Large-scale scan found 2,289 malicious Go module versions and showed 99.4% remained retrievable via proxy after GitHub takedowns.
4.5 million (suspected) fake stars in github: A growing spiral of popularity contests, scams, and malware
4 Pith papers cite this work. Polarity classification is still indexing.
representative citing papers
Scam2Prompt is a framework that converts scam-site intents into developer-style prompts and measures how often production LLMs generate malicious code, finding rates from 4.24% to 47.3% across eleven models and showing that current guardrails do not block the behavior.
Longitudinal GitHub analysis of 15 multi-agent frameworks finds star counts unreliable for adoption and recommends contributor density, cross-ecosystem engagement, and retention as superior health metrics.
citing papers explorer
-
Beyond Takedown: Measuring Malicious Go Module Persistence in the Wild
Large-scale scan found 2,289 malicious Go module versions and showed 99.4% remained retrievable via proxy after GitHub takedowns.
-
Scam2Prompt: A Scalable Framework for Auditing Malicious Scam Endpoints in Production LLMs
Scam2Prompt is a framework that converts scam-site intents into developer-style prompts and measures how often production LLMs generate malicious code, finding rates from 4.24% to 47.3% across eleven models and showing that current guardrails do not block the behavior.
-
Adoption and Ecosystem Health: A Longitudinal Analysis of Open-Source Multi-Agent Frameworks
Longitudinal GitHub analysis of 15 multi-agent frameworks finds star counts unreliable for adoption and recommends contributor density, cross-ecosystem engagement, and retention as superior health metrics.
- Psychological Safety Framework in Pull-based Open Source Projects