Lemmy.one
  • Communities
  • Create Post
  • heart
    Support Lemmy
  • search
    Search
  • Login
  • Sign Up
Lemmit.Online bot@lemmit.onlineMB to Open Source on Reddit@lemmit.onlineEnglish · 7 months ago

4.5 Million (Suspected) Fake Stars in GitHub: A Growing Spiral of Popularity Contests, Scams, and Malware

arxiv.org

external-link
message-square
0
fedilink
  • cross-posted to:
  • programming@programming.dev
  • technology@beehaw.org
1
external-link

4.5 Million (Suspected) Fake Stars in GitHub: A Growing Spiral of Popularity Contests, Scams, and Malware

arxiv.org

Lemmit.Online bot@lemmit.onlineMB to Open Source on Reddit@lemmit.onlineEnglish · 7 months ago
message-square
0
fedilink
  • cross-posted to:
  • programming@programming.dev
  • technology@beehaw.org
GitHub, the de-facto platform for open-source software development, provides a set of social-media-like features to signal high-quality repositories. Among them, the star count is the most widely used popularity signal, but it is also at risk of being artificially inflated (i.e., faked), decreasing its value as a decision-making signal and posing a security risk to all GitHub users. In this paper, we present a systematic, global, and longitudinal measurement study of fake stars in GitHub. To this end, we build StarScout, a scalable tool able to detect anomalous starring behaviors (i.e., low activity and lockstep) across the entire GitHub metadata. Analyzing the data collected using StarScout, we find that: (1) fake-star-related activities have rapidly surged since 2024; (2) the user profile characteristics of fake stargazers are not distinct from average GitHub users, but many of them have highly abnormal activity patterns; (3) the majority of fake stars are used to promote short-lived malware repositories masquerading as pirating software, game cheats, or cryptocurrency bots; (4) some repositories may have acquired fake stars for growth hacking, but fake stars only have a promotion effect in the short term (i.e., less than two months) and become a burden in the long term. Our study has implications for platform moderators, open-source practitioners, and supply chain security researchers.
This is an automated archive made by the Lemmit Bot.

The original was posted on /r/opensource by /u/TradingAllIn on 2025-01-02 20:36:39+00:00.

alert-triangle
You must log in or # to comment.

Open Source on Reddit@lemmit.online

opensource@lemmit.online

Subscribe from Remote Instance

You are not logged in. However you can subscribe from another Fediverse account, for example Lemmy or Mastodon. To do this, paste the following into the search field of your instance: !opensource@lemmit.online
lock
Community locked: only moderators can create posts. You can still comment on posts.

A subreddit for everything open source related.

Visibility: Public
globe

This community can be federated to other instances and be posted/commented in by their users.

  • 1 user / day
  • 1 user / week
  • 4 users / month
  • 15 users / 6 months
  • 1 local subscriber
  • 84 subscribers
  • 1.21K Posts
  • 2 Comments
  • Modlog
  • mods:
  • Lemmit.Online bot@lemmit.online
  • BE: 0.19.7
  • Modlog
  • Legal
  • Instances
  • Docs
  • Code
  • join-lemmy.org