Found a Coordinated GitHub Follow Botnet Hiding in My Followers?
This title could be clearer and more informative.Try out Clickbait Shieldfor free (5 uses left this month).
A developer auditing their GitHub followers discovered 8 accounts created across 6 years with following counts within a range of 25. Classic cross-follow botnet detection returned all zeros, but computing pairwise Jaccard similarity on their full following lists (~29,800 entries each) revealed scores above 0.99 across all pairs, with 29,682 accounts followed by all 8 simultaneously. The post explains why following-list overlap is a more robust detection signal than cross-following, provides the Python script used, and discusses plausible use cases including social proof laundering for malicious repositories.
Table of contents
The Naive Test Failed — By DesignThe Important Signal Wasn't Cross-FollowingReading the EvidenceAlternative Explanations and False PositivesThe Detection MethodThe CodeReportingToolsSort: