
GitHub left a malware-laced software imitation up for 3 weeks
Developer Andy Brice reported a GitHub repository that copied his product's name and logo and shipped a Mac installer flagged by VirusTotal. For 23 days the reply was an automated message — then the page vanished ten minutes after his post hit Hacker News.
Software developer Andy Brice spent 23 days trying to get GitHub to remove a repository that copied his product's name and logo and handed out a Mac installer flagged as malware. The page disappeared about ten minutes after his blog post about it reached the front page of Hacker News.
A counterfeit repository
Brice develops Easy Data Transform, a data-wrangling tool sold under a commercial licence. On 31 August he received an email from a customer who had found an imitation of the software on GitHub. The repository used the product name and logo without permission and offered a Mac .dmg file for download.
He reported it to GitHub as an imitation the same day. The only reply he received was an automated message from support.
Malware inside the disk image
A colleague scanned the .dmg file with VirusTotal and got a long list of malware detections. Looking at the file with Isobuster, he found that the background image of the disk image had been replaced: the new graphic urges anyone opening it to ignore warnings about malware.
Brice forwarded that evidence to GitHub on 10 September. It changed nothing. By 23 September he had still heard nothing beyond the original automated email, and his next step, he wrote, would have been a DMCA takedown request.
Gone in ten minutes
The takedown never became necessary. The post reached Hacker News on 24 September, and the repository was gone roughly ten minutes later. Brice called the timing "total coincidence" with obvious irony, and drew the conclusion himself: to get even basic support from GitHub, you apparently have to reach the front page of Hacker News.
Why it matters
Brice admits he has little sympathy for people who install a pirated copy of his software and end up with an infected machine. The real problem is impersonation: someone searching for a familiar product name can land on a repository that looks official and ships a hostile installer instead.
His advice is to download software from the vendor's own site whenever possible. The case also shows how thin the support channel can be for a small developer whose product identity is abused on a major code-hosting platform.
SiTech — AI-powered web development
We build fast, modern websites and bring AI into real business workflows. Have a project or a question? We'd love to help.