Skip to content
Merged
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
175 changes: 175 additions & 0 deletions 2026/09/2026-09-30-expo.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,175 @@
While GitHub did not find sufficient information to determine a valid anti-circumvention claim, we determined that this takedown notice contains other valid copyright claim(s).

---

Note: Because the parent repository was actively being forked when this DMCA takedown notice was received, and the submitter had identified all known forks at the time they submitted the takedown notice, GitHub processed the takedown notice against the entire network of 83 repositories, inclusive of the parent repository.

---

**Are you the copyright holder or authorized to act on the copyright owner's behalf? If you are submitting this notice on behalf of a company, please be sure to use an email address on the company's domain. If you use a personal email address for a notice submitted on behalf of a company, we may not be able to process it.**

Yes, I am the copyright holder.

**Are you submitting a revised DMCA notice after GitHub Trust & Safety requested you make changes to your original notice?**

Yes

**Does your claim involve content on GitHub or npm.js?**

GitHub

**Please describe the nature of your copyright ownership or authorization to act on the owner's behalf.**

I am the [private] [private] and copyright owner of the proprietary software at issue. [private] created and maintain the original source code, which is stored in [private] [private] [private] repository. I have not authorized the reported repository or its owner to copy, decompile, deobfuscate, reproduce, distribute, or publish [private] copyrighted source code or derivative copies of it.

**Please provide a detailed description of the original copyrighted work that has allegedly been infringed.**

The original copyrighted work is [private] proprietary Java software project, Expo, which [private] [private] developed and maintain.

The original source code for Expo is privately maintained and has never been released as open-source software or licensed to the public for redistribution, modification, or republication. [private] distribute Expo only in compiled Java form. The distributed builds are intentionally obfuscated, including obfuscated class/member names, encrypted or transformed strings, invokedynamic-based transformations, and other code-protection mechanisms.

The reported repository, NoHackClient/OpenExpo, contains a substantially complete and buildable Java source-code reconstruction of [private] proprietary Expo software. The source code in that repository was obtained by decompiling and deobfuscating compiled distributions of Expo. In particular, substantial portions of the original program logic, class structure, method implementations, constants, strings, control flow, and other original code have been recovered and reproduced.

Most of the obfuscation present in [private] distributed builds has been removed in the reported repository. This includes restoration or resolution of protected strings, invokedynamic-based code, and substantial portions of the program implementation. Some identifiers or portions of the code may remain partially obfuscated or incompletely remapped, but the repository nevertheless contains a substantially complete, functional, and buildable reconstruction derived from [private] copyrighted software.

I have never authorized the owner or contributors of the reported repository to decompile, deobfuscate, reproduce, publish, sublicense, or distribute [private] source code or reconstructed versions of it.

**If the original work referenced above is available online, please provide a URL.**

The original source code is not publicly available online. It is maintained in a private [private] repository because Expo is proprietary, closed-source software.

Public users only receive compiled and obfuscated distributions of the software, not the original source code.

A public page showing the software/project is available at:
https://expo.sell.app/
[private]

[private] [private] repository link:
[private]

**We ask that a DMCA takedown notice list every specific file in the repository that is infringing, unless the entire contents of the repository are infringing on your copyright. Please clearly state that the entire repository is infringing, OR provide the specific files within the repository you would like removed.**

**Based on the above, I confirm that:**

The entire repository is infringing

**Identify the full repository URL that is infringing:**

https://github.com/NoHackClient/OpenExpo

**Do you claim to have any technological measures in place to control access to your copyrighted content? Please see our Complaints]([https://docs.github.com/articles/guide-to-submitting-a-dmca-takedown-notice#complaints-about-anti-circumvention-technology%22%3EComplaints](https://docs.github.com/articles/guide-to-submitting-a-dmca-takedown-notice#complaints-about-anti-circumvention-technology%22%3EComplaints)) about Anti-Circumvention Technology if you are unsure.**

Yes

**What technological measures do you have in place and how do they effectively control access to your copyrighted material?**

[private] software, Expo, uses SkidOnion / Phantom Shield X ([private] / [private] / [private]) as part of its technological protection and authorization system.

Expo uses its license verification and authentication system to control access to the software. Users are required to have valid authorization and successfully authenticate before being permitted to use the protected software. The licensing system is used to manage and verify authorized users and licenses.

In addition to authorization controls, the distributed Java application is protected using Java bytecode obfuscation and transformation mechanisms. These protections include class and member obfuscation, string encryption/protection, control-flow obfuscation, and invokedynamic-based transformations. [private] distribute only the compiled and protected version of Expo and do not provide users with the original Java source code.

Together, these measures restrict use of the software to authorized users and make the underlying proprietary implementation unavailable to users in its original source-code form. Users who legitimately receive the software receive only the protected compiled build, not the original source code.

**How is the accused project designed to circumvent your technological protection measures?**

The accused project is specifically designed and produced by circumventing the technological protection measures applied to [private] software, Expo.

The repository's own README expressly describes the process used to defeat and remove those protections. It identifies protection systems used by Expo, including Phantom Shield, Zelix KlassMaster, JNIC, VMProtect, and Themida, and states that the repository maintainers performed deobfuscation, unpacking, and devirtualization in order to reconstruct the protected software.

In particular, the repository states that they restored protected strings, resolved invokedynamic transformations, removed or reversed control-flow obfuscation, unpacked the protected expoantidump.dll, restored JNIC native methods and constants, unpacked and devirtualized the Themida-protected components associated with Phantom Shield, and decrypted/restored protected classes.

These actions are not incidental to the project. They are the means by which the repository was created. The resulting repository contains a substantially deobfuscated, readable, buildable reconstruction of Expo and includes instructions for compiling it into a working JAR.

The stated purpose and design of the project therefore include defeating the technological protections that prevent users of the distributed compiled build from directly accessing and reconstructing the protected implementation of Expo.

**If you are reporting an allegedly infringing fork, please note that each fork is a distinct repository and must be identified separately. Please read more about forks.</a]([https://docs.github.com/articles/dmca-takedown-policy#b-what-about-forks-or-whats-a-fork%22%3Eforks.%3C/a)>](https://docs.github.com/articles/dmca-takedown-policy#b-what-about-forks-or-whats-a-fork%22%3Eforks.%3C/a)%3E) As forks may often contain different material than in the parent repository, if you believe any of the repositories or files in the forks are infringing, please list each fork URL below:**

https://github.com/AQ84/OpenExpo
https://github.com/Arui1891/OpenExpo
https://github.com/BaiduYun114514/OpenExpo
https://github.com/bedkillerspacex-boop/OpenExpo
https://github.com/Biddiamond666/openSolstice
https://github.com/butchers277/OpenExpo
https://github.com/CNLETI7N/OpenExpo
https://github.com/dawfn/OpenExpo
https://github.com/Dl1447/OpenExpo
https://github.com/dot-1337/OpenExpo
https://github.com/dyzjct/OpenExpo
[private]
https://github.com/Farewell-sleep/OpenExpo
https://github.com/fearful3232candyeater/OpenGoonSpo
https://github.com/fengyushaonian/OpenExpo
https://github.com/fkbmr/OpenExpo
https://github.com/Go1denQwQ/OpenExpo
https://github.com/GUKUAN/OpenExpo
[private]
https://github.com/Jared2013-arch/Expo
https://github.com/K9isztus/OpenExpo
https://github.com/kaworld9027-cmyk/OpenExpo
https://github.com/KEpt1337/OpenExpo
https://github.com/kiooop1/OpenExpo
https://github.com/L1ZeZzz/OpenExpo
https://github.com/lhy1145/OpenExpo
https://github.com/lightfeather721/OpenExpo
https://github.com/LLLLL456789/OpenExpo
https://github.com/LovelyDazai/OpenExpo
https://github.com/Moon85CN/OpenExpo
https://github.com/mxchu666/OpenExpo
https://github.com/nian-520/OpenExpo
https://github.com/Niuauuuu/OpenExpo
https://github.com/NotAlley233/OpenExpo
https://github.com/ObiDefense/expo-
https://github.com/QingYanQwQ233/OpenExpo
https://github.com/qinjunhaocn/OpenExpo
https://github.com/rvwa/openexpo
https://github.com/Sh4rdgel/openexpo
https://github.com/shenbai1221/OpenExpo
https://github.com/SPEEDBOY19/OpenExpo
https://github.com/storagepurpose9090/OpenExpo
https://github.com/Sup3rS061c/OpenExpo
https://github.com/SUSRDev/OpenExpo
https://github.com/Texro-Doof/OpenExpo
https://github.com/TR114514-QwQ/OpenExpo
https://github.com/UnknownUser03393/OpenExpo
https://github.com/WangYang1337/OpenExpo
https://github.com/winfqqqq/OpenExpo
https://github.com/wszgr114514/OpenExpo
https://github.com/wyx6669036/OpenExpo
https://github.com/XHR914/OpenExpo
https://github.com/xiaoaiXA/OpenExpo
https://github.com/XiaoCi233/OpenExpo
https://github.com/XiaoHanHan233/OpenExpo
https://github.com/xiaoyu777666/OpenExpo
https://github.com/xijinping18964/OpenExpo
https://github.com/xoo0524tw/OpenExpo
https://github.com/xquj/OpenExpo
https://github.com/XxYo01/OpenExpo
https://github.com/Xylitol0429/OpenExpo
**Is the work licensed under an open source license?**

No

**What would be the best solution for the alleged infringement?**

Reported content must be removed

**Do you have the alleged infringer’s contact information? If so, please provide it.**

I do not have any contact information for the alleged infringer other than their publicly available GitHub account/repository information.

**I have a good faith belief that use of the copyrighted materials described above on the infringing web pages is not authorized by the copyright owner, or its agent, or the law.**

**I have taken fair]([https://www.lumendatabase.org/topics/22%22%3Efair](https://www.lumendatabase.org/topics/22%22%3Efair)) use into consideration.**

**I swear, under penalty of perjury, that the information in this notification is accurate and that I am the copyright owner, or am authorized to act on behalf of the owner, of an exclusive right that is allegedly infringed.**

**I have read and understand GitHub's Guide]([https://docs.github.com/articles/guide-to-submitting-a-dmca-takedown-notice/%22%3EGuide](https://docs.github.com/articles/guide-to-submitting-a-dmca-takedown-notice/%22%3EGuide)) to Submitting a DMCA Takedown Notice.**

**So that we can get back to you, please provide either your telephone number or physical address.**

[private]

**Please type your full name for your signature.**

[private]
Loading