Urgent.News

What's breaking now, across thousands of outlets.

Tech

Flagged by the Machine: How Google Ads Suspended an Open-Source macOS Term as Malicious

Przemyslaw Alexander Kaminski created RACE, a Rust terminal multiplexer on an infinite canvas that detaches child shells into background processes. When he launched an ad campaign, automated scanners suspended his account for malware despite clean notarization and Safe Browsing checks. The flag illustrates operational deadlocks when ad heuristics evaluate POSIX process architectures. By Olimpiu…

Google Ads unexpectedly suspended an open-source macOS terminal multiplexer developer's account, labeling it as malicious. Przemyslaw Alexander Kaminski, the creator of RACE, an open-source native macOS terminal multiplexer written in Rust, launched an ad campaign for his product. Despite passing native operating system notarization and independent antimalware inspections, Kaminski's ad distribution account was flagged under compromised site and malicious binary designations.

This incident sheds light on the disconnect between advanced security heuristics and developer tools using sophisticated POSIX process orchestration. Kaminski's RACE differs from traditional grid-based terminal multiplexers like tmux by implementing an infinite canvas architecture for shell positioning and resizing. Security scanners evaluate binary safety by analyzing file signatures, static strings, and dynamic process execution patterns.

Conventional desktop applications wouldn't exhibit such behavior, as they typically fork orphaned background workers that receive arbitrary command-line input. However, when Kaminski set up campaigns pointing to product documentation and binary downloads, the campaign platform flagged the destination infrastructure for malicious software violations.

Despite third-party malware analyzers and Google's own diagnostics tools reporting clean results, Google's security policy crawlers still flagged the developer account. Attempts to rectify the suspension revealed circular dependencies in the platform's automated enforcement loop, with no clear explanation provided for the suspension.

The case highlights the growing challenge developers face when building legitimate native utilities under increasingly reliant platform operators using black-box behavioural models for software inspection.

Written by urgent.news from InfoQ's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at infoq.com →

More in Tech

More from Tuesday 6 October →