I am serious. The amount of fake projects is scandalous. I am talking about indexed projects that are unchallenged for months. And even reported projects stay unquarantined and sometimes indexed for weeks.
Most of those things are uploaded on obviously hacked accounts. The problem is not something simple as a try my game on discord scam, where you get a password for a rar archive. It is the let's browse shiny new games on itch minefield. The malware will take away your itch credentials (cookie theft) and not even 2fa will protect your account. And who knows what else they do.
Since some of those hacked accounts have had payment options, some of those scams have pay what you want active, sometimes even paid only. They have fake ratings sometimes and sometimes are not reported, so you can encounter a scam that is half a year old or older.
Fortunate for many players, the scammers most often target adult games. But I have also seen regular indie games, that were released on Steam.
So if you are unsure about a game, trust your scepticism. And if you are sure it is a scam, report it. I saw games with comments about it being a scam, but apparantly the users did not bother to click the report button. The scammers are experimenting with all sorts of variations in their publications. And this sometimes includes impersonating the original creator by linking sites of the original creator.
Oh the games might be real, but at the very least they are pirated, and at the worst you get infected with malware and as a bonus your itch account is used to spread more malware.
General tipps:
If it looks too good to be true, it probably isn't. Seeing a finished game here for free that is paid on Steam? Obvious fake.
Use the itch app sandbox mode. Or create your own sandbox mode (use the internet to find out how. It involves creating a new user on windows that has a password and starting the not yet trusted app as this different user. This way at least most of your stuff should be safe-ish.)
One method of detection avoidance is to not have the malware in the downloadabe, but prompt the user to download additional stuff. So be very suspicous, if you have to download other things.
While some legit games do provoke a warning message from antivirus, guess what a scammer would tell you about that message. Right. Never trust an unknown person on the internet that tells you to shut off your protection. Triple check, why the message appears. On hopefully rare occasions even legit devs could have their development computer hacked and they unknowingly uploaded malware.
There are many red flags and some green flags for games. I shall not talk about them in detail, lest the scammers upgrade their schemes. But if you regularly browse new games, you will notice patterns. Be careful. They do also appear in new&popular. And in popular if you select tags with few hundred games.
But the best green flag is a game that is alive. Not old and undeleted, not having a dozen fake ratings, not being posted on an old hacked account that still has followers and even payment possible, not having several games posted in a few days, not having links to patreon and twitter, but alive in the sense of having an active community and surroundings.
---
For any admin reading this. I collect them in a private collection. Accounts get hacked right and left. Please do something, anything to protect the users of this site. Whatever you are doing now is not working good enough.