Summary: Claiming the well-known web software site is serving malware, Google's safe browsing API is marking as malicious.

Google's safe browsing API, a security blacklist service which warns of malicious web sites, has marked the site as malicious. As a result, users of Google Chrome and Mozilla Firefox get a dire warning when attempting to visit the site.

[Update: 9:30 AM EST and I'm not seeing the warning on one of my systems. Perhaps the fix is in.]

The warning in Firefox

PHP is an extremely popular web server-side scripting language and is the home page for it. PHP creator Rasmus Lerdorf tweeted several hours ago about the blockage and claimed it was a false positive.

The detail provided by Google includes the following information:

Of the 1613 pages we tested on the site over the past 90 days, 4 page(s) resulted in malicious software being downloaded and installed without user consent. The last time Google visited this site was on 2013-10-24, and the last time suspicious content was found on this site was on 2013-10-23.

Malicious software includes 4 trojan(s).

Malicious software is hosted on 4 domain(s), including,,

3 domain(s) appear to be functioning as intermediaries for distributing malware to visitors of this site, including,,

The warning in Chrome

Hat tip to Netcraft.

The Netcraft analysis points to a Hacker News analysis which indicates that may, in fact, have been compromised. And the file they cite as malicious has since been removed from the PHP repository.

  • Just tried it...

    myself @ 10am central. Still all clear.
  • False positives...malware!

    You get more of those on downloads dot com
  • Hat tip to Google, who got it right in the first place

    This was a non-story.
    A legitimate website was compromised - not the first and certainly won't be the last.
    Google DNS blocked the site - as it is supposed to do.
    Site owners removed malicious code - again, as they should have done.
    Google DNS stopped blocking the site as it is no longer compromised.
    There is no story here - unless technology working as it should is now news.
    • Bias

      Your bias is evident Cavan. There was no malware to begin with. Google is notorious for false positives in relation to their blacklist. The difference here is normally it happens with smaller websites whose owners take a big financial hit as a result
      • Bias??

        I don't think I'm biased... the story itself concludes with this:

        "Hat tip to Netcraft.

        The Netcraft analysis points to a Hacker News analysis which indicates that may, in fact, have been compromised. And the file they cite as malicious has since been removed from the PHP repository."

        Why hat tip Netcraft and not Google?
      • Biased how?

        Here is an extract that came directly from the website:

        To summarise, the situation right now is that:

        JavaScript malware was served to a small percentage of users from the 22nd to the 24th of October 2013.
        Neither the source tarball downloads nor the Git repository were modified or compromised.
        Two servers were compromised, and have been removed from service. All services have been migrated to new, secure servers.
        SSL access to Web sites is temporarily unavailable until a new SSL certificate is issued and installed on the servers that need it.
    • Google DNS?

      How is this related to Google DNS?
    • Google is Destroying Legitimate Businesses

      It's about time that someone investigated the damage that Google has done to legitimate businesses.
      Take my car rental site - this was ranked by Google ( not that high) until I had the site rebranded in August. As soon as the new site was submitted for indexing, it suddenly disappeared off the planet. What had been a successful growing concern suddenly flat-lined overnight. It now transpires that our server, within a national hosting provider, has been blacklisted. I have contacted the hosting company and they are currently attempting to reverse this situation.
      The ironic thing is that ranks page 1 on Yahoo and Bing for specific keywords.
      • Maybe that is just one reason...

        I don't use Google - maybe I don't like their EULA either - anyways, I ain't used Google in more than a year, as a general practice, anyways!

        I can't stand Yahoo!, so I guess I'll have to go with Bing in a more or less secure browser like Comodo Dragon. Tomorrow may change everything - so the landscape is chaotic!
  • Rasmus Lerdorf claimed it was a false positive

    "The Netcraft analysis points to a Hacker News analysis which indicates that may, in fact, have been compromised. And the file they cite as malicious has since been removed from the PHP repository."

    And I'll bet they apologised for wronging Google. Immediately.
  • Still blocked

    I get in with Firefox 24 but not with IE 10 or Chrome 30.

    I assume is still blacklisted, but Mozilla Firefox (at least with my settings) lets it through anyway.
  • hog wash !

    just tried it on 2 computer no problems , I have far more trouble when using Google and downloading any of these .com on their web site , but perhaps dumping dozen of site while looking for one is google perception of business , SPAMING .
  • Hog wash 2

    just went on the deep web with another pc , no problems , is google blocking the competition ????