Google Play malware policy: fixes and checks
By The Draftbit team · Updated
Sources checked
This guide is for Apps flagged for potentially harmful code, including bundled dependencies.
Google can classify code as malware because of the risk it creates, even if you didn’t intend harm. A dependency or behavior affecting only some supported devices can still cause a rejection.
What to check
Start with the category, package version, and evidence in the notice. Preserve a copy of the submitted artifact for comparison. Inspect dependencies, downloaded code, privileged operations, data transfers, billing, and remote commands.
A Play Protect warning that an app is uncommon means Google lacks enough information to clear it as safe. That isn’t the same finding as confirmed malicious behavior. Read the actual classification before choosing an appeal argument.
How to address the rejection
Remove the harmful behavior and identify how it entered the build. Update or remove affected libraries and rebuild from a trusted dependency set. Verify that the behavior is absent across supported devices and remote configurations.
If you believe the classification is wrong, provide a focused explanation of the flagged code and its observed behavior. A clean scan from another tool can be supporting evidence, but it doesn’t explain away the behavior Google identified.
Official sources
We checked these instructions against the sources below. The console layout may change, and your review decision may call for different steps.
- Google Play: Malware Checked 22 September 2026