PlatformIO shows up as pioarduino?

I’ve just tried bootstrapping a new project with that fork. Indeed, the official PlatformIO packages were replaced with unofficial ones, and PIO Home now contains injections designed to boost pioarduino’s popularity. Copying someone else’s success rarely works out. What is more, @jason2866 has never contributed to PIO Home or our IDE, so we don’t understand the motivation behind these aggressive actions. We reached out to @jason2866 (the owner of pioarduino) regarding these issues, but we have received no response.

At PlatformIO, we never expected anyone to use a dev-platform to compromise PlatformIO Core and its dependencies. Because of that trust, we provided a rich API for the “PlatformIO Development Platform”, including full code execution and disk manipulation access. While official packages must pass our Malware & Vulnerability Isolation Environment before being published to the PlatformIO Registry, unofficial packages can execute whatever code they want - even deleting personal files. This highlights the severe risks of using unofficial packages in any software ecosystem, not just PlatformIO.

We are currently working on PlatformIO Core 7.0 and will address this security vulnerability directly. In the meantime, please exercise extreme caution with that fork or inspect its source code every time it updates. Typically, when someone leeches off open-source software to artificially build a user base, the next step is monetizing or exploiting those users - which can easily lead to hidden malicious injections.