Fake Mac Apps on GitHub
To be very clear this is not another post of “Breaking news malware exists on the internet” (or it may be depending on how you want to look at it) but I feel like it’s important that I leave a small PSA as I have recently seen an influx of seemingly convincing GitHub repo replicas for decently popular Mac apps. They are so similar that they almost fooled me. Thankfully I quickly spotted some anomalies and I nearly avoided getting infected. Unfortunately these are the sort of red flags I don’t expect an average Joe to know about. Which is why I’m explaining what the malware is, and how to spot it.
[…]
By far the easiest way to avoid this is to simply look for the app online and track down the original developer. This will let you kill 2 birds with one stone by A: Looking for the original source of the app and avoid impostors and B: See if the App or the developer had any previous reputation to begin with.
[…]
The second discrepancy is that the size of the fake app is ridiculously small. For instance the original app is 13mb in size while the fake one is less than 2mb. Now this is not necessarily a red flag (For example some viruses do the opposite and fill their dmg with a lot of useless data to make the file larger than what VirusTotal can handle.) but it’s still important to raise an eye brow for installers with suspiciously small sizes.
I recently had this problem with EagleFiler. Someone had made a decently convincing GitHub repo using the official icon and screenshots and similar marketing text. It ranked highly in Google searches, I guess because GitHub itself has lots of PageRank. The page tried to get users to paste a Base64-encoded snippet into Terminal, which would download and run a shell script that would prompt the user for a password and save it to a cleartext file.
GitHub has ways to report abuse, as well as DMCA and trademark violations, and they got rid of the repo promptly.
Previously:
Update (2025-09-24): Jeff Johnson:
There’s a malware impersonation of StopTheMadness Pro on Github whose “download” is a malicious shell script.
Update (2025-09-26): Three more fake repos of my apps popped up on GitHub, and there are more for other Mac developers such as Rogue Amoeba.
Update (2025-09-29): Jeff Johnson:
The search phrase “for macOS” on GitHub reveals countless such fakes, pretending to be well-known Mac apps such as 1Blocker, Airfoil, BBEdit, Figma, Little Snitch, Malwarebytes, OmniOutliner, SoundSource, and VLC Media Player. This is clearly the work of a single person or group, because every repository follows the exact same template and technique. And there’s always a blatant “SEO Keywords” section on the page in order to game search engine results, already exploiting GitHub’s own prominent ranking.
[…]
This scam on GitHub is running amok. I’ve reported a few of the fakes myself to GitHub, but I can’t keep up, and that’s not my job. GitHub and Microsoft, the owner of GitHub, need to take decisive and comprehensive action to stop the spread of malware on their platform. Most concerning, I think, is the apparently unlimited ability of an attacker to create and deploy legions of anonymous new GitHub accounts for nefarious purposes.
Update (2025-10-04): Brian Webster:
Read this blog post by @lapcatsoftware about fake GitHub repos imitating real apps. Did a search for PowerPhotos and sure enough, found a couple hits. Good news is I reported it to GitHub and they took it down within a day. Could be an uphill battle if the scammers keep up the pace though.
I just got GitHub to take down another fake EagleFiler repo.
Update (2025-10-06): Jeff Johnson:
Apple Logic Pro for Windows…
…no. GitHub malware imposter, yes.
Also, GitHub malware imposter Final Cut Pro[…]







