Google Ads wrongly suspends macOS terminal app

Major distribution platforms’ automated verification processes are causing delays for systems utility developers. Przemyslaw Alexander Kaminski, creator of the open-source macOS terminal multiplexer RACE, reported his ad distribution account was automatically suspended after launching a campaign, despite passing security checks.
Despite distributed release binaries passing native operating system notarization and independent antimalware inspections, security policy crawlers flagged the developer account under compromised site and malicious binary designations.
Security Scanners and False Positives
Automated security scanners evaluate binary safety and web endpoints by analysing file signatures, static strings, and dynamic process execution patterns. In typical desktop application spaces, an executable that persistently forks orphaned background workers capable of receiving arbitrary command-line input shares behavioural signatures with persistent backdoors and remote access trojans.
RACE differs from conventional grid-based terminal multiplexers such as tmux by implementing an infinite canvas architecture where shell surfaces can be arbitrarily positioned, resized, and grouped.
Investigation and Remediation
When Kaminski provisioned campaigns pointing to the product documentation domain and binary downloads, the campaign platform flagged the destination infrastructure for malicious software violations. A manual verification sweep by the author revealed clean reports across third-party malware analyzers as well as Google’s own diagnostics tools.
Google Search Console and the Google Safe Browsing verification service reported zero compromised assets across the domain root and download infrastructure. The diagnostic payload submitted during automated appeal review included “notarization_status”: “Apple Notarized Developer ID”, “google_safe_browsing”: “CLEAN”, and “search_console_security”: “NO_ISSUES_DETECTED”.
Attempts to remediate the suspension uncovered circular dependencies inside the platform’s automated enforcement loop. Submitting diagnostic reports via standard appeal interfaces resulted in deterministic rejections without disclosing the specific binary hash, rule match, or network artefact triggering the policy flag.
Resolution and Implications
The policy suspension was ultimately rescinded only after community escalation surfaced the operational deadlock to engineering teams. Kaminski stated that his Google Ads account has been reinstated, but he still has not received an explanation of what triggered the suspension.
The case illustrates the systemic tension between security automation and non-standard systems programming. As platform operators rely increasingly on black-box behavioural models to inspect software ecosystems, developers building legitimate native utilities face growing friction across distribution and commercial infrastructure.
