The Spectrum Dispatch News

technology

GitHub removes malicious software after 3 weeks only following Hacker News attention

A developer reported finding imitation software with malware warnings on GitHub, but the platform took no action for 23 days until the post gained attention online.

GitHub removes malicious software after 3 weeks only following Hacker News attention

On August 31, a developer discovered an imitation of their data wrangling software on GitHub that used their product name and logo without permission. They reported it to GitHub as an imitation the same day and received an automated acknowledgment.

GitHub removes malicious software after 3 weeks only following Hacker News attention

Upon further investigation, the developer’s colleague scanned the macOS .dmg file from the repository using VirusTotal and found multiple malware warnings. The malware-infected file had been modified to include a background image designed to encourage downloaders to ignore security warnings.

The developer submitted this additional information to GitHub support on September 10, providing evidence of the malicious content. However, as of September 23—23 days after the initial report—GitHub had not responded beyond the automated email or taken any action.

According to the developer’s account, GitHub finally removed the repository on September 24, approximately 10 minutes after the post appeared on the front page of Hacker News. The developer noted the timing and expressed frustration with GitHub’s responsiveness, stating that the platform appeared capable of acting quickly when motivated, but required public attention to do so.

Comments on the post revealed similar experiences from other developers. One user reported submitting a comparable report to GitHub in June and receiving only an initial acknowledgment, with no follow-up action despite the malicious content remaining live and appearing as a top search result for their product on Google. Another commenter noted that a competitor’s platform, TinyURL, moved quickly to address the fraudulent download and protect users once notified.

The incident highlights concerns about GitHub’s support response times and the effectiveness of its abuse-reporting mechanisms for addressing intellectual property violations and malware-infected repositories.

Key facts

  • A developer reported finding imitation software using their product name and logo on GitHub on August 31
  • The software contained malware, confirmed via VirusTotal scanning, with a modified .dmg file designed to hide warnings from users
  • GitHub took no action for 23 days after the initial report and additional evidence submitted on September 10
  • The repository was removed on September 24, shortly after the complaint reached the front page of Hacker News
  • Other developers reported similar experiences with slow or non-existent responses from GitHub support

Sources

← All posts