GitHub has not removed malicious imitation software after 3 weeks
First reported by Successfulsoftware ·
Your software hosted on GitHub can be impersonated, leading to malware distribution, and GitHub's support response time is significantly impacted by public visibility.
A developer reported a malicious imitation of his software, Easy Data Transform, on GitHub on August 31st. The imitation used the product's name and logo without permission and distributed a .dmg file containing malware, as confirmed by VirusTotal scans. The developer also found that the imitation software altered the .dmg's background image to instruct users to ignore malware warnings. He escalated the report to GitHub on September 10th with the additional information about the altered background image, but received no response beyond an automated email. After 23 days of silence, the developer posted about the issue on September 24th, and the offending GitHub repository was removed approximately 10 minutes after the post gained traction on Hacker News.
The incident highlights a critical vulnerability in how platforms like GitHub handle user-reported malicious content, particularly when it involves software imitation and malware distribution. The significant delay in action, despite clear evidence provided by the developer, suggests a potential gap in their automated or manual review processes for such reports. This inaction could foster an environment where malicious actors exploit popular platforms to distribute harmful software, posing risks to both end-users and legitimate software vendors.
Furthermore, the resolution timeline, drastically shortened only after the issue gained widespread attention on Hacker News, implies that platform moderation and support are heavily influenced by public pressure rather than established protocols. This dynamic forces developers to seek external validation through social media or community forums to get timely assistance, which is an unsustainable and inefficient model for platform governance and user protection. It suggests a need for more robust, proactive, and consistently responsive moderation systems across code-hosting platforms.
AI-written summary. May contain errors.