# Google Ads suspends an open-source macOS terminal tool whose process behaviour resembled a backdoor, then reinstates it > Google Ads suspended the account promoting RACE, a Rust terminal multiplexer for macOS, citing a malicious binary. Notarization and scans were clean; it was reinstated. FireAI Security & Research Team (HisnLabs) · Published 2026-10-06 Canonical: https://hisnlabs.com/en/news/google-ads-flags-race-macos-terminal-tool-as-backdoor-behaviour InfoQ and LavX News reported in early October 2026 that Google Ads suspended the advertising account of Przemyslaw Alexander Kaminski, the developer of RACE, an open-source terminal multiplexer for macOS, citing a “compromised site and malicious binary” [[1]](https://www.infoq.com/news/2026/10/google-wrong-flagging/) [[2]](https://news.lavx.hu/article/google-ads-suspends-open-source-macos-terminal-multiplexer-race-reinstates-after-community-pressure). The account was reinstated after discussion on Hacker News and without an explanation [[1]](https://www.infoq.com/news/2026/10/google-wrong-flagging/) [[2]](https://news.lavx.hu/article/google-ads-suspends-open-source-macos-terminal-multiplexer-race-reinstates-after-community-pressure). The case shows how behaviour-based security flags can mislabel a legitimate Mac developer tool. ## Background A terminal multiplexer keeps shell sessions running in the background and lets the user attach to them. RACE, written in Rust, uses an infinite canvas in which shell surfaces can be placed and resized freely, unlike the grid layout of tmux [[1]](https://www.infoq.com/news/2026/10/google-wrong-flagging/). To keep sessions alive, such a program manages pseudoterminal pairs and background worker processes. ## What the reports describe InfoQ reports that the suspension followed a campaign promoting RACE’s documentation and binary downloads, and that automated scanners identified behaviour matching backdoors, namely forking orphaned background workers that can receive arbitrary command-line input [[1]](https://www.infoq.com/news/2026/10/google-wrong-flagging/). The article states that such an executable “shares behavioural signatures with persistent backdoors and remote access trojans” [[1]](https://www.infoq.com/news/2026/10/google-wrong-flagging/). Other checks came back clean. The two sources report that the RACE binaries passed Apple notarization, that VirusTotal showed zero positives, and that Google’s own Safe Browsing and Search Console security reports found no issue [[1]](https://www.infoq.com/news/2026/10/google-wrong-flagging/) [[2]](https://news.lavx.hu/article/google-ads-suspends-open-source-macos-terminal-multiplexer-race-reinstates-after-community-pressure). InfoQ adds that the developer’s diagnostic submissions met circular rejections [[1]](https://www.infoq.com/news/2026/10/google-wrong-flagging/). After the Hacker News escalation, the developer wrote that his account had been reinstated “through the apparent magic of Hacker News”; the LavX report states that Google gave no explanation [[2]](https://news.lavx.hu/article/google-ads-suspends-open-source-macos-terminal-multiplexer-race-reinstates-after-community-pressure). InfoQ reports he said he would continue the dispute, including before the EU courts [[1]](https://www.infoq.com/news/2026/10/google-wrong-flagging/). > FireAI, the on-device firewall for macOS developed by HisnLabs, identifies each app by its code signature and shows whether it is signed by a known developer before asking about a connection. A 17-day trial is available. [Download FireAI for Mac](https://hisnlabs.com/en/download) ## Implications for Mac users and developers The incident cuts in two directions. For developers, an automated flag can block distribution channels such as advertising even when notarization and independent scans are clean. For users, it is a reminder that a process which forks long-lived workers is not by itself proof of abuse, and that a clean signature and notarization are also not proof of benign behaviour: they establish who built an app and that Apple scanned it, not what it will do. ## Recommendations 1. Download developer tools from the project’s own repository or a package manager you trust, and compare the checksum if one is published. 2. Check the code-signing identity and notarization status of a downloaded binary before first launch. 3. Judge background processes by what they connect to and which files they touch, not by their existence alone. 4. Developers who face a flag should keep scan reports and notarization records, since they were the evidence in this case. 5. Treat a single automated verdict, positive or negative, as one input among several. ## Relevance to FireAI FireAI is a firewall for one Mac. It identifies the exact app behind a connection by its code signature, and when a prompt appears for an app that is not signed by a known developer, or that changed since it was signed, the [connection prompt](https://hisnlabs.com/en/docs/answer-your-first-connection-prompt) says so. The user then decides, and [per-app rules](https://hisnlabs.com/en/docs/per-app-rules) keep that decision. FireAI does not scan binaries, does not classify a program as a backdoor from its process behaviour, and does not influence Google Ads or any other platform’s verdicts. It does not read the inside of an encrypted connection. It makes no statement about RACE itself beyond the reports cited here. > Whether a tool is flagged or clean, its connections tell more than its name. FireAI lists which apps went online and where. Try it free for 17 days. [Download FireAI for Mac](https://hisnlabs.com/en/download) ## Limitations Both sources are secondary, and neither quotes Google; the reason for the suspension is inferred in the reports from the developer’s account and from technical reasoning, not stated by Google [[1]](https://www.infoq.com/news/2026/10/google-wrong-flagging/) [[2]](https://news.lavx.hu/article/google-ads-suspends-open-source-macos-terminal-multiplexer-race-reinstates-after-community-pressure). LavX dates its article to 6 October 2026, and InfoQ’s page gives no date in the extract reviewed. This item did not test RACE or its binaries. Try [FireAI, by HisnLabs](https://hisnlabs.com/en/download) free for 17 days. ## Sources - [InfoQ, October 2026: Flagged by the machine, how Google Ads suspended an open-source macOS terminal as malicious](https://www.infoq.com/news/2026/10/google-wrong-flagging/) - [LavX News, 6 October 2026: Google Ads suspends open-source macOS terminal multiplexer RACE, reinstates after community pressure](https://news.lavx.hu/article/google-ads-suspends-open-source-macos-terminal-multiplexer-race-reinstates-after-community-pressure)