How to Ruin All of Package Management
This title could be clearer and more informative.Try out Clickbait Shieldfor free (5 uses left this month).
Package management systems are vulnerable to metric manipulation at scale. The tea.xyz experiment demonstrated how financial incentives led to 150,000+ spam packages flooding npm, RubyGems, and PyPI. Six million fake GitHub stars have been identified, with services selling stars for as little as 10 cents each. These metrics—downloads, stars, dependencies—were designed as quality proxies but cost nothing to manufacture. The problem intensifies as AI coding assistants trained on this data propagate manipulated packages, and as these metrics influence government policy, corporate procurement, and potentially prediction markets. The low-barrier ecosystem that enabled open source growth now enables industrial-scale gaming.
Table of contents
The tea.xyz experimentGitHub stars for saleWhy it’s so easy to breakAI has entered the chatSort: