GitHub has not removed malicious imitation software after 3 weeks
- ID
- 28488
- Status
- summarized
- Published
- 24 Sep 2026, 11:50 PM
- Fetched
- 25 Sep 2026, 6:46 PM
- Provider
- Hacker News
- Category
- dev-community
- Original URL
- https://successfulsoftware.net/2026/09/24/github-has-not-removed-malicious-imitation-software-after-3-weeks/
- Source URL
- https://hnrss.org/best
Summary
- Score
- 7.0
- Created
- 25 Sep 2026, 6:47 PM
- Tags
- Audience
- developersvibe_coderssaas_founders
What happened
Developer Andy Brice reported a GitHub repository impersonating his data-wrangling product Easy Data Transform — same name and logo — on 31 August 2026, and GitHub's only reply was an automated acknowledgement. A colleague's VirusTotal scan of the repo's Mac .dmg returned multiple malware warnings, and the .dmg background image had been edited to tell downloaders to ignore malware warnings; Brice sent that evidence on 10 September and had heard nothing 23 days later. GitHub removed the page roughly 10 minutes after the post hit the front page of Hacker News on 24 September, and a commenter (coretech24x7) said their own June report also got only an automated reply until TinyURL acted instead.
Why it matters
If you ship any downloadable software, a cloned repo with your name and logo can be live for weeks while GitHub's abuse queue stays silent — and the escalation path that actually worked here was public pressure on Hacker News, not the report form. Practical steps from this case: monitor for impersonation repos yourself, keep a VirusTotal scan and a DMCA takedown drafted in advance rather than waiting on support, and tell users to download only from your vendor site, since the malware here was aimed at people avoiding a paid licence.
Discussion angle
What is your actual escalation path when a platform ignores an abuse report for weeks — and is a public HN post or a DMCA notice a realistic part of it, or does that only work for people with an audience?