Something is rotting inside GitHub. If you've browsed Trending recently, you've probably noticed: repositories with hundreds of stars that appeared overnight, glowing issue comments that read like they were written by the same person, and contributor profiles with suspiciously perfect green-square grids. Welcome to the Reputation-as-a-Service economy.
This isn't vanity metrics. It's a coordinated effort to trick both GitHub's ranking algorithms and human developers into trusting malicious or low-quality code. And despite years of countermeasures, it's getting worse.
The Numbers: Six Million Fake Stars and Counting
In December 2024, researchers from Carnegie Mellon University, Socket, and North Carolina State University published the most comprehensive study of GitHub star fraud to date. Using a detection tool called StarScout, they analyzed GitHub event data from July 2019 to December 2024 and identified six million suspected fake stars across 15,835 repositories.
The trajectory is alarming. Fake star campaigns grew two orders of magnitude in 2024 alone. At their peak in July 2024, 16% of all repositories with star activity were associated with fake star campaigns, with 3,216 repositories and 30,779 participating bot accounts active in a single month.
GitHub responded by purging flagged accounts: roughly 91% of the identified repositories and 62% of the suspected inauthentic accounts were deleted by October 2024. But researchers found new clusters appearing faster than old ones could be removed. The purge didn't solve the problem; it just reset the scoreboard.
