BT

Facilitating the Spread of Knowledge and Innovation in Professional Software Development

Write for InfoQ

Topics

Choose your language

InfoQ Homepage News Flagged by the Machine: How Google Ads Suspended an Open-Source macOS Term as Malicious

Flagged by the Machine: How Google Ads Suspended an Open-Source macOS Term as Malicious

Listen to this article -  0:00

Automated verification pipelines inside major distribution platforms continue to create operational bottlenecks for systems utility developers. Przemyslaw Alexander Kaminski, the creator of RACE, an open-source native macOS terminal multiplexer written in Rust, recently detailed the automated suspension of his ad distribution account following an ad campaign launch. Despite distributed release binaries passing native operating system notarization and independent antimalware inspections, security policy crawlers flagged the developer account under compromised site and malicious binary designations. The incident highlights the disconnect between developer tools utilising advanced POSIX process orchestration and automated safety heuristics.

RACE differs from conventional grid-based terminal multiplexers such as tmux by implementing an infinite canvas architecture where shell surfaces can be arbitrarily positioned, resized, and grouped. Architecturally, the multiplexer detaches command execution from window layout lifecycles, guaranteeing that child interactive shells persist across desktop application restarts or UI crashes. Under macOS, this requires managing pseudoterminal pairs and background worker processes through either an internal PTY host daemon or an external dtach backend.

 Generate with Gemini based on information provided in the original blog post

Automated security scanners evaluate binary safety and web endpoints by analysing file signatures, static strings, and dynamic process execution patterns. In typical desktop application spaces, an executable that persistently forks orphaned background workers capable of receiving arbitrary command-line input shares behavioural signatures with persistent backdoors and remote access trojans.

When Kaminski provisioned campaigns pointing to the product documentation domain and binary downloads, the campaign platform flagged the destination infrastructure for malicious software violations. A manual verification sweep by the author revealed clean reports across third-party malware analyzers as well as the Google's own diagnostics tools. Google Search Console and the Google Safe Browsing verification service reported zero compromised assets across the domain root and download infrastructure.


 

// Diagnostic payload submitted during automated appeal review

{

  "target_binary": "RACE.dmg",
  "notarization_status": "Apple Notarized Developer ID",
  "google_safe_browsing": "CLEAN",
  "search_console_security": "NO_ISSUES_DETECTED",
  "virustotal_positives": 0,
  "process_lifecycle": "documented_pty_multiplexing"

}

Attempts to remediate the suspension uncovered circular dependencies inside the platform's automated enforcement loop. Submitting diagnostic reports via standard appeal interfaces resulted in deterministic rejections without disclosing the specific binary hash, rule match, or network artefact triggering the policy flag. Seeking account support was blocked by prerequisites that the underlying security suspension must be resolved first.

To isolate whether runtime daemon persistence caused the flag, the developer modified the lifecycle teardown routines in version 1.0.39, introducing explicit user prompts and process cleanup hooks to terminate orphaned multiplexing threads upon parent deletion. A later edit to the post underlines that the policy suspension was ultimately rescinded only after community escalation surfaced the operational deadlock to engineering teams:

Through the apparent magic of Hacker News, my Google Ads account has been reinstated. Still no explanation of what triggered the suspension, but thank you to everyone who helped make it visible (and/or fixed).

The case illustrates the systemic tension between security automation and non-standard systems programming. As platform operators rely increasingly on black-box behavioural models to inspect software ecosystems, developers building legitimate native utilities that manage processes, manipulate memory maps, or hook low-level kernel abstractions face growing friction across distribution and commercial infrastructure. Engineering teams distributing developer-focused binaries must anticipate false positives by documenting process topologies and isolating persistent worker agents from primary UI binaries. Kaminski stated in his article that he will continue his fight on all possible paths, even in the EU Court.

About the Author

Rate this Article

Adoption
Style

BT