Six Million (Suspected) Fake Stars in GitHub: A Growing Spiral of Popularity Contests, Spams, and Malware
Fuente:
arXiv
Saved in:
| Main Authors: | He, Hao, Yang, Haoqin, Burckhardt, Philipp, Kapravelos, Alexandros, Vasilescu, Bogdan, Kästner, Christian |
|---|---|
| Format: | Preprint |
| Published: |
2024
|
| Subjects: | |
| Online Access: | |
| Tags: |
Add Tag
No Tags, Be the first to tag this record!
|
Similar Items
Pinning Is Futile: You Need More Than Local Dependency Versioning to Defend against Supply Chain Attacks
by: He, Hao, et al.
Published: (2025)
by: He, Hao, et al.
Published: (2025)
Unpacking Security Scanners for GitHub Actions Workflows
by: Fares, Madjda, et al.
Published: (2026)
by: Fares, Madjda, et al.
Published: (2026)
On the effectiveness of Large Language Models for GitHub Workflows
by: Zhang, Xinyu, et al.
Published: (2024)
by: Zhang, Xinyu, et al.
Published: (2024)
Is GitHub's Copilot as Bad as Humans at Introducing Vulnerabilities in Code?
by: Asare, Owura, et al.
Published: (2022)
by: Asare, Owura, et al.
Published: (2022)
Characterizing and Modeling the GitHub Security Advisories Review Pipeline
by: Segal, Claudio, et al.
Published: (2026)
by: Segal, Claudio, et al.
Published: (2026)
Exploring User Privacy Awareness on GitHub: An Empirical Study
by: Alfieri, Costanza, et al.
Published: (2024)
by: Alfieri, Costanza, et al.
Published: (2024)
Can Highlighting Help GitHub Maintainers Track Security Fixes?
by: Liu, Xueqing, et al.
Published: (2024)
by: Liu, Xueqing, et al.
Published: (2024)
Security Weaknesses of Copilot-Generated Code in GitHub Projects: An Empirical Study
by: Fu, Yujia, et al.
Published: (2023)
by: Fu, Yujia, et al.
Published: (2023)
Unveiling A Hidden Risk: Exposing Educational but Malicious Repositories in GitHub
by: Masud, Md Rayhanul, et al.
Published: (2024)
by: Masud, Md Rayhanul, et al.
Published: (2024)
On the Prevalence and Usage of Commit Signing on GitHub: A Longitudinal and Cross-Domain Study
by: Sharma, Anupam, et al.
Published: (2025)
by: Sharma, Anupam, et al.
Published: (2025)
Security in the Age of AI Teammates: An Empirical Study of Agentic Pull Requests on GitHub
by: Siddiq, Mohammed Latif, et al.
Published: (2026)
by: Siddiq, Mohammed Latif, et al.
Published: (2026)
Heimdallr: Characterizing and Detecting LLM-Induced Security Risks in GitHub CI Workflows
by: Ruan, Bonan, et al.
Published: (2026)
by: Ruan, Bonan, et al.
Published: (2026)
IssueGuard: Real-Time Secret Leak Prevention Tool for GitHub Issue Reports
by: Rahman, Md Nafiu, et al.
Published: (2026)
by: Rahman, Md Nafiu, et al.
Published: (2026)
LLM-Enabled Open-Source Systems in the Wild: An Empirical Study of Vulnerabilities in GitHub Security Advisories
by: Shifat, Fariha Tanjim, et al.
Published: (2026)
by: Shifat, Fariha Tanjim, et al.
Published: (2026)
Bugdar: AI-Augmented Secure Code Review for GitHub Pull Requests
by: Naulty, John, et al.
Published: (2025)
by: Naulty, John, et al.
Published: (2025)
Security Concerns in Generative AI Coding Assistants: Insights from Online Discussions on GitHub Copilot
by: Ferreyra, Nicolás E. Díaz, et al.
Published: (2026)
by: Ferreyra, Nicolás E. Díaz, et al.
Published: (2026)
Automating the Detection of Code Vulnerabilities by Analyzing GitHub Issues
by: Cipollone, Daniele, et al.
Published: (2025)
by: Cipollone, Daniele, et al.
Published: (2025)
Granite: Granular Runtime Enforcement for GitHub Actions Permissions
by: Moazen, Mojtaba, et al.
Published: (2025)
by: Moazen, Mojtaba, et al.
Published: (2025)
Demystifying and Detecting Agentic Workflow Injection Vulnerabilities in GitHub Actions
by: Wang, Shenao, et al.
Published: (2026)
by: Wang, Shenao, et al.
Published: (2026)
Multi-Agent Taint Specification Extraction for Vulnerability Detection
by: Ghebremichael, Jonah, et al.
Published: (2026)
by: Ghebremichael, Jonah, et al.
Published: (2026)
FV8: A Forced Execution JavaScript Engine for Detecting Evasive Techniques
by: Pantelaios, Nikolaos, et al.
Published: (2024)
by: Pantelaios, Nikolaos, et al.
Published: (2024)
Manifest V3 Unveiled: Navigating the New Era of Browser Extensions
by: Pantelaios, Nikolaos, et al.
Published: (2024)
by: Pantelaios, Nikolaos, et al.
Published: (2024)
Eradicating the Unseen: Detecting, Exploiting, and Remediating a Path Traversal Vulnerability across GitHub
by: Akhoundali, Jafar, et al.
Published: (2025)
by: Akhoundali, Jafar, et al.
Published: (2025)
A Study of Malware Prevention in Linux Distributions
by: Vu, Duc-Ly, et al.
Published: (2024)
by: Vu, Duc-Ly, et al.
Published: (2024)
Security Vulnerabilities in AI-Generated Code: A Large-Scale Analysis of Public GitHub Repositories
by: Schreiber, Maximilian, et al.
Published: (2025)
by: Schreiber, Maximilian, et al.
Published: (2025)
Identifying Adversary Tactics and Techniques in Malware Binaries with an LLM Agent
by: Xuan, Zhou, et al.
Published: (2026)
by: Xuan, Zhou, et al.
Published: (2026)
BIDO: An Out-Of-Distribution Resistant Image-based Malware Detector
by: Wang, Wei, et al.
Published: (2025)
by: Wang, Wei, et al.
Published: (2025)
MARD: A Multi-Agent Framework for Robust Android Malware Detection
by: Zeng, Xueying, et al.
Published: (2026)
by: Zeng, Xueying, et al.
Published: (2026)
A Time Series Analysis of Malware Uploads to Programming Language Ecosystems
by: Ruohonen, Jukka, et al.
Published: (2025)
by: Ruohonen, Jukka, et al.
Published: (2025)
FCGHunter: Towards Evaluating Robustness of Graph-Based Android Malware Detection
by: Song, Shiwen, et al.
Published: (2025)
by: Song, Shiwen, et al.
Published: (2025)
Detecting Android Malware by Visualizing App Behaviors from Multiple Complementary Views
by: Meng, Zhaoyi, et al.
Published: (2024)
by: Meng, Zhaoyi, et al.
Published: (2024)
Enhancing Android Malware Detection: The Influence of ChatGPT on Decision-centric Task
by: Li, Yao, et al.
Published: (2024)
by: Li, Yao, et al.
Published: (2024)
MalCVE: Malware Detection and CVE Association Using Large Language Models
by: Cristea, Eduard Andrei, et al.
Published: (2025)
by: Cristea, Eduard Andrei, et al.
Published: (2025)
MalFlows: Context-aware Fusion of Heterogeneous Flow Semantics for Android Malware Detection
by: Meng, Zhaoyi, et al.
Published: (2025)
by: Meng, Zhaoyi, et al.
Published: (2025)
Static Semantics Reconstruction for Enhancing JavaScript-WebAssembly Multilingual Malware Detection
by: Xia, Yifan, et al.
Published: (2023)
by: Xia, Yifan, et al.
Published: (2023)
A Practical Adversarial Attack against Sequence-based Deep Learning Malware Classifiers
by: Tan, Kai, et al.
Published: (2025)
by: Tan, Kai, et al.
Published: (2025)
Synergistic Directed Execution and LLM-Driven Analysis for Zero-Day AI-Generated Malware Detection
by: Edwards, George, et al.
Published: (2026)
by: Edwards, George, et al.
Published: (2026)
How Reliable Are FOSS Popularity Metrics? Analyzing the Effort Required for Spoofing Common Software Popularity Metrics
by: Swierzy, Ben, et al.
Published: (2025)
by: Swierzy, Ben, et al.
Published: (2025)
Tactics, Techniques, and Procedures (TTPs) in Interpreted Malware: A Zero-Shot Generation with Large Language Models
by: Zhang, Ying, et al.
Published: (2024)
by: Zhang, Ying, et al.
Published: (2024)
FlowMalTrans: Unsupervised Binary Code Translation for Malware Detection Using Flow-Adapter Architecture
by: Hu, Minghao, et al.
Published: (2025)
by: Hu, Minghao, et al.
Published: (2025)
Similar Items
-
Pinning Is Futile: You Need More Than Local Dependency Versioning to Defend against Supply Chain Attacks
by: He, Hao, et al.
Published: (2025) -
Unpacking Security Scanners for GitHub Actions Workflows
by: Fares, Madjda, et al.
Published: (2026) -
On the effectiveness of Large Language Models for GitHub Workflows
by: Zhang, Xinyu, et al.
Published: (2024) -
Is GitHub's Copilot as Bad as Humans at Introducing Vulnerabilities in Code?
by: Asare, Owura, et al.
Published: (2022) -
Characterizing and Modeling the GitHub Security Advisories Review Pipeline
by: Segal, Claudio, et al.
Published: (2026)