frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Tell HN: YC companies scrape GitHub activity, send spam emails to users

123•miki123211•3h ago
Hi HN,

I recently noticed that an YC company (Run ANywhere, W26) sent me the following email:

From: Aditya <aditya@buildrunanywhere.org>

Subject: Mikołaj, think you'd like this

[snip]

Hi Mikołaj,

I found your GitHub and thought you might like what we're building.

[snip]

I have also received a deluge of similar emails from another AI company, Voice.AI (doesn't seem to be YC affiliated). These emails indicate that those companies scrape people's Github activity, and if they notice users contributing to repos in their field of business, send marketing emails to those users without receiving their consent. My guess is that they use commit metadata for this purpose. This includes recipients under the GDPR (AKA me).

I've sent complaints to both organizations, no response so far.

I have just contacted both Github and YC Ethics on this issue, I'll update here if I get a response.

Comments

neya•1h ago
This is atleast fine as it's just spam, I got pulled into an actual scam and it never made it to the frontpage.

https://news.ycombinator.com/item?id=45357205

ChrisMarshallNY•1h ago
Looks like GH nuked it, though.

Hope they didn’t get too many folks.

nubinetwork•1h ago
That's a little creepier than the time I got an email from someone trying to push a new crypto coin to me because I contributed to OSS.
medi8r•16m ago
But that is someone pretending to be YC which is sort of less interesting than a YC company doing something bad. Because phishers imitate legit companies all the time. Easy to get roped in and I sympathise, anyone is suseptable (today I almost clicked the phishing training email as it looked urgent and pushed the right buttons)
pscanf•1h ago
I was also spammed (twice) by voice.ai.

You mention GDPR, which also "applies" to me, though I wonder if what they're doing is actually illegal. I mean, after all, I'm putting my email on GitHub precisely to give people a way to contact me.

Of course, I do that naïvely, assuming good faith, not expecting _companies_ to use it to spam me. So definitely what they're doing is, at the very least, in poor taste.

zvqcMMV6Zcr•1h ago
Is there any company that will take my money to solve GDPR issues? And by solve I mean sue the spammers? For last few years I saw they "try" to look legit, by claiming addresses are managed by some Hungarian/Spanish shell company, hoping no one will be able to afford pursuing infractions over borders.
KomoD•1h ago
> Is there any company that will take my money to solve GDPR issues? And by solve I mean sue the spammers?

A lawyer

RobotToaster•1h ago
There's probably a law against it, but I've always thought a legal company could make decent money taking cases like this in bulk for free, on the condition that they get to keep all the compensation, while the "client" still gets the satisfaction of punishing the offending party.
notpushkin•20m ago
That’s pretty much class action lawsuits!
victorbjorklund•45m ago
They spammed me as well.
notpushkin•22m ago
> I'm putting my email on GitHub precisely to give people a way to contact me.

They’re not only looking at the public email in your profile, they’re also looking at your committer email (git config user.email). You could argue that you’re not putting that out for people to contact you.

(I’ve used that trick a couple times to reach out to people, too, but never mass emailing.)

ValentineC•1h ago
> These emails indicate that those companies scrape people's Github activity, and if they notice users contributing to repos in their field of business, send marketing emails to those users without receiving their consent. My guess is that they use commit metadata for this purpose.

There are likely marketing email datasets floating around the internet that contain email addresses scraped from commit metadata.

I use a catchall with a specific Git client (not GitHub) email address, and found spam and phishing emails being sent there quite a few times.

input_sh•1h ago
May not necessarily be from commit messages, there's at least one way simpler way: simply adding .gpg to the end of any user URL will return that user's public GPG key.
armchairhacker•1h ago
I remember this being discussed a while ago

https://news.ycombinator.com/item?id=9332418 (11 years ago)

https://news.ycombinator.com/item?id=20660624 (7 years ago)

https://news.ycombinator.com/item?id=27855152 (5 years ago)

https://news.ycombinator.com/item?id=30900237 (4 years ago)

Seems it’s a reoccurring issue

ChrisMarshallNY•1h ago
I’m not especially bothered by this [yet -AI is likely to make this worse]. It’s a fairly insignificant component of my spam catcher. At least, it’s a bit focused.

Every day, I get deluged with hundreds of spam and scam emails, often because some knucklehead entered my email in a form (either accidentally, or as a throwaway red herring).

Maxious•1h ago
Sure but these YC spammers are identifiable and have much more to lose https://www.ycombinator.com/ethics/

> Some examples of ethical behavior we expect from founders are:

> - Not spamming members of the community

> To maintain our community, if we determine (in our sole discretion) that a founder has behaved unethically during or after YC, we will revoke their YC founder status. This includes access to all Y Combinator spaces, software, lists and events. All founders in a company may be held responsible for the unethical actions of a single co-founder or a company employee, depending on the circumstances.

RobotToaster•53m ago
Has this ever actually been enforced?
ChrisMarshallNY•31m ago
> > - Not spamming members of the community

Ah... but there's the rub.

Define "the community."

Does it count if you are selecting random GH accounts count as being members of "the YC community"?

Sorry, but unsolicited contact, much as I hates, HATESSSS it, is a classic component of any business, and has been, for many decades. I don't think it would be appropriate for a business organization to prohibit its members from engaging in "cold calling," of which, UCE is really an example.

Using the YC branding/name, however, is a different matter.

kristoff_it•1h ago
I have received over the years so much spam of this kind by multiple YC-funded companies that I now reflexively send to spam any email that mentions being YC-funded, regardless of how legitimate the email is.
neya•1h ago
I don't blame you, the FOMO is real to the point even basic ChatGPT wrappers are getting funded these days, I guess.
AznHisoka•17m ago
Same here, having YC attached to your name is not the flex you think it is, its even the opposite for me
koakuma-chan•1h ago
I have been having the same experience. If you starred a GitHub repo, and they think that their product is similar, they will send you their spam. I condemn this! They should be ashamed!
outloudvi•1h ago
I usually check the "Received" header and report to the email service provider. Once in a while I receive a response saying the case is properly handled.

These providers are the only ones that care about their reputation and thus may take some action. Investors? Nope.

dewey•1h ago
This happens all the time, not really surprised as the GitHub API makes it pretty easy to extract valuable leads with real and confirmed email addresses.
tommoor•56m ago
Yea, been going on at least a decade
c16•1h ago
Email address privacy is a feature offered by Github and replaces your day to day email: https://docs.github.com/en/account-and-profile/how-tos/email...
bakugo•1h ago
This sounded familiar, so I checked my inbox and I did indeed receive a similar email from sanchitmonga@runanywheresdk.com earlier this month:

> I came across your GitHub profile and thought you might be interested in what my team and I are building. We're developing an open source SDK that runs LLMs directly on-device.

What's even more interesting is that both buildrunanywhere.org and runanywheresdk.com show a stock hostinger parking page when accessed in a browser. Something tells me they're intentionally registering these "alternate" domains specifically for spam, to avoid tanking the email reputation of their main runanywhere.ai domain.

I guess I shouldn't be surprised given YC is going all in on AI and most AI companies are no better than the crypto scammers of yesteryear, but still.

rlaabs•58m ago
I've received the exact same email from the same company.
WhatsName•50m ago
Doesn't YC have some code of conduct or legal/ethical guidelines? I would assume a legal and compliance department would have some major headache if documented cases of misconduct jeopardize later due diligence. I would not fund or aquire a company on the radar of national regulatory bodies for something as stupid as this.
martinwoodward•34m ago
Martin from GitHub here. This type of behaviour is explicitly against the GitHub terms of service, when we catch the accounts doing this we can (and do) take action against those accounts including banning the accounts. It's a game of whack-a-mole for sure, and it's not just start-ups that take part in this sketchy behaviour to be honest. I've been plenty of examples in my time across the board.

The fundamental nature of Git makes this pretty easy for folks to scrape data from open source repositories. It's against our terms of service and those folks might want to talk with some lawyers about doing it - but as every Git commit contains your name and email address in the commit data it's not technically difficult even if it is unethical.

From the early days we've added features to help users anonymise their email addresses for commits posted to GitHub. Basically, you configure your local Git client to use your 'no-reply' email address in commits and that still links back to your GitHub account when you push: https://docs.github.com/en/account-and-profile/reference/ema...

I think that's still probably the best route. We want to keep open source data as open as possible, so I don't think locking down API's etc is the right route. We do throttle API requests and scraping traffic, but then again there have been plenty of posts here over the years from people annoyed at hitting those limits so it's definitely a balancing act. Love to know what folks here think though.

ayhanfuat•28m ago
I am also getting constant spam because apparently they can see who starred a repo (i.e. I see you starred repo x and we are doing something similar). I am not starring anything anymore.
AznHisoka•20m ago
Maybe I am missing something, but can’t you simply not show the email address in a git commit? (Sincere question, not saying this is trivial. i am dumb and like to ask dumb questions even if might be embarassing ok?)

If someone wants to message someone, it goes through github notifications or github emails them

Also banning an account doesnt seem like a heavy punishment, given they can simply move to gitlab, bitbucket etc

EdNutting•15m ago
That would be a fundamental change to how Git works, not just GitHub. Even if the web UI didn't show it, a simple `git log` would reveal it.

You can mask your email address in git commits but a lot of open source projects won't accept that. And some pseudo-open-source ones insist on sending you an email to authenticate before they'll give you access to the GitHub repo (looking at you Unreal Engine!)

So, no, I don't think they could simply "not show the email address".

easton•12m ago
Git commits have a email address as a required field[0], although some people put something bogus in there. And then it's in the data provided when you clone the repo onto your machine even if you aren't using the GitHub APIs.

To his point, you can set that to the no-reply email address GitHub gives you if you don't want mail but do want the commit to be linked to your GitHub account.

[0]: https://git-scm.com/docs/git-commit#_commit_information

theturtletalks•34m ago
General advice would be to mark the email as spam or junk and hopefully their email platform penalizes them, but this has been working less and less. Email has truly become pay to play now.
nprateem•15m ago
There's no reason to put your real email in git config unless you're signing, in which case repos should be private. I would have thought that was obvious.
scottydelta•14m ago
YC is a proud investor in Flock, what YC Ethics thing are you talking about?
cassonmars•11m ago
And Cluely
keiferski•11m ago
I've spent a lot of my career marketing to developers, and spamming their GitHub account might be top 1 or 2 worst marketing tactics you can use.

Cold emailing rarely works by itself. Cold emailing developers via emails you pulled from their GitHub accounts? At that point, you're actively harming your brand, and may as well just send them spam diet pill ads.

EdNutting•11m ago
My solution to this is to use a Github-specific email address. All emails sent to that address which do not originate from GitHub are immediately reported as spam, marked unread and deleted.

I sometimes use different git/GitHub addresses depending on who I'm working for or specific projects so I can more accurately detect where data is being scraped from.

EdNutting•3m ago
N.B. Using service-specific emails is trivial - you don't need separate email accounts. Just use email aliases, e.g. "john.smith+github@gmail.com" -- which is an alias called "github" for "john.smith@gmail.com"

Show HN: Terminal Phone – E2EE Walkie Talkie from the Command Line

https://gitlab.com/here_forawhile/terminalphone
78•smalltorch•2h ago•19 comments

Google API keys weren't secrets, but then Gemini changed the rules

https://trufflesecurity.com/blog/google-api-keys-werent-secrets-but-then-gemini-changed-the-rules
811•hiisthisthingon•17h ago•171 comments

Show HN: Agent Swarm – Multi-agent self-learning teams (OSS)

https://github.com/desplega-ai/agent-swarm
6•tarasyarema•40m ago•3 comments

Fentanyl makeover: Core structural redesign could lead to safer pain medications

https://www.scripps.edu/news-and-events/press-room/2026/20260211-janda-molecule.html
3•littlexsparkee•11m ago•0 comments

Jimi Hendrix was a systems engineer

https://spectrum.ieee.org/jimi-hendrix-systems-engineer
537•tintinnabula•16h ago•165 comments

Tell HN: YC companies scrape GitHub activity, send spam emails to users

125•miki123211•3h ago•46 comments

Technical Excellence Is Not Enough

https://raccoon.land/posts/technical-excellence-is-not-enough/
16•bo0tzz•3h ago•4 comments

Hightouch (YC S19) Is Hiring

https://hightouch.com/careers#open-positions
1•joshwget•53m ago

The Physics and Economics of Moving 44 Tonnes at 56mph

https://www.mikeayles.com/blog/heavy-haulage-basics/
30•mikeayles•2d ago•17 comments

Men in their 50s may be aging faster due to toxic 'forever chemicals'

https://www.cnn.com/2026/02/26/health/forever-chemicals-aging-men-wellness
35•jb1991•57m ago•12 comments

How will OpenAI compete?

https://www.ben-evans.com/benedictevans/2026/2/19/how-will-openai-compete-nkg2x
296•iamskeole•14h ago•400 comments

Banned in California

https://www.bannedincalifornia.org/
207•pie_flavor•13h ago•237 comments

First Website (1992)

https://info.cern.ch
245•shrikaranhanda•13h ago•68 comments

Windows 11 Notepad to support Markdown

https://blogs.windows.com/windows-insider/2026/01/21/notepad-and-paint-updates-begin-rolling-out-...
304•andreynering•19h ago•457 comments

Making MCP cheaper via CLI

https://kanyilmaz.me/2026/02/23/cli-vs-mcp.html
245•thellimist•16h ago•99 comments

Artist who “paints” portraits on glass by hitting it with a hammer

https://simonbergerart.com
197•cs702•3d ago•84 comments

Bus stop balancing is fast, cheap, and effective

https://worksinprogress.co/issue/the-united-states-needs-fewer-bus-stops/
374•surprisetalk•20h ago•542 comments

You Want to Visit the UK? You Better Have a Google Play or App Store Account

https://www.heltweg.org/posts/you-want-to-visit-the-uk-you-better-have-a-google-play-or-app-store...
115•rhazn•1h ago•158 comments

Large-Scale Online Deanonymization with LLMs

https://simonlermen.substack.com/p/large-scale-online-deanonymization
291•DalasNoin•1d ago•210 comments

Show HN: Respectify – A comment moderator that teaches people to argue better

https://respectify.org/
184•vintagedave•22h ago•182 comments

Out of Light Adjust Share: Caravaggio, La Tour, and the Art of Attention

https://harpers.org/archive/2026/03/out-of-light-nicole-krauss-caravaggio-georges-de-la-tour/
24•prismatic•3d ago•1 comments

RAM now represents 35 percent of bill of materials for HP PCs

https://arstechnica.com/gadgets/2026/02/ram-now-represents-35-percent-of-bill-of-materials-for-hp...
299•jnord•10h ago•234 comments

The First Fully General Computer Action Model

https://si.inc/posts/fdm1/
272•nee1r•2d ago•69 comments

A 26-Gram Butterfly-Inspired Robot Achieving Autonomous Tailless Flight

https://arxiv.org/abs/2602.06811
17•Terretta•3d ago•3 comments

Nihilistic Violent Extremism

https://en.wikipedia.org/wiki/Nihilistic_violent_extremism
8•doener•43m ago•0 comments

Writers and Their Day Jobs

https://lithub.com/the-work-behind-the-writing-on-writers-and-their-day-jobs/
42•simplegeek•4d ago•13 comments

Tech companies shouldn't be bullied into doing surveillance

https://www.eff.org/deeplinks/2026/02/tech-companies-shouldnt-be-bullied-doing-surveillance
329•pseudolus•12h ago•106 comments

The Om Programming Language

https://www.om-language.com/
279•tosh•19h ago•77 comments

Show HN: Modern Reimplementation of the Speck Molecule Renderer

https://github.com/vangelov/modern-speck
8•vlad_angelov•4d ago•0 comments

Dissecting the CPU-memory relationship in garbage collection (OpenJDK 26)

https://norlinder.nu/posts/GC-Cost-CPU-vs-Memory/
101•jonasn•1d ago•30 comments