40 Million Fake Push: When Spam Commits Took Over The Public GitHub
Blog post from GitGuardian
GitGuardian reported a dramatic rise in public GitHub commits from roughly 8 million daily in June 2026 to nearly 40 million by July 31, driven largely by an apparent spam campaign using randomly named repositories, unrelated email addresses, long single-file commits, and content containing Chinese text, URLs, domains, and AI-generated images. The activity reportedly accounted for more than 70% of sampled public GitHub events and saturated the platform’s public events feed, inflating visible measures such as commit, repository, and active-user counts. Investigation linked many commits to short .cc and .vip domains, which redirected through changing .xyz domains and cloud-hosted infrastructure in Hong Kong before reaching what appeared to be a Chinese online lottery or gambling application using the “Rúyì cǎi” name. Although the researchers found no additional overtly malicious behavior beyond the promotion of a likely illegal gambling service, the campaign’s large-scale automated account creation, domain rotation, and redirect structure illustrate how public development platforms can be used for spam distribution and resilient advertising infrastructure.
| Trend | Post Mentions | Total Month Mentions | Posts | Companies | MoM |
|---|---|---|---|---|---|
| Secrets Management | 1 | 584 | 99 | 52 | -76% |
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.