| This is just one flavour of abuse. GitHub does NOT give a shit about the scale of the malware problem. I've seen so many forms of malware repos working on a GitHub trends newsletter [1], mostly about crypto, NFTs, KMS, and similar stuff. In the first runs of the project, I was so surprised by tens of malware repos that looked like trending repos. A lot of them share some common traits that made filtering feasible: - Made by a fresh GitHub user - many created in the past few days. - The average creation date of Stargazers accounts is very close to the repo creation date. If you take the mean time diff, those bad repos get exposed. I reported 10s of malware repos, but then I gave up as I felt GitHub was not really doing enough to fight back. I was like... these guys don't seem to care, why should I? God knows how many people have been abused by these malware repos on GitHub. --- [1] https://github.com/mhadidg/gh-trends |