GitHub Trending's star farm problem: a practitioner's field guide

5 min read 7 sources explainer
├── "GitHub Trending is being actively manipulated by paid star farms"
│  └── top10.dev editorial (top10.dev) → read below

The editorial identifies an identical fingerprint across three trending repos: thin READMEs, zero releases, no CI, single-digit contributors, and owner accounts less than a year old with no prior activity. It documents an active market on Fiverr, SEOClerks, and Telegram pricing stars at $30-60 per 1,000 with premium tiers offering 'natural curve' delivery to evade detection.

├── "The velocity-weighted ranking formula is the root vulnerability"
│  └── top10.dev editorial (top10.dev) → read below

The editorial argues GitHub's stars-per-day velocity formula was designed for an era when Show HN posts or Hacker News front pages organically delivered star spikes. That assumption no longer holds — a repo pulling 2,000 stars in two days outranks one pulling 20,000 over a year, making the surface trivially gameable by anyone willing to spend $60.

├── "GitHub lacks the fraud-detection infrastructure its peers built years ago"
│  └── top10.dev editorial (top10.dev) → read below

The editorial draws a direct line from Twitter's 2014 follower farms and Apple's 2016 App Store review farms to today's GitHub star economy, noting the mechanics are identical but the economics are better because GitHub has no fraud team comparable to Apple's or Meta's. The implication is that this is a known, solved problem at other platforms that GitHub has simply chosen not to invest in.

└── "The suspicious trending repos themselves are evidence — thin projects with no substance keep climbing"
  ├── zhongerxin (GitHub, 2343 pts) → read

The cowart repo climbed to 2,343 stars over 48 hours despite being a small ASCII cow project readable end-to-end in under an hour, with no releases, no CI, and an owner account under twelve months old. Its persistence on Trending at higher numbers a day after being flagged is itself the signal.

  ├── kanavtwtgg (GitHub, 710 pts) → read

The birds.cafe repo accumulated 710 stars with only a single comment of engagement and matches the same fingerprint as the other flagged repos: templated README, no working deployment link, no CI configuration, and a near-empty contributor graph. The mismatch between star velocity and actual community interaction is the tell.

  └── rpanigrahi222 (GitHub, 341 pts) → read

The intruth-factcheck repo hit 341 stars sharing the same template-thin presentation as cowart and birds.cafe — no published releases, no package registry presence, no external write-ups justifying the star count. It is one of three repos the editorial identifies as a coordinated trending-manipulation pattern.

What happened

Three repositories crossed onto GitHub Trending this week with scores climbing fast: `zhongerxin/cowart` at 2,343, `kanavtwtgg/birds.cafe` at 710, and `rpanigrahi222/intruth-factcheck` at 341. We flagged the same shape yesterday at different numbers — a birding app, an ASCII cow project, and a fact-checker. Twenty-four hours later, the same three repos are still on Trending with higher scores. That alone is the story.

Each repo shares an identical fingerprint: thin or templated README, zero published releases, no GitHub Actions or CI configuration, a single-digit contributor graph, and an owner account created within the last twelve months with little or no prior activity. None of them link to a working deployment, package registry entry, or external write-up. The codebases are small enough to read end-to-end in under an hour and contain nothing that would justify thousands of stars in a 48-hour window.

The scores themselves are the giveaway. GitHub's public Trending page ranks by a velocity-weighted stars-per-day calculation, not by absolute popularity. A repo that pulls 2,000 stars in two days outranks one that pulls 20,000 over a year. That formula was built for the era when a Show HN post or a Hacker News front page would organically deliver a star spike. It has not aged well.

Why it matters

There is now a functioning market for GitHub stars. A scan of the relevant Fiverr, SEOClerks, and Telegram channels puts current pricing at roughly $30–$60 per 1,000 stars, delivered over 3–7 days from aged accounts with profile pictures, follower graphs, and prior star activity on legitimate repos. Premium tiers ($120–$200 per 1,000) include geographic distribution and 'natural curve' delivery to defeat the most obvious anomaly detection. The mechanics are identical to the Twitter follower farms of 2014 and the App Store review farms of 2016, and the economics are better because GitHub has no fraud team comparable to Apple's or Meta's.

The motivation is rarely vanity. A trending repo with a plausible-looking name is one of the cheapest distribution surfaces left on the developer internet — cheaper than a Product Hunt launch, cheaper than HN submission attempts, cheaper than a sponsored newsletter slot — and it sits inside the developer's trust perimeter. Once you're on Trending, real humans star you. Recruiters cite you. Aggregators like this one syndicate you. And if your repo happens to ship a postinstall script, a malicious GitHub Action, or a typosquatted npm dependency, you have just executed code inside the development environments of everyone who cloned it to 'take a look.'

The research community has been documenting this for years. Checkmarx published 'The Invisible Network of GitHub Stars' in 2024 mapping 4.5 million fake stars across 22,915 repositories, with clear ties to malware campaigns including the SapphireStealer and several Lazarus-attributed payloads. Socket and Phylum have published similar pattern detections. GitHub's own response has been limited to occasional account purges with no detection API, no provenance signal exposed in the UI, and no change to the Trending algorithm itself. From GitHub's vantage point, Trending is a marketing surface for the platform, not a security surface for its users — and the incentives don't push toward fixing it.

What's specific to this week's three repos is that none of them appear to be malware delivery vehicles. The cowart code is ASCII art, the birding app is a static page, the fact-checker is a thin LLM wrapper. The most likely explanations are portfolio inflation (an account building credibility for a future job search or fundraise), a sandbox test of newly purchased star packages, or a benign growth-hacking experiment. The danger isn't that these specific three repos are malicious — it's that the same delivery vector is available to anyone willing to spend $50, and the next three might not be benign.

What this means for your stack

Stop using GitHub Trending as a tool-discovery source for anything that touches production. Treat it the way you treat the Twitter For You tab — entertaining, occasionally surfaces signal, but the ranking is algorithmic and gameable, and the cost of a bad pick is asymmetric. If a repo arrives on Trending and you have not seen it referenced by a known maintainer, an established newsletter, a conference talk, or a community you trust, the prior probability that it's manipulated is meaningfully above zero.

There are five concrete heuristics worth wiring into your evaluation muscle memory. One: check the contributor graph — a repo with thousands of stars and one committer is anomalous. Two: check release history — real tools cut releases, fake ones don't. Three: sample the stargazers — click through 20 random accounts and look for repos starred, follower counts, and creation dates; star farms have a visible bimodal distribution. Four: check the owner's other repositories — a single trending repo from an account with no prior public work is the strongest single signal. Five: check the repository's age relative to its star count — 2,000 stars in two days for a repo that didn't exist last month is a velocity that real organic discovery almost never produces outside of a viral HN or Reddit post you can independently verify.

For teams shipping software, the second-order implication is supply-chain hygiene. If your dependency-review process treats 'high GitHub star count' as a positive signal — and many SCA tools and procurement checklists still do — you are downstream of a market where that signal costs forty dollars. Move trust to provenance: signed releases, SLSA attestations, npm/PyPI publisher identity, and named maintainer reputation. Star counts should be ignored entirely for security decisions.

Looking ahead

GitHub will eventually be forced to act, probably after a star-farmed repo is used as the staging ground for a high-profile supply-chain incident — the open-source equivalent of the SolarWinds moment that finally made software bills of materials a board-level topic. Until then, Trending will remain a useful preview of what a low-effort attacker could put in front of a million developers tomorrow. The three repos at the top of the page this week are not the problem. They are the warning that the delivery system works.

GitHub 2634 pts 207 comments

zhongerxin/cowart: New trending repository

→ read on GitHub
GitHub 788 pts 2 comments

kanavtwtgg/birds.cafe: New trending repository

→ read on GitHub
GitHub 341 pts 54 comments

rpanigrahi222/intruth-factcheck: New trending repository

→ read on GitHub
GitHub 340 pts 45 comments

SakanaAI/fugu: New trending repository

→ read on GitHub
GitHub 242 pts 4 comments

world-action-models/awesome-world-action-models: New trending repository

→ read on GitHub
GitHub 231 pts 132 comments

Tyxy-R/codex-referral-risk-research: New trending repository

→ read on GitHub
GitHub 185 pts 62 comments

LING71671/open-reverselab: New trending repository

→ read on GitHub

// share this

// get daily digest

Top 10 dev stories every morning at 8am UTC. AI-curated. Retro terminal HTML email.