The editorial argues that Trending's ranking function weights star velocity over authorship reputation, making it trivially gameable. With star-selling services offering ~$50-60 per thousand stars from plausibly-human accounts, a decade-long reliable discovery mechanism has quietly degraded into a leaderboard for whoever can manufacture the cheapest signal.
The editorial notes that 'Free Discord Nitro' repos have been a known malware pattern since at least 2021, documented by Sophos, Trend Micro, and CyberArk. Despite this multi-year paper trail, fresh throwaway accounts like Outsideglutweezers keep landing variants on Trending, often shipping obfuscated Python (exec(base64.b64decode(...))) or executables aimed at stealing credentials.
The editorial flags that today's cohort shares telltale signals: nonsense handles like 'Outsideglutweezers' or single-letter-plus-digits usernames (wy51ai, wangmingxuan666), minimal commit history relative to stars, and README quality that doesn't match the traction. These signals don't prove malice — some repos may be legitimate — but the shape of the pattern is consistent and detectable.
The core structural argument is that Trending's algorithm rewards exactly the signal that's easiest to fake. A dozen active star-selling services, Telegram coordination groups, and 24-72 hour delivery windows mean anyone with $50 can buy a Trending slot. Fixing this requires weighting authorship reputation, account age, or commit history — signals that are expensive to fake — not raw star velocity.
GitHub's Trending page today is surfacing a repo called `Outsideglutweezers/Discord-Nitro-Generator` alongside `wangmingxuan666/Tiersense` and `wy51ai/floorplan-3d`. The Nitro generator is the tell. "Free Discord Nitro" repos have been a known credential-stealer distribution vector since at least 2021 — Sophos, Trend Micro, and CyberArk have all published on the pattern — yet variants keep landing on Trending under fresh throwaway accounts.
The playbook is boring and consistent. A newly-created GitHub account (often with a nonsense handle like `Outsideglutweezers`) pushes a repo with an eye-catching README, sometimes an executable, sometimes a Python script obfuscated with `exec(base64.b64decode(...))`. The account and adjacent sockpuppets then generate a burst of stars over 24–48 hours. Because Trending's ranking function weights star velocity over any signal of authorship reputation, the repo lands on the front page next to legitimate work.
The other two repos in today's cohort aren't obviously malicious, but they carry hallmarks worth noting: single-letter-plus-digits usernames, minimal commit history relative to star count, and README quality that doesn't quite match the traction. Neither has been flagged, and both may be entirely legitimate — but the shape of the signal is what it is.
GitHub Trending was, for roughly a decade, one of the more reliable ambient discovery mechanisms in the developer world. You could open it on a Monday and find `zed`, `bun`, `htmx`, or `ruff` on their way up. That utility has quietly degraded, and the mechanism is worth naming precisely.
Trending is a velocity leaderboard, and velocity is the cheapest signal in software to manufacture. A cursory search surfaces at least a dozen active services selling GitHub stars — the current going rate is roughly $50–60 per thousand stars, delivered over 24–72 hours from accounts that look plausibly human. There are Telegram groups organizing mutual-starring rings among indie devs. There are open-source "star exchange" scripts on, ironically, GitHub itself. The barrier to entry for gaming Trending is a credit card and patience.
Compare this to the signals that are hard to fake: appearance in another project's `package.json` or `Cargo.toml`, a merged PR from a maintainer of an established project, a citation in a tagged release note, download counts on npm/PyPI/crates.io that correlate with unique IPs. These are all still trustworthy because there is no cheap way to fabricate them at scale. Trending, by contrast, is downstream of a metric — the star — that GitHub itself has never invested in defending, because stars aren't monetized and the abuse doesn't threaten enterprise revenue.
The second-order effect is more damaging than the scams themselves: legitimate small projects can't get on Trending anymore without either luck or their own star campaign, so honest maintainers increasingly participate in the same behaviors, which further degrades the signal for everyone. I've watched founder friends debate whether to buy stars — not because they want to deceive, but because the shelf is now crowded with people who did, and organic traction alone no longer clears the ranking bar. This is a classic Akerlof lemons market applied to attention.
The community reaction has been muted, partly because complaining about GitHub Trending feels like complaining about the weather. But the practical consequence is that a discovery channel that used to route serious developers toward serious tools now routes juniors, students, and drive-by browsers toward whatever gamed the algorithm this week. When one of those repos is a credential stealer targeting Discord tokens — which, for a lot of young developers, is the same account tied to their GitHub SSO — the harm stops being theoretical.
If you or anyone on your team is still opening `github.com/trending` as a way to find libraries or tools to evaluate, adjust the workflow. Treat Trending the way you'd treat a Product Hunt front page: it's a lead list of things that got attention, not a filtered list of things worth your time.
A few concrete substitutions that have held up better:
- Dependency-graph discovery. For a given ecosystem, look at what your existing trusted dependencies depend on. Cargo's `crates.io` reverse-dep view, npm's `dependents` API, and `deps.dev` all expose this and none of it is star-manipulable at any useful scale. - Maintainer follow-graph. Follow ten to twenty maintainers you already trust and rely on their stars/retweets/mentions rather than an aggregate leaderboard. Star inflation collapses at the individual-attestation level because a specific person's reputation is on the line. - Release-notes surfacing. Tools like `newreleases.io` or a simple RSS aggregator over a curated repo list will beat Trending on precision by an order of magnitude for tracking things you already know you care about. - CVE and typo-squat scanning at install time. If a junior dev on your team is going to install something they found on Trending, `npm audit`, `pip-audit`, and `socket.dev`-style provenance checks catch a meaningful fraction of the credential-stealer class of attack before it executes.
On the trust hygiene front, worth reminding people that a repo appearing on GitHub Trending confers zero endorsement from GitHub. There is no review, no vetting, no takedown SLA beyond the standard abuse-report queue. A repo can be on the front page for hours while GitHub's trust and safety team processes reports against it.
The honest fix would be a Trending page that weights something other than raw star velocity — median account age of starrers, prior-90-day activity of starrers, whether starrers have other repos they've contributed to, or downloads-per-star on package registries where relevant. GitHub has all of this data. What it doesn't have, apparently, is a business reason to spend engineering cycles on it. Until that changes, Trending will keep drifting toward the equilibrium every unpoliced ranking eventually reaches, and the developers who need discovery signals most — the ones new enough to not have a maintainer follow-graph yet — will keep being the ones most exposed to the noise.
Top 10 dev stories every morning at 8am UTC. AI-curated. Retro terminal HTML email.