GitHub has not removed malicious imitation software after 3 weeks
hermitcrab
250 points
109 comments
September 24, 2026
Related Discussions
Found 5 related stories in 96.3ms across 7,602 title embeddings via pgvector HNSW
- GitHub Has an Availability Problem. Is It Time to Look Elsewhere? dhruv3006 · 63 pts · August 17, 2026 · 51% similar
- Researchers replace downloaded macOS apps with evil twins, Apple shrugs sbulaev · 17 pts · July 25, 2026 · 51% similar
- Lessons Learned from CISA's Recent GitHub Leak Bender · 14 pts · July 13, 2026 · 49% similar
- OpenAI did not notice Hugging Face hack for a week himaraya · 18 pts · July 25, 2026 · 48% similar
- Incident with Github.com kevcampb · 698 pts · August 17, 2026 · 48% similar
Discussion Highlights (18 comments)
someonebaggy
If it's your software send a DMCA. They have a legally required timeframe to process those. If it's open source, however, then you don't have any valid DMCA claim.
joshuat
Not exactly the same, but I've noticed a pretty sizable uptick in the number of spam/scam PR comments being left on GitHub (and a longer delay before they're removed after report). Not the worst thing in the world, they're easy to spot, but I'd like to see GitHub invest more time in protecting their users from falling victim to these bad actors.
kg
In the future just issue a DMCA takedown right away for cases like this, IMO.
hermitcrab
Author of the post here. Github finally took the offending page down approximately 10 minutes after the post appeared on the front page of HN. Total coincidence. I'm sure! Moral of the story. If you want even the most basic level of support from Github, you need to get on the front page of HN first. And it seems they are able to do things very quickly, when they want to. Bastards.
jay73763
why would anyone host commercial binary software on github or any other third party domain?
Havoc
They’re presumably too busy with keeping availability above nine sixes
OCTAGRAM
I recently found "free" version of Lossless Scaling on GitHub. The release installer is definitely malware. It took GitHub 3 days to shutdown malware distribution. Category of my ticket was malware report, not copyright infringe
msalihb
I found a page that serving e-books I've purchased on github. It is a bit bad feeling
MBCook
What do you know. Apple’s “never run to the media it never helps anything” rule works just as well with GitHub.
wingerlang
If GitHub staff is still reading this thread, maybe you can take down https://screenmemory.github.io/ as well. I reported it 4 weeks ago, ticket ID 4703161
hannob
Welcome to the club! There's an impersonation profile of me on Github (username happyhannob). I've reported it a while ago, received the same automated message, and no reaction otherwise. It's still online. I guess you can't expect basic fraud prevention from a company currently building the future with AI...
bananamogul
Three weeks? Try almost three years: https://lowendbox.com/blog/will-github-ever-remove-this-null...
nixgeek
I see OP edited their post claiming getting to HN's front helped. I think the likelihood GitHub did something within 10 minutes of a post appearing on HN's front page is approximately zero. Nobody in GitHub Trust & Safety is sat there watching HN. An executive or communications professional who might have heard it got on HN, or seen it appear in a tool monitoring Microsoft and GitHub's mentions across the internet, and who then flagged the post, Trust & Safety would probably spend *more than 10 minutes* noticing the email or Teams message, then trying to find the right ticket internally. Then after locating the ticket you still have to investigate the facts, discuss, and click buttons to ban/delete the user. It's (much) more likely this sat in a queue until someone got to it and the timing of it being on HN is a complete coincidence.
revexos
Seems like they don't even care
icemanvault
These kinds of imitation attacks seem to be getting more common. It’s not just random malware anymore — some of them are getting surprisingly polished and even use the real product name and logo. Interesting (and a bit sad) how visibility on HN seems to speed things up on GitHub’s side.
tgsovlerkhgsel
Lack of moderation is an issue everywhere, because there are few consequences for the platforms. Booking.com kept a clearly fraudulent listing (images clearly stolen from another Booking.com listing with mirroring + some filters) fully online for at least two days (I got distracted and stopped taking daily screenshots after that). I just got a response that they've taken it down almost 10 days after I had initially reported it (although I think they marked it as not bookable some time before that).
kelnos
If they were using your logo, you could have sent a DMCA takedown notice. That would have likely gotten a faster, more serious response.
rcleveng
Please give GitHub some slack, just check out the massive number of copilot changes they've had to release over the last 3 weeks ( https://github.blog/changelog/ ). There's clearly little time left for security, maintenance, or reliability work.