Earlier quoted context omitted.
This is only tenuously related but every single Mac app I see advertised on X by verified accounts is malware. I reported one last week to them, they said it's not malware. I appealed it and said the install link is copy and paste obfuscated base64 into your terminal, and they said after review it doesn't break their terms. So whatever else they do, they take money to knowingly promote malware.
> the install link is copy and paste obfuscated base64 This doesn't make it malware, as likely as it is that malware would hide itself like that. base64 encoding avoids issues with quoting and escaping in the terminal, and is an easy way to include a bit of binary data that might be needed by a command (or even just written directly to disk somewhere). "Obfuscated base64" is only saying something if you decoded the b…
I reported them all the Cloudflare and Cloudflare took them down. One moved away from Cloudflare, and Twitter kept them up.
I reported another to NiceNIC and they asked for: 1. Verifiable malicious download file or sample hash 2. Screenshot or screen recording with the full URL visible 3. Evidence of malicious scripts, obfuscated code, or download chain 4. HTTP response, redirect chain, headers, or packet capture data 5. Third-party security verdict tied to the specific URL or file
I just ignored them. I don't work for them and if they want to host illegal content then it's not my business decision.
This one in particular had the download in base64, piping into Javascript and running a binary as a fake Apple Updater script.
But I am sick of this attitude that it's my responsibility for a malware report to be taken seriously. If they introduce malware bounties then ok, but otherwise I'm doing them a favour by reporting it and if they want to continue to host it after reasonable being made aware of its existence, they should be legally responsible.