GitHub Pulls Malware Repo Minutes After It Hits Hacker News
Security / news
GitHub Pulls Malware Repo Minutes After It Hits Hacker News
Developer Andy Brice reported an Easy Data Transform impostor carrying a malware-laced installer on Aug. 31; GitHub removed it only after his account reached the site's front page 24 days later.
GitHub removed a malware-laced repository impersonating the commercial app Easy Data Transform about 10 minutes after its developer's complaint reached the front page of Hacker News, developer Andy Brice said Sept. 24, 24 days after he first reported it.
Brice, who runs the data-wrangling software company behind Easy Data Transform, published the timeline himself on his Successful Software blog. A customer told him on Aug. 31 that they had found an imitation of his product on GitHub using its name and logo without permission; Brice reported the repository to GitHub the same day.
What GitHub had, and when
On Sept. 10, a colleague scanned the repository's Mac .dmg installer with VirusTotal and got, in Brice's words, "a whole load of malware warnings." Whoever built the fake installer had changed the disk image's background image to tell people to ignore the security warning it triggers. Brice passed that evidence to GitHub the same day.
GitHub's response for the next 13 days was nothing beyond an automated acknowledgment email, Brice said. He published his post on Sept. 23, noting 23 days had passed with no substantive reply. He declined to link to the repository itself, to avoid sending it more traffic.
| Date | Event |
|---|---|
| Aug. 31, 2026 | Brice reports the impersonating repository to GitHub |
| Sept. 10, 2026 | A colleague's VirusTotal scan finds malware in the .dmg; evidence sent to GitHub |
| Sept. 23, 2026 | Brice publishes the timeline after 23 days of silence |
| Sept. 24, 2026 | Post reaches Hacker News' front page; GitHub removes the repository about 10 minutes later |
"Github finally took the offending page down approximately 10 minutes after this post appeared on the front page of Hacker News," Brice wrote. "Total coincidence. I'm sure!" His conclusion: "If you want even the most basic level of support from Github, you need to get on the front page of Hacker News." GitHub did not explain, in anything Brice published, why the two earlier reports drew no visible action.
The pattern is bigger than one repository
Brice's case is small next to what security researchers have been logging on GitHub for two and a half years. Threat intelligence newsletter Risky Bulletin counted more than a dozen distinct malicious-repository campaigns reported by name between February 2024 and March 2026, starting with a single campaign of over 100,000 repositories that security firm Apiiro found in February 2024. Kaspersky, Microsoft, Sophos, Trend Micro and Prodaft each published their own findings on separate campaigns in the years that followed, distributing malware families including SmartLoader, LummaStealer, CastleLoader and the Redox Stealer.
The tactic Risky Bulletin describes matches Brice's account: a threat actor copies a legitimate project's name and files, adds an infostealer or remote-access trojan, then drives traffic to it through social media, forums or paid GitHub stars. As Risky Bulletin's Catalin Cimpanu put it, citing security researcher Artem Golubin, "about the only one that's not taking notice appears to be GitHub itself."
The pattern also shows up closer to Brice's own beat: a fake npm package impersonating Twilio's bug-bounty tooling hid credential-stealing code in a dependency published to the registry GitHub also owns, and a revived open-source FoxPro project inherited a 20-year-old security hole its own maintainers had not yet closed. In all three cases, the platform's own trust signals, familiar branding, real download counts, a plausible-looking repository, are what make the impersonation work. GitHub had not published any statement on the Easy Data Transform case as of Sept. 24.
Sources
More in Security
- 01CISA Gives Agencies 3 Days to Patch an Exploited SharePoint BugMicrosoft rated the flaw a low-risk spoofing issue for 16 days after patching it, and a honeypot logged the first attack four weeks after the correction upgraded it to an 8.8.
- 02CISA Adds a Fourth MikroTrick Bug to Its Exploited ListCVE-2026-67279 joins two other bugs from the same six-flaw MikroTik batch already on CISA's list, but Bishop Fox says it, not the pair flagged in September, is the one that actually opens the door.
- 03OpenClaw's New Scanners Agree on Just 0.69% of Risky SkillsFour audits since February have counted between 341 and 1,467 malicious or flawed skills on ClawHub, and NVIDIA's scanner disagrees with the other two on all but 468 of 67,453 skills checked.
- 04CISA Lists 14 Botslab Dashcam Flaws With No Fix in SightThe worst of the bugs lets a network attacker push firmware with no cryptographic signature onto the device, and Botslab has not told CISA whether it plans to fix any of the 14.