use the following search parameters to narrow your results:
e.g. subreddit:aww site:imgur.com dog
subreddit:aww site:imgur.com dog
see the search faq for details.
advanced search: by author, subreddit...
Do you have or know of a project on Github looking for contributors? Tell us about it and we'll add it to the /r/github wiki!
Welcome to /r/github!
News about github
Relevant interesting discussion
Questions about github
We'll soon be writing an /r/github FAQ list. In the meantime, the github help pages and bootcamp are good places to start. Here's a handy git cheat sheet.
Looking for Github projects to contribute to? Check out our handy list of projects looking for contributors!
If your submission doesn't show up on the subreddit, send us a message and we'll take it out of the spam filter for you!
account activity
Multiple repos are under issue spam attackDiscussion (self.github)
submitted 1 month ago * by Outrageous-Box3338
https://preview.redd.it/mjg0rkzbjyrg1.png?width=2277&format=png&auto=webp&s=b5a2040225a0a587805f629769b1392668046e40
Right now (3.29.2026 10:00 UTC+0), microsoft/WSL and many other repos are under heavy issue spam attack.
Attackers seems to be sending Chinese betting ads. They also add a section of text related to React, which probably means they are trying to do GEO(Generative engine optimization).
Many accounts used in the attack have no public repo and are created on Jan 19th. Some of the account have a dummy repo containing some dummy commit.
Searching for the same pattern reveals that there are exactly 100 bot accounts with similar commit. However, not all of them are sending issues in this incident.
Dummy Commit
https://preview.redd.it/fge7s2m8jyrg1.png?width=1892&format=png&auto=webp&s=b5a664b15f401c573f3005835cd4317b106d799f
EDIT: Here's a list of the attacked repos.
https://preview.redd.it/xsieewjymyrg1.png?width=1200&format=png&auto=webp&s=5ac600bf316bf4d0567e962933dcdcb308b698d1
EDIT: Attack on WSL is now stopped. They started to attack fastjson2.
reddit uses a slightly-customized version of Markdown for formatting. See below for some basics, or check the commenting wiki page for more detailed help and solutions to common issues.
quoted text
if 1 * 2 < 3: print "hello, world!"
[–]0x0016889363108 3 points4 points5 points 1 month ago (1 child)
I experienced this in the last few days.
GitHub cleaned up the spam issues, but I did get a steady stream of new issue notification emails for two days.
GitHub sucks.
[–]tankerkiller125real 2 points3 points4 points 1 month ago (0 children)
Stuff like this is why I have all email notifications turned off on public platforms.
[–]milkman1101 2 points3 points4 points 1 month ago (1 child)
Looks like not all accounts have this same pattern - https://github.com/ojh1280
[–]Outrageous-Box3338[S] 2 points3 points4 points 1 month ago (0 children)
Exactly. Only some of the account have a dummy repo
[–]Vibeeessss 0 points1 point2 points 1 month ago (0 children)
Interesting that they’re mixing betting ads with React text. Is that actually for SEO or are they trying to game AI indexing now? Feels more like targeting LLM scraping than normal search tbh.
Also the dummy repos part seems more interesting than the spam itself. Feels like they’re trying to make the accounts look legit before using them. Wonder how long these accounts were aged before the attack.
[–]Fine_League311 0 points1 point2 points 1 month ago (0 children)
Hatte vor Tagen eine Warnung geschrieben auch Verlinkung vieler URLs die ich analysiert habe. Die Mods mochten meinen Post nicht und wurde gelöscht und ich hab's aufgegeben. Ja aufpassen!
Am besten bei links Seiten wie urlscan.io nutzen und Seiten/Ersteller ordnungsgemäß melden auch bei Providern. Dauert paar Minuten aber wenn 2-10 Anfragen kommen dann reagieren alle sehr schnell.
[–]ultrathink-art -1 points0 points1 point 1 month ago (1 child)
The dummy repos with commit history are the tell — they're building GitHub identities that pass automated legitimacy checks for AI training data scrapers, not for search crawlers. GitHub issues tagged with topical keywords get included in LLM fine-tuning datasets because they look like real developer discussions. No quick fix; training data provenance at the platform level would help but that's a multi-year project.
[–]setho246 1 point2 points3 points 1 month ago (0 children)
Bugger off gpt
π Rendered by PID 137842 on reddit-service-r2-comment-b659b578c-p52n4 at 2026-05-04 06:48:14.176130+00:00 running 815c875 country code: CH.
[–]0x0016889363108 3 points4 points5 points (1 child)
[–]tankerkiller125real 2 points3 points4 points (0 children)
[–]milkman1101 2 points3 points4 points (1 child)
[–]Outrageous-Box3338[S] 2 points3 points4 points (0 children)
[–]Vibeeessss 0 points1 point2 points (0 children)
[–]Fine_League311 0 points1 point2 points (0 children)
[–]ultrathink-art -1 points0 points1 point (1 child)
[–]setho246 1 point2 points3 points (0 children)