AI Weekly Malaysia

Back to items Summaries

GitHub has not removed malicious imitation software after 3 weeks

ID
28488
Status
summarized
Published
24 Sep 2026, 11:50 PM
Fetched
25 Sep 2026, 6:46 PM
Provider
Hacker News
Category
dev-community
Original URL
https://successfulsoftware.net/2026/09/24/github-has-not-removed-malicious-imitation-software-after-3-weeks/
Source URL
https://hnrss.org/best

Summary

Score
7.0
Created
25 Sep 2026, 6:47 PM
Tags
Audience
developersvibe_coderssaas_founders

What happened

Developer Andy Brice reported a GitHub repository impersonating his data-wrangling product Easy Data Transform — same name and logo — on 31 August 2026, and GitHub's only reply was an automated acknowledgement. A colleague's VirusTotal scan of the repo's Mac .dmg returned multiple malware warnings, and the .dmg background image had been edited to tell downloaders to ignore malware warnings; Brice sent that evidence on 10 September and had heard nothing 23 days later. GitHub removed the page roughly 10 minutes after the post hit the front page of Hacker News on 24 September, and a commenter (coretech24x7) said their own June report also got only an automated reply until TinyURL acted instead.

Why it matters

If you ship any downloadable software, a cloned repo with your name and logo can be live for weeks while GitHub's abuse queue stays silent — and the escalation path that actually worked here was public pressure on Hacker News, not the report form. Practical steps from this case: monitor for impersonation repos yourself, keep a VirusTotal scan and a DMCA takedown drafted in advance rather than waiting on support, and tell users to download only from your vendor site, since the malware here was aimed at people avoiding a paid licence.

Discussion angle

What is your actual escalation path when a platform ignores an abuse report for weeks — and is a public HN post or a DMCA notice a realistic part of it, or does that only work for people with an audience?

Top