Skip to content

[FIX] Re-sign the dev Electron; correct the recorded cause of the malware flag - #23

Merged
onyxdevs merged 2 commits into
mainfrom
fix/electron-stock-signature
Sep 21, 2026
Merged

onyxdevs merged 2 commits into
mainfrom
fix/electron-stock-signature

Conversation

@onyxdevs

Copy link
Copy Markdown
Owner

Summary

macOS flagged "Electron.app … contains malware" again — this time the untouched development Electron binary. That disproves the cause I recorded in #19, so this PR corrects the record and protects dev mode.

Correction to #19

#19 said an invalid code signature made macOS flag the app. That was wrong.

codesign --verify on stock Electron always prints code has no resources but signature indicates they must be present — for 31.7.7 and for 31.0.0, which ran all evening without complaint. It is how Electron ships, not something electron-builder broke. I had noticed the 31.0.0 inconsistency at the time and did not run it down.

What the evidence supports

Launched Electron Signature Result
Packaged app (01:38 build) 31.0.0 stock ran fine, repeatedly
Packaged app (02:46 build) 31.7.7 stock flagged + deleted
Pristine dev Electron.app ×2 31.7.7 stock flagged + deleted
Re-signed packaged app ×4, re-signed dev binary ×3 31.7.7 ad hoc, own identifier ran fine, 7 of 7

The download is authentic (matches Electron's published SHA-256) and every bundled package is identical to npm, so this is not a compromised dependency. The one consistent discriminator is the executable's CDHash (5195eea8… stock 31.7.7 vs 987eb685… stock 31.0.0), which re-signing replaces.

Most likely Apple blocklists that stock hash because real malware ships inside unmodified Electron binaries. That last step is inference — I cannot read Apple's list — but it is the only account consistent with all observations.

The fix from #19 is still correct and effective. Only its stated reason changes.

Changes

  • scripts/sign-dev-electron.js: re-signs the dev binary before dev / start, and reinstalls it first if macOS already removed it. Idempotent. yarn start now boots with a clean log.
  • Rationale corrected in adhoc-sign.js, CLAUDE.md, .claude/rules/mac-app.md and both skills.
  • verify-mac-bundle.sh and the release workflow now also fail a bundle that is validly signed but still identifies as stock Electron (Identifier=Electron). Verified with a negative control: fails when it should, passes when it should.

Worth knowing

  • An Electron version bump changes the stock hash, so behaviour may differ per version. Electron 31 is also long out of support; upgrading is a separate, deliberate migration.
  • A Developer ID + notarization would make all of this moot, but needs a paid Apple Developer account.

🤖 Generated with Claude Code

onyxdevs and others added 2 commits September 21, 2026 04:00
- Launching the stock dev binary (node_modules/electron/dist/Electron.app) makes macOS 26 report "Electron.app was not opened because it contains malware" and delete it, so `yarn workspace @subzilla/mac dev` could not start. The download is authentic: it matches Electron's published SHA-256.
- scripts/sign-dev-electron.js re-signs it ad hoc under its own identifier before `dev` and `start` launch it, and reinstalls the binary first if macOS has already removed it. Idempotent.
- Verified: the same binary that was flagged twice runs and stays on disk once re-signed; `yarn start` boots the app with a clean log.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
- #19 blamed an invalid code signature. That was wrong. `codesign --verify` on STOCK Electron always says "code has no resources but signature indicates they must be present" - including 31.0.0, which ran all along - so it cannot be the cause.
- What the evidence supports: macOS flags anything still carrying stock Electron 31.7.7's executable code hash (the packaged app once, a pristine checksum-verified Electron.app twice), never stock 31.0.0, and never a re-signed 31.7.7 (7 of 7 launches). Re-signing replaces the CDHash. That Apple blocklists the stock hash because malware ships inside unmodified Electron binaries is inference; the rest is measured.
- The fix from #19 (ad-hoc re-signing in afterPack) is still correct and effective; only its stated reason changes. Updated the hook's comment, CLAUDE.md, the mac rule and both skills.
- verify-mac-bundle.sh and the release workflow now also fail a bundle that is validly signed but still identifies as stock Electron. Checked with a negative control.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
@onyxdevs
onyxdevs merged commit 19a095f into main Sep 21, 2026
6 checks passed
@onyxdevs
onyxdevs deleted the fix/electron-stock-signature branch September 21, 2026 01:05
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant