Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Issue]: Setup is detected as malicious by 2 of 72 vendors on VirusTotal #1228

Open
ChristianGalla opened this issue Jan 28, 2025 · 1 comment

Comments

@ChristianGalla
Copy link

ChristianGalla commented Jan 28, 2025

What happened?

Google and Varist detect the setup file of the latest release 1.2.2 as malicious.

Image

https://www.virustotal.com/gui/file/2d5ad523aa6182205da77c0eb8210638aaa8792f4e6a4bc12e1ac854c5455a68

I am not sure if this is related, but it looks like the copyright metadata is not correct:

Image

What did you expect to happen?

No malicious software is detected

Version

1.2.0 or newer (Default)

Which version of Windows?

No response

Which locale?

None

Which shell are you running NVM4W in?

No response

User Permissions?

Other, please describe

Is Developer Mode enabled?

None

Relevant log/console output

Debug Output

n/a

Anything else?

I created a bug issue instead of reporting a Security Vulnerability, because I assume this is a false alarm.

@coreybutler
Copy link
Owner

This is a false positive. Several other AV tools have incorrectly reported this as a trojan too. Ikarus was the most recent (see here).

Since you posted, Google has already been removed from the list. I'll try to reach out to Varist when time allows (I have to reach out to each of these vendors individually).

I'm going to leave this open because the metadata issue is a bug... looks like an encoding issue.

Thanks for reporting!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants