40 Million Fake Commits Flood GitHub’s Public Feed
This title could be clearer and more informative.Try out Clickbait Shieldfor free (5 uses left this month).
Since mid-July 2026, GitHub's public event feed has been overwhelmed by a massive spam campaign generating up to 40 million fake commits per day — roughly 5x the June baseline and over 70% of all observable public events. GitGuardian's monitoring detected the anomaly by tracking a sudden spike above the normal 8M daily commit rate. Investigation revealed the commits share common traits: random 6-letter repo names, unrelated email addresses, and files containing Chinese characters, domain names, and AI-generated images. Tracing the redirect chain through dozens of .cc and .vip domains hosted in Hong Kong ultimately leads to an illegal Chinese online gambling site impersonating a defunct lottery brand. The campaign appears aimed at promoting the gambling platform and ensuring its resilience against takedowns via a large pool of rotating domains. A side effect is that GitHub's public metrics — commit counts, repo counts, active users — are now significantly inflated by non-development activity, illustrating how easy bot-driven automation has become even on mature platforms.