On August 31, 2025, Andy Brice — developer of Easy Data Transform, a data wrangling tool — received a customer tip: someone had cloned his product's name, logo, and branding into a GitHub repository distributing a macOS .dmg file. A VirusTotal scan of the .dmg returned a wall of malware warnings. The fake installer even swapped the background image to instruct users to override macOS Gatekeeper security warnings — a social engineering move designed to get past Apple's last line of defense. Brice reported the repository to GitHub the same day via its official abuse-reporting channel. He received an automated acknowledgment. On September 10 he submitted the additional malware evidence. As of September 23 — 23 days after the original report — he had received no human response and the repository remained live. The resolution, when it came, was instructive. Brice published a blog post detailing the timeline. It hit the front page of Hacker News. Approximately ten minutes later, GitHub removed the repository. Brice's summary was dry: "If you want even the most basic level of support from Github, you need to get on the front page of Hacker News." The pattern here is familiar to anyone who has tried to get a platform to act on abuse. GitHub has the technical capability to review and remove a repository in minutes. What it lacks — or declines to fund — is the human triage layer that treats a malware distribution report from a small independent developer with the same urgency as a PR crisis. The support queue is a cost center; the front page of Hacker News is a reputation event. This is a governance failure, not a technical one. GitHub is the default infrastructure for open-source and increasingly for software distribution broadly. Its abuse-reporting pipeline is a public safety function, whether it wants it to be or not. A repository actively distributing malware with social engineering instructions to disable OS protections is not an edge case requiring weeks of deliberation. The extractive dynamic is subtle but real. GitHub captures the network effects and trust of being the default code-hosting platform. Independent developers like Brice contribute to that ecosystem. When those developers need the platform to enforce its own policies against bad actors exploiting their work, they discover the support relationship is effectively one-directional — unless they can generate public pressure. The 23-day window matters. Every day that repository was live, users searching for Easy Data Transform could have landed on a malware installer. The cost was borne entirely by Brice (brand damage, customer trust) and by any users who downloaded the file (compromised machines). GitHub bore zero cost until the story went viral.