Google Ads Mistakenly Flags Open-Source macOS Terminal as Malicious
Google Ads' automated security systems recently flagged an open-source macOS terminal multiplexer called RACE as malicious, causing its developer's ad account to be suspended. Przemyslaw Alexander Kaminski, the creator of RACE, encountered this issue despite the software passing Apple's notarization and third-party antivirus checks. The automated systems mistook RACE's legitimate process management features for malicious behavior, particularly its use of persistent background workers.
RACE is unique among terminal multiplexers for its infinite canvas architecture, allowing users to freely position, resize, and group shell surfaces. This design requires managing pseudoterminal pairs and background processes, which triggered Google's security scanners due to similarities with malicious software patterns. Kaminski's attempts to appeal the suspension were met with automatic rejections, with no specific explanation provided.
After modifying the software's lifecycle teardown routines to include explicit user prompts and process cleanup hooks, Kaminski eventually saw the suspension lifted following community intervention. The case highlights the challenges developers face when automated security systems flag legitimate software for behavior that mimics malicious patterns. Kaminski expressed determination to continue addressing these issues, even considering legal action in EU courts.