Your daily reminder that download counts are a bad proxy for legitimacy
Case in question: newly published npm package gets half a million downloads a day. How? because they faked the downloads.
Stars on GitHub can also be farmed by bots.
Your daily reminder that download counts are a bad proxy for legitimacy
Case in question: newly published npm package gets half a million downloads a day. How? because they faked the downloads.
Stars on GitHub can also be farmed by bots.
If you have a fediverse account, you can quote this note from your own instance. Search https://infosec.exchange/users/lirantal/statuses/114388308740447560 on your instance and quote it. (Note that quoting is not supported in Mastodon.)