Spam Bots Flooded GitHub With 40 Million Fake Commits in July 2026

GitHub's public commit activity spiked nearly fivefold in July 2026, surging from roughly 8 million commits per day in June to close to 40 million by July 31, according to analysis by GitGuardian. Researchers identified a coordinated spam campaign in which bots created thousands of repositories using random six-letter usernames, random email addresses, and GitHub's built-in web-flow user. The fake commits contained files mixing Chinese characters, domain names, URLs, and AI-generated images, with each repository hosting over a thousand such files. The campaign became so dominant that around 73% of the last 1,000 observable public GitHub events were linked to it, effectively saturating the platform's public event feed. Most commits referenced short domains under .cc and .vip top-level domains, with infrastructure traced to IP addresses hosted primarily in Hong Kong.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.



Discussion (0)
Log in to join the discussion and vote.
Log in