–
An AI Tool Called malus.sh Rebuilds Any Open-Source App in Minutes — And the Copy Is Legally “Not a Copy”
Two security guys built a robot photocopier for code. It takes free software, launders the copyright out of it, and hands you a version you can slap a price tag on. And it actually works.
The old way to legally clone software: months of work, a team of lawyers, and hundreds of thousands of dollars (1982). The new way: a few cents, a few minutes, one website.
Dylan Ayrey (the guy behind Truffle Security) and Mike Nolan spun up a real, money-making company called malus.sh that uses AI to rebuild open-source apps into “corporate-friendly” copies. It’s half a joke to prove a point — and half a loaded gun pointed at the entire free-software world. Full story broke on 404 Media.

🧩 Dumb Mode Dictionary — read this first, everything else makes sense after
| Fancy Term | What It Actually Means |
|---|---|
| Open source | Software where the recipe is public. Anyone can read it, use it, change it — for free. |
| License (like GPL) | The rulebook attached to free software. Usually: “use it, but if you build on it, YOU have to keep it free too.” |
| Copyleft | The sticky version of the above. It “infects” your project so you can’t lock it up and charge for it. That’s the whole point. |
| Clean room | An old legal trick. One person describes what software does. A second person — who NEVER saw the original code — writes fresh code from that description. Result: same function, legally different, no copyright broken. |
| malus.sh | The new AI tool doing that clean-room trick automatically, in minutes, for pocket change. (“Malus” = Latin for apple tree… and also “bad.” Cute.) |
| Legally distinct | Lawyer-speak for “looks the same, does the same, but you can’t sue me.” |
🕰️ How we got here — the 1982 photocopy trick, sped up 10,000x
Right, so here’s what’s actually happening. This isn’t a new idea — it’s an old idea with a rocket strapped to it.
Back in 1982, a company called Phoenix wanted to copy IBM’s PC “BIOS” (the tiny bit of code that boots a computer) without getting sued into the ground. So they used a clean room: one team read IBM’s code and wrote a plain-English description. A second team, locked away, never saw a single line of IBM’s code — they only got the description, and built their own version from scratch. Totally legal. It’s why we got cheap PC clones and, eventually, the whole affordable-computer world. (The real history here, for the curious.)
That process took months and a small fortune in salaries and lawyers.
malus.sh does the same dance — one AI reads the original, writes the spec; another AI (that “never saw” the source) rebuilds it — in minutes, for cents. Kids these days, honestly.
⚙️ What the thing actually does (and why it's scary-clever)
- You point it at a free open-source project.
- Pay a small fee.
- It hands you back new code that does the same job — but wrapped in a “corporate-friendly” license you control.
- The GPL / copyleft “you must keep this free” rule? Gone. Washed out in the AI rinse cycle.
The gut-punch: it’s marketed as satire — a protest art piece screaming “hey, this loophole is real and nobody’s guarding it.” But it’s also a registered LLC that genuinely charges money and genuinely works. The joke does the crime. That’s what makes it land.
Ayrey’s own write-up and the tool frame it as a warning shot at how fragile open-source licensing really is once AI can rephrase code faster than a lawyer can read the first page.
🚨 Why every open-source maintainer just got a cold sweat
Open source runs on a handshake: “I’ll give you my work for free, IF you promise to keep your version free too.” That promise is enforced by copyright — the copyleft license.
Now imagine a big company takes your popular free tool, runs it through the AI launderer, and ships a paid, closed version — legally “distinct,” so you can’t sue. You did the work. They took the paycheck. And the free ecosystem that everyone (including that company) relies on slowly bleeds out.
That’s not a hypothetical anymore. That’s a website with a checkout button. (TechSpot’s breakdown is a solid read if you want the doom in more detail.)
🗣️ What the timeline's saying
- Devs: split down the middle — half calling it brilliant activism, half calling it “the day open source started dying.”
- Lawyers: quietly sweating, because “AI-assisted clean room” has basically zero case law behind it. Nobody knows if a judge buys it yet.
- The suits: pretending not to look. (They’re looking.)
- The maintainers: doing what they always do — shipping free code at 3 AM while everyone argues about who gets to profit from it.
Cool. So a Robot Can Now Copy Anyone’s Homework Legally… Now What the Hell Do We Do? (⊙_⊙)

Here’s the thing — every panic like this cracks open doors nobody’s walked through yet. The loophole is real, the tools are cheap, and the crowd hasn’t caught up. That’s the window. Five plays ![]()
🛡️ The Clone Insurance Guy
Everyone’s freaking about their free code getting laundered. Almost nobody is checking for it. Be the person who scans the internet for stolen-and-relicensed versions of open-source projects and tells the maintainers “hey, someone cloned you — here’s proof.”
You’re selling peace of mind + a paper trail. Provenance detective. First mover in a niche that literally didn’t exist last quarter.
Example: A 24-year-old CS grad in Nigeria sets up alerts using GitHub code search + free copyright-diff tools, monitoring 40 popular open-source repos. When a suspicious “legally distinct” twin pops up on a paid SaaS, he sells a 1-page evidence report to the original maintainer’s company for $250 a pop. 6 reports his first month.
Timeline: First paying client in ~3 weeks (word spreads fast in maintainer Discords). Plateau in 4-6 months once bigger security firms notice the niche and undercut you — so bank it and build a name early.
🪟 The Patch-Window Sprinter
Right now, “AI clean-room cloning” has almost no legal rulebook. That fuzzy gap is a window. Position yourself as the person who explains the rules that don’t exist yet — a plain-English field guide for scared indie devs on how to license-protect their work before the copy-bots find them.
Not a course. A living, updated cheat-sheet + a paid “audit my license” service. Be the dictionary for a brand-new panic.
Example: A 27-year-old ex-paralegal in the Philippines writes the first genuinely readable “How to armor your open-source license against AI cloning” guide, posts it free on dev.to, then upsells a $40 “review your repo’s license setup” gig at the bottom. The free guide ranks #1 on Google for the term within weeks; the gig prints quietly.
Timeline: SEO traffic builds over 4-8 weeks. Golden window lasts until courts actually rule on this (12-18 months out) — after that the guide becomes commodity. Ride it hard now.
🧰 Sell the Picks, Not the Gold
Everyone wants to use AI clean-rooming; almost nobody wants to figure out the boring plumbing. So sell the plumbing. Build and rent out the pieces: solid spec-extraction prompt packs, a checklist for doing a defensible clean-room, ready-made “corporate-friendly” license templates.
You never touch anyone else’s code. You just sell shovels to both the miners AND the sheriffs.
Example: A 22-year-old in Brazil bundles a “Clean-Room Starter Kit” — prompt templates + a license generator built on the free Anthropic API with Claude — and sells it as a one-time $19 download on Gumroad. 300 sales in two months from devs who want to understand the process without building it from zero.
Timeline: First sales within days of a good Reddit/HN post. Sales taper after ~10 weeks as free copycats appear — refresh the kit with new templates to stay ahead.
🔍 The Abandonware Reviver
Thousands of genuinely useful open-source projects are dead — maintainer vanished, last commit in 2019, but people still depend on them. Perfectly legal move: fork the (permissively licensed) ones, use AI to modernize + document them, then sell support and hosting, not the code.
You’re not laundering anyone. You’re resurrecting corpses everyone forgot and charging for the babysitting.
Example: A 29-year-old sysadmin in Poland finds a beloved-but-abandoned MIT-licensed backup tool on GitHub, spends a weekend cleaning it up with AI help, and offers “managed hosting + we’ll actually answer your emails” for $15/month to small businesses still running it. 20 subscribers = rent covered.
Timeline: First subscriber in ~2 weeks. Steady, boring, durable — this one doesn’t get “patched,” it just needs you to keep answering support tickets. The unsexy plays last longest.
📡 The Copy-Trail Watermarker
Here’s the reverse-the-data-flow angle. If AI can rephrase code to dodge copyright, maintainers need a way to prove their fingerprints were in the original. Sell a service that plants subtle, harmless “signatures” in open-source code — quirky variable patterns, decoy comments, structural tells — that survive an AI rewrite and later scream “this came from MY project.”
It’s basically invisible ink for source code. Ammunition for the lawsuit nobody’s filed yet.
Example: A 26-year-old security researcher in India offers “code fingerprinting” as a $99 setup for open-source teams, embedding traceable patterns and logging them. When a cloned version shows up months later, the fingerprint is the receipt. She lands 8 paranoid mid-size projects in her first quarter off a single Hacker News thread about the malus.sh drama.
Timeline: Slow start (needs trust — 4-6 weeks of proving it works), but once one lawsuit uses your fingerprint as evidence, referrals explode. High ceiling, patient game.
🛠️ Follow-Up Actions
| If you want to… | Do this |
|---|---|
| Understand the actual loophole | Read the 404 Media original |
| Learn the 40-year-old trick behind it | Clean room design (Wikipedia) |
| Protect your own project’s license | Compare licenses at choosealicense.com |
| Find abandoned projects to revive | Sort GitHub by “least recently updated + high stars” |
| Sell any of the shovels above | Set up a store on Gumroad |
Quick Hits
| You Want… | Then… |
|---|---|
| Set GitHub code-search alerts on your repo’s unique strings | |
| Write the plain-English “protect your license” guide before anyone else does | |
| Say “AI-assisted clean room” and watch lawyers flinch | |
| Fingerprint your open-source code today, sue tomorrow | |
| TechSpot’s writeup |
They didn’t hack the code. They hacked the copyright. And the scariest part? It’s a checkout button, not a crime.
!