas Höbenreich, Jens GrossklagsCCS 2023 · 4 citations
- Who's Pushing the Code? An Exploration of GitHub ImpersonationYueke Zhang, Anda Liang, Xiaohan Wang, Pamela J. Wisniewski et al.ICSE 2025 · 2 citations
- Rep2Vec: Repository Embedding via Heterogeneous Graph Adversarial Contrastive LearningYiyue Qian, Yiming Zhang, Qianlong Wen, Yanfang Ye et al.KDD 2022 · 17 citations
- Attributing Open-Source Contributions is Critical but Difficult: A Systematic Analysis of GitHub Practices and Their Impact on Software Supply Chain SecurityJan-Ulrich Holtgrave, Kay Friedrich, Fabian Fischer, Nicolas Huaman et al.NDSS 2025
