Severity
High
Short Description
The GitHub repository of this package may have been artificially inflated with stars (from bots, crowdsourcing, etc.).
Suggestion
This could be a sign of spam, fraud, or even a supply chain attack. The package should be carefully reviewed before installing.
Suspicious Stars on GitHub is a high-severity alert in the supply chain risk category. Using the number of GitHub stars as a metric for supply chain security is not always reliable, as this popularity metric can be corrupted. There are multiple GitHub star black markets where people can purchase stars to artificially inflate this metric.
Our research has determined that fake GitHub stars are frequently associated with scams, fraud, and malicious activity. We identified 3,746,538 suspected fake stars in the last five years (July 2019 to July 2024) and 10,155 repositories that have seemingly run a fake star campaign. The number of suspected fake stars has rapidly growing in the last six months.
If you find a dependency flagged with the "Suspicious GitHub Stars" alert from Socket, here are the recommended actions:
These steps can help protect your project from potential risks associated with fake stars and malicious activity.
Packages flagged with this alert link to the package overview page. It also gives an estimate for the percentage of suspicious stars.

This alert employs two heuristics:
3.7 Million Fake GitHub Stars: A Growing Threat Linked to Scams and Malware
The GitHub Black Market That Helps Coders Cheat the Popularity Contest