Hacker News new | ask | show | jobs
by unregistereddev 16 days ago
This reeks of likely malware.

- Fake commit history

- No source code, despite being hosted on github

- Windows-only binaries available for download

If I weren't on my work computer I would pull down those binaries to see what is in them. It sure smells fishy.

1 comments

The commit history is a mirror of the real codebase, I wanted to show people that I've been working on this for a long time and that it's not vibe coded ai slop. In retrospect it seems that it was a mistake to do this.

Neverclick is digitally signed with Microsoft Trusted Signing (now known as Azure Artifact Signing). I had to send them my address and ID to get my identity verified so that I'd get approved for it.

Is there anything else I can do to put your mind at ease?

Microsoft Trusted Signing only tells me you were able to get a key.

If this is intended to be an open source project, transparency would go a long way. The source code and actual history will make a big difference. If this is not intended to be an open source project, then hosting it on a source control system is misleading.

Not releasing source code is fine, but then you need to build trust. Is it paid software? Is there a company or a known name behind it (in which case, can you host it on that entity's website)? At minimum, toss up a website that describes what the software does, what the usage terms are, and whether it collects information about user systems and/or uploads data anywhere. Bonus, scan it with Windows Defender and a couple other malware scanners. Advertise that it scans clean.