On the 31st August I got an email from a customer, telling me that they had found an imitation of my data wrangling software on Github. I’m not linking to it, but here is a screenshot:
It is using our product name and logo, without permission. I reported it to Github as an imitation on the same day. I got this reply:
A colleague scanned the Mac .dmg file from the repository using virustotal.com and got a whole load of malware warnings:
Using Isobuster he found out that they have also changed the background image of the .dmg:
The new image encourages downloaders to ignore any warnings about the malware!

I reported this additional information on the 10th September.
As of the 23rd September, I have had no response from Github support beyond the original automated email. 23 days without a reponse. This is pisspoor. Do better Github.
I’m not sure what my next line of attack is. A DCMA takedown request to Github?
Realistically the only people likely to download the .dmg are those trying to avoid paying for a license for Easy Data Transform. I don’t have a huge amount of sympathy for them if they get their computers compromised. But I really don’t like bad guys taking advantage of my hard work.
Ps/ Always download software from the vendor, where possible.




