vx-underground says GitHub banned its account and removed its malware-code archive
The archive operator says it kept a local copy; GitHub's policy allows dual-use research but permits restrictions in cases of widespread abuse.
By Ryan Merket · Published
Primary source: X
Why it matters
The episode puts GitHub's dual-use malware policy into practice: research code can aid defenders and be repurposed for attacks, while an independent copy can outlast removal from a major hosting platform.

vx-underground (@vxunderground), the malware-research archive, said on October 6th that GitHub had banned its account and removed its collection of malware source code. The account said it retained a local copy, so the GitHub removal did not destroy the archive. The post did not identify a specific repository or explain what prompted the action.
A public page for the repository named in outside indexes, vxunderground/MalwareSourceCode, returned a 404 when checked on October 6th. That is consistent with the account's claim, but does not establish the full scope of any account or repository restriction. A third-party snapshot indexed on September 29th listed the repository with about 18,754 stars and 2,101 forks. The snapshot establishes that the listing was indexed then; it does not show whether GitHub users could access the repository at that time. The available evidence leaves the timing and extent of the removal unsettled.
The archive's announcement also needs to be read narrowly. MalwareSourceCode is a collection of code, while vx-underground's broader operation includes malware samples, research papers and other materials. In a 2022 interview with The Record, founder smelly__vx described the project as a successor to VX Heaven, an archive he had used as a teenager. He said he had worked as a software engineer focused on low-level C and C++ development for Windows before building vx-underground in 2019. His post says GitHub removed the source-code collection; it does not say GitHub shut down the separate website or erased the broader library.
Malware source code lets analysts examine how malicious programs are structured and how techniques are implemented. The files can also be repurposed to build or adapt malware. Publishing them therefore creates a dual-use problem for a hosting platform: the same material can support defensive analysis and enable abuse. vx-underground's locally retained copy preserves one route to the material, while the reported GitHub action removes the collection from a widely used code-hosting service.
GitHub's active malware and exploits policy permits research into malware and exploits, describing educational value for the security community. It also bars using GitHub to deliver malicious executables or operate attack infrastructure. In rare cases of widespread abuse involving dual-use material, the policy says GitHub may restrict access to a specific instance, usually by placing it behind authentication; disabling access or removing content is described as a last resort when other options are not possible. The policy allows enforcement action in defined circumstances, but it does not establish why GitHub acted against vx-underground.
The 2022 interview gives context for why the code archive matters to its operator. Smelly__vx said vx-underground began after he could not find the older VX Heaven library and wanted to rebuild a place for malware samples, papers and source code. He described the project as a collection built by enthusiasts, rather than a commercial security product. At the time, he said it was funded by donations and that contributors had regular jobs. Those are historical statements, not current financial or organizational figures.
In the thread, vx-underground called the takedown "mildly annoying" and said it was "not the end of the world." When an operator keeps an independent copy, GitHub can remove its hosted instance, but copies outside GitHub remain beyond that action. The post does not say where the local copy is stored or how it will be distributed. The immediate confirmed impact is narrower: vx-underground reports losing its GitHub account and its hosted malware-source collection, while saying the archive survives elsewhere.