GitGuardian
Read post

40 Million Fake Commits Flood GitHub’s Public Feed

This title could be clearer and more informative.Try out Clickbait Shieldfor free (5 uses left this month).

Since mid-July 2026, GitHub's public event feed has been overwhelmed by a massive spam campaign generating up to 40 million fake commits per day — roughly 5x the June baseline and over 70% of all observable public events. GitGuardian's monitoring detected the anomaly by tracking a sudden spike above the normal 8M daily commit rate. Investigation revealed the commits share common traits: random 6-letter repo names, unrelated email addresses, and files containing Chinese characters, domain names, and AI-generated images. Tracing the redirect chain through dozens of .cc and .vip domains hosted in Hong Kong ultimately leads to an illegal Chinese online gambling site impersonating a defunct lottery brand. The campaign appears aimed at promoting the gambling platform and ensuring its resilience against takedowns via a large pool of rotating domains. A side effect is that GitHub's public metrics — commit counts, repo counts, active users — are now significantly inflated by non-development activity, illustrating how easy bot-driven automation has become even on mature platforms.

    #security#github#gitguardian
Yesterday•7m read time•From blog.gitguardian.com
Post cover image
Table of contents
The Month GitHub Public Contributions ExplodedWhat’s the point of this?Same Pipeline, Different Detection
2K Impressions
GitGuardian's image
GitGuardian

GitGuardian Blog provides insights, tutorials, and updates on secrets management, code security, and...

96 Followers

•

969 Upvotes

Would you recommend this post?

Copy link
WhatsApp
Facebook
X
New Squad
  • © 2026 Daily Dev Ltd.
  • Guidelines
  • Explore
  • Tags
  • Sources
  • Squads
  • Leaderboard