BrokeIt - Trending Repos · All episodes: ↗

6M Fake GitHub Stars, AsyncAPI Botnet Hijack, X Goes Open Source

2026-07-20 · 7 min

Listen · Apple Podcasts Listen · Spotify

Stories covered

Transcript

Intro

Sam: Four @asyncapi packages shipping an obfuscated payload that fires the second you import them — no install script, no runtime trigger, just import and you're already talking to a botnet loader.

Kai: [excited] Okay, that's a horrifying way to start a Monday — this is Kai.

Sam: And this is Sam.

Kai: It's July 20th, 2026, and we've got three open-source stories with your name all over them.

Sam: [dry] Well, one of them literally had my name on a malware C2. But sure. Three.

Kai: First up — Microsoft Threat Intelligence says the @asyncapi npm org got fully hijacked, and four packages started shipping botnet malware.

Sam: Then the big one everyone's yelling about: Elon says X is open-sourcing its entire codebase after a security review.

Kai: And to close it out, a CMU study just mapped GitHub's fake-star economy, and the numbers are, uh, spicy.

Sam: Six million spicy, to be exact. But we'll get there.

AsyncAPI npm packages hijacked to deliver multi-stage botnet malware

Kai: Let's start with the AsyncAPI npm compromise. Sam, walk me off the ledge here.

Sam: I can't. On July 14th someone got into the @asyncapi npm org and pushed poisoned versions of four packages — generator, generator-helpers, generator-components, and specs.

Kai: Wait — generator? That's the tool people run to scaffold their whole API layer. That's everywhere.

Sam: Right. And the payload wasn't in a postinstall hook where you'd expect it. It ran at import time — obfuscated first stage, then it pulls down a multi-stage botnet loader.

Kai: So even your CI just requiring the module is enough to get popped?

Sam: That's the nasty part. And here's the kicker — they abused GitHub Actions to publish, which let them slip past some of npm's newer defenses.

Kai: [groans] Of course they did. The CI pipeline is the soft underbelly now.

Sam: And this isn't one researcher hyping it. OX Security, SafeDep, Socket, and StepSecurity all confirmed it independently. That's a real corroboration stack.

Kai: Okay, hot take — attacks like this are gonna make provenance signing mandatory within a year. Pain forces adoption.

Sam: [dry] Kai, we've been saying that for five years. Provenance is opt-in and half the ecosystem ignores it.

Kai: This time's different! ...he says, every time.

Sam: [laughs] What this means for you: pin your versions, check your lockfile, and if you pulled any @asyncapi generator packages between the 14th and the disclosure, assume compromise and rotate your secrets.

Kai: And audit your Actions permissions while you're in there. Least privilege isn't a vibe, it's a firewall.

X (formerly Twitter) to open-source its entire codebase after security review

Sam: Onto number two — Elon Musk announced on July 15th that X is going to open-source its complete codebase. All of it.

Kai: [excited] Sam, this is HUGE. One of the biggest open-source commitments a major social platform has ever made!

Sam: [skeptical] Announced. That word's doing a lot of work in your sentence.

Kai: They've done it before! The recommendation algorithm went public back in the day —

Sam: A slice of it went public, with the spicy parts commented out. This is being framed as a full release, after a security review, with no license announced and no repo structure yet.

Kai: Okay, but if they actually ship it, transparency wins. Researchers get to audit ranking, moderation, the whole pipeline.

Sam: IF the license is real open source and not some 'source-available, look-don't-touch' thing. That distinction is the entire ballgame.

Kai: Fair. And 'after a security review' can mean six weeks or six years.

Sam: My hot take: I'd rather they publish nothing than dump a repo with hardcoded secrets baked into the git history. We literally just did a whole segment on supply-chain fallout.

Kai: [laughs] Full circle. Imagine leaking your internal service tokens to fourteen million forks in one afternoon.

Sam: That's exactly the security review's job — and why it should take a while.

Kai: What this means for you: don't refactor your career around a codebase that doesn't have a public repo yet.

Sam: But bookmark it. If a real OSI license lands, that's a genuinely great learning resource. I'm skeptical, not dead inside.

CMU study maps GitHub's fake-star economy: 6M suspected fake stars across 18,617 repos

Kai: Last one — and Sam, this is basically your origin story. CMU mapped GitHub's fake-star economy.

Sam: [satisfied] Vindication. Peer-reviewed, ICSE 2026. They built a tool called StarScout and went digging.

Kai: Hit me with the number.

Sam: Roughly six million suspected fake stars, across 18,617 repositories, driven by about 301,000 accounts.

Kai: [stunned] Three hundred thousand sockpuppet accounts just... starring things all day?

Sam: And guess which category got hit the hardest? AI and LLM repos.

Kai: [sighs] Of course. The shiniest boards are the fakest boards.

Sam: Which is why every time you breathlessly tell me a repo went from zero to 40k stars in a weekend —

Kai: — you say 'show me the star velocity curve.' [laughs] I KNOW, Sam.

Sam: Because organic growth ramps. A vertical wall of stars overnight is a purchase order, not a fanbase.

Kai: Hot take though — I still think stars mean something. A million real stars is real signal.

Sam: Sure, at the top. It's the mid-tier where a few thousand bought stars gets you a spot on trending and a seed round.

Kai: [beat] ...okay, that's genuinely grim.

Sam: What this means for you: judge a repo by its commit history, issue quality, and real contributors — not the star badge. StarScout's methodology is public if you want to check.

Kai: Basically: read the code, not the vanity metric. Which, ironically, is also the fix for story two.

Sam: So today: AsyncAPI's npm org got hijacked, four packages shipped an import-time botnet loader, confirmed by four separate firms.

Kai: X says it's open-sourcing its entire codebase after a security review — real license and repo structure still TBD.

Sam: And CMU counted six million fake GitHub stars across eighteen thousand repos, with AI projects leading the fraud.

Kai: Before we go — small thing that made me smile. Somebody built a browser extension that overlays StarScout-style fake-star scores right on GitHub trending.

Sam: [laughs] The 'trust nothing' plugin. I love it. Does it flag its OWN repo's stars?

Kai: [laughs] It'd better, or it's a hypocrite. But hey — verify before you install that one too, folks.

Sam: See? He's learning. Import-time payloads, everyone. Read the code.

Kai: That's the show! We survived a botnet, a maybe-open-source giant, and six million fake stars in one sitting.

Sam: Come back tomorrow — and Kai, I will personally be checking the star velocity on whatever you try to hype next. This is Sam.

Kai: [laughs] I'll bring receipts. This is Kai — see you tomorrow, can't wait.

This show is made with AI: the hosts’ voices are synthetic and the scripts are AI-assisted. Every story links to its original source.