GitHub Trending is broken — and the incentives explain why

4 min read 6 sources clear_take
├── "GitHub Trending has been compromised by star-farming and scam repos, degrading its value as a discovery mechanism"
│  └── top10.dev editorial (top10.dev) → read below

The editorial argues that Trending's ranking function weights star velocity over authorship reputation, making it trivially gameable. With star-selling services offering ~$50-60 per thousand stars from plausibly-human accounts, a decade-long reliable discovery mechanism has quietly degraded into a leaderboard for whoever can manufacture the cheapest signal.

├── "Discord Nitro generator repos are a well-documented credential-stealer distribution vector that GitHub keeps failing to block"
│  └── top10.dev editorial (top10.dev) → read below

The editorial notes that 'Free Discord Nitro' repos have been a known malware pattern since at least 2021, documented by Sophos, Trend Micro, and CyberArk. Despite this multi-year paper trail, fresh throwaway accounts like Outsideglutweezers keep landing variants on Trending, often shipping obfuscated Python (exec(base64.b64decode(...))) or executables aimed at stealing credentials.

├── "Suspicious repo patterns are recognizable — throwaway usernames, thin commit history, and README quality mismatched to star count"
│  └── top10.dev editorial (top10.dev) → read below

The editorial flags that today's cohort shares telltale signals: nonsense handles like 'Outsideglutweezers' or single-letter-plus-digits usernames (wy51ai, wangmingxuan666), minimal commit history relative to stars, and README quality that doesn't match the traction. These signals don't prove malice — some repos may be legitimate — but the shape of the pattern is consistent and detectable.

└── "Velocity-based ranking is fundamentally the wrong signal because velocity is the cheapest thing to manufacture in software"
  └── top10.dev editorial (top10.dev) → read below

The core structural argument is that Trending's algorithm rewards exactly the signal that's easiest to fake. A dozen active star-selling services, Telegram coordination groups, and 24-72 hour delivery windows mean anyone with $50 can buy a Trending slot. Fixing this requires weighting authorship reputation, account age, or commit history — signals that are expensive to fake — not raw star velocity.

What happened

GitHub's Trending page today is surfacing a repo called `Outsideglutweezers/Discord-Nitro-Generator` alongside `wangmingxuan666/Tiersense` and `wy51ai/floorplan-3d`. The Nitro generator is the tell. "Free Discord Nitro" repos have been a known credential-stealer distribution vector since at least 2021 — Sophos, Trend Micro, and CyberArk have all published on the pattern — yet variants keep landing on Trending under fresh throwaway accounts.

The playbook is boring and consistent. A newly-created GitHub account (often with a nonsense handle like `Outsideglutweezers`) pushes a repo with an eye-catching README, sometimes an executable, sometimes a Python script obfuscated with `exec(base64.b64decode(...))`. The account and adjacent sockpuppets then generate a burst of stars over 24–48 hours. Because Trending's ranking function weights star velocity over any signal of authorship reputation, the repo lands on the front page next to legitimate work.

The other two repos in today's cohort aren't obviously malicious, but they carry hallmarks worth noting: single-letter-plus-digits usernames, minimal commit history relative to star count, and README quality that doesn't quite match the traction. Neither has been flagged, and both may be entirely legitimate — but the shape of the signal is what it is.

Why it matters

GitHub Trending was, for roughly a decade, one of the more reliable ambient discovery mechanisms in the developer world. You could open it on a Monday and find `zed`, `bun`, `htmx`, or `ruff` on their way up. That utility has quietly degraded, and the mechanism is worth naming precisely.

Trending is a velocity leaderboard, and velocity is the cheapest signal in software to manufacture. A cursory search surfaces at least a dozen active services selling GitHub stars — the current going rate is roughly $50–60 per thousand stars, delivered over 24–72 hours from accounts that look plausibly human. There are Telegram groups organizing mutual-starring rings among indie devs. There are open-source "star exchange" scripts on, ironically, GitHub itself. The barrier to entry for gaming Trending is a credit card and patience.

Compare this to the signals that are hard to fake: appearance in another project's `package.json` or `Cargo.toml`, a merged PR from a maintainer of an established project, a citation in a tagged release note, download counts on npm/PyPI/crates.io that correlate with unique IPs. These are all still trustworthy because there is no cheap way to fabricate them at scale. Trending, by contrast, is downstream of a metric — the star — that GitHub itself has never invested in defending, because stars aren't monetized and the abuse doesn't threaten enterprise revenue.

The second-order effect is more damaging than the scams themselves: legitimate small projects can't get on Trending anymore without either luck or their own star campaign, so honest maintainers increasingly participate in the same behaviors, which further degrades the signal for everyone. I've watched founder friends debate whether to buy stars — not because they want to deceive, but because the shelf is now crowded with people who did, and organic traction alone no longer clears the ranking bar. This is a classic Akerlof lemons market applied to attention.

The community reaction has been muted, partly because complaining about GitHub Trending feels like complaining about the weather. But the practical consequence is that a discovery channel that used to route serious developers toward serious tools now routes juniors, students, and drive-by browsers toward whatever gamed the algorithm this week. When one of those repos is a credential stealer targeting Discord tokens — which, for a lot of young developers, is the same account tied to their GitHub SSO — the harm stops being theoretical.

What this means for your stack

If you or anyone on your team is still opening `github.com/trending` as a way to find libraries or tools to evaluate, adjust the workflow. Treat Trending the way you'd treat a Product Hunt front page: it's a lead list of things that got attention, not a filtered list of things worth your time.

A few concrete substitutions that have held up better:

- Dependency-graph discovery. For a given ecosystem, look at what your existing trusted dependencies depend on. Cargo's `crates.io` reverse-dep view, npm's `dependents` API, and `deps.dev` all expose this and none of it is star-manipulable at any useful scale. - Maintainer follow-graph. Follow ten to twenty maintainers you already trust and rely on their stars/retweets/mentions rather than an aggregate leaderboard. Star inflation collapses at the individual-attestation level because a specific person's reputation is on the line. - Release-notes surfacing. Tools like `newreleases.io` or a simple RSS aggregator over a curated repo list will beat Trending on precision by an order of magnitude for tracking things you already know you care about. - CVE and typo-squat scanning at install time. If a junior dev on your team is going to install something they found on Trending, `npm audit`, `pip-audit`, and `socket.dev`-style provenance checks catch a meaningful fraction of the credential-stealer class of attack before it executes.

On the trust hygiene front, worth reminding people that a repo appearing on GitHub Trending confers zero endorsement from GitHub. There is no review, no vetting, no takedown SLA beyond the standard abuse-report queue. A repo can be on the front page for hours while GitHub's trust and safety team processes reports against it.

Looking ahead

The honest fix would be a Trending page that weights something other than raw star velocity — median account age of starrers, prior-90-day activity of starrers, whether starrers have other repos they've contributed to, or downloads-per-star on package registries where relevant. GitHub has all of this data. What it doesn't have, apparently, is a business reason to spend engineering cycles on it. Until that changes, Trending will keep drifting toward the equilibrium every unpoliced ranking eventually reaches, and the developers who need discovery signals most — the ones new enough to not have a maintainer follow-graph yet — will keep being the ones most exposed to the noise.

GitHub 1301 pts 268 comments

wy51ai/floorplan-3d: New trending repository

→ read on GitHub
GitHub 505 pts 94 comments

wangmingxuan666/Tiersense: New trending repository

→ read on GitHub
GitHub 470 pts 85 comments

xikhar/spiderbench: New trending repository

→ read on GitHub
GitHub 425 pts 62 comments

LuwuDynamics/xgoduck_hardware: New trending repository

→ read on GitHub
GitHub 412 pts 40 comments

Outsideglutweezers/Discord-Nitro-Generator: New trending repository

→ read on GitHub
GitHub 385 pts 28 comments

Rieranthony/product-film-skill: New trending repository

→ read on GitHub

// share this

// get daily digest

Top 10 dev stories every morning at 8am UTC. AI-curated. Retro terminal HTML email.