Six Million (Suspected) Fake Stars on GitHub: A Growing Spiral of Popularity Contests, Spams, and Malware
Hao He, Haoqin Yang, Philipp Burckhardt, Alexandros Kapravelos, Bogdan Vasilescu, Christian Kästner
摘要
GitHub, the de facto platform for open-source software development, provides a set of social-media-like features to signal high-quality repositories. Among them, the star count is the most widely used popularity signal, but it is also at risk of being artificially inflated (i.e., faked), decreasing its value as a decision-making signal and posing a security risk to all GitHub users. In this paper, we present a systematic, global, and longitudinal measurement study of fake stars in GitHub. To this end, we build StarScout, a scalable tool able to detect anomalous starring behaviors across all GitHub metadata between 2019 and 2024. Analyzing the data collected using StarScout, we find that: (1) fake-star-related activities have rapidly surged in 2024; (2) the accounts and repositories in fake star campaigns have highly trivial activity patterns; (3) the majority of fake stars are used to promote short-lived phishing malware repositories; the remaining ones are mostly used to promote AI/LLM, blockchain, tool/application, and tutorial/demo repositories; (4) while repositories may have acquired fake stars for growth hacking, fake stars only have a promotion effect in the short term (i.e., less than two months) and become a liability in the long term. Our study has implications for platform moderators, open-source practitioners, and supply chain security researchers.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper4
- ConfuGuard: Using Metadata to Detect Active and Stealthy Package Confusion Attacks Accurately and at ScaleWenxin Jiang, Berk Çakar, Mikola Lysenko, James C DavisICSE 2026 · 被引用 2 次
- Inequality in the Age of PseudonymityAviv Yaish, Nir Chemaya, Dahlia Malkhi, Lin William CongAAAI 2026 · 被引用 1 次
- “Write in English, Nobody Understands Your Language Here”: A Study of Non-English Trends in Open-Source RepositoriesMasudul Hasan Masud Bhuiyan, Manish Kumar Bala Kumar, Cristian-Alexandru StaicuICSE 2026 · 被引用 1 次
- MalTotal: Cost-Effective and Language-Agnostic Malicious Code Poisoning Detection for Millions of RepositoriesJian Zhao, Shenao Wang, Qingyang Wu, Yanjie Zhao 等ISSTA 2026
它引用的顶会 Paper5
- Selecting third-party libraries: the practitioners' perspectiveEnrique Larios Vargas, Maurício Finavaro Aniche, Christoph Treude, Magiel Bruntink 等FSE 2020 · 被引用 81 次
- Committed to Trust: A Qualitative Study on Security & Trust in Open Source Software ProjectsDominik Wermke, Noah Wöhler, Jan H. Klemmer, Marcel Fourné 等S&P 2022 · 被引用 54 次
- Exposing the Hidden Layer: Software Repositories in the Service of Seo ManipulationMengying Wu, Geng Hong, Wuyuao Mai, Xinyi Wu 等ICSE 2025 · 被引用 1 次
- Ethical Frameworks and Computer Security Trolley Problems: Foundations for ConversationsTadayoshi Kohno, Yasemin Acar, Wulf LohUSENIX Security 2023
- SoK: Taxonomy of Attacks on Open-Source Software Supply ChainsPiergiorgio Ladisa, Henrik Plate, Matias Martinez, Olivier BaraisS&P 2023
相关 Paper
- "This Is Damn Slick!" Estimating the Impact of Tweets on Open Source Project Popularity and New ContributorsHongbo Fang, Hemank Lamba, James D. Herbsleb, Bogdan VasilescuICSE 2022 · 被引用 18 次
- The Effectiveness of Security Interventions on GitHubFelix Fischer, Jonas Höbenreich, Jens GrossklagsCCS 2023 · 被引用 4 次
- Who's Pushing the Code? An Exploration of GitHub ImpersonationYueke Zhang, Anda Liang, Xiaohan Wang, Pamela J. Wisniewski 等ICSE 2025 · 被引用 2 次
- Rep2Vec: Repository Embedding via Heterogeneous Graph Adversarial Contrastive LearningYiyue Qian, Yiming Zhang, Qianlong Wen, Yanfang Ye 等KDD 2022 · 被引用 17 次
- Attributing Open-Source Contributions is Critical but Difficult: A Systematic Analysis of GitHub Practices and Their Impact on Software Supply Chain SecurityJan-Ulrich Holtgrave, Kay Friedrich, Fabian Fischer, Nicolas Huaman 等NDSS 2025
