Newt for Windows throws a Windows Defender alert #2

Closed
opened 2025-11-19 07:11:31 -06:00 by GiteaMirror · 1 comment
Owner

Originally created by @infinitehope2025 on GitHub (Jan 27, 2025).

Download is blocked by Defender. States that it contains a virus "Trojan:Win32/Wacatac.B!ml" and "This program is dangerous and executes commands from an attacker."

Originally created by @infinitehope2025 on GitHub (Jan 27, 2025). Download is blocked by Defender. States that it contains a virus "Trojan:Win32/Wacatac.B!ml" and "This program is dangerous and executes commands from an attacker."
Author
Owner

@oschwartz10612 commented on GitHub (Jan 28, 2025):

Hi,

Thank you for raising awareness of this issue.

In poking around online I believe this to be a false positive and/or a unreliable AV actor. Virustotal and defender are legitimate AV tools that do real good, but they just feed files into many different AV vendors. It is possible to get false positives or bad results from some of the vendors. Take a look at a few of the following similar threads I have found:

I dont want to downplay this but I have taking a look around the code and PRs here and everything appears to be in good order.

We will probably start providing hashes for built binaries at some point in our build pipeline to help ease some concerns. You can also follow our build instructions and checkout and build the code for yourself and scan it again to see what you think.

@oschwartz10612 commented on GitHub (Jan 28, 2025): Hi, Thank you for raising awareness of this issue. In poking around online I believe this to be a false positive and/or a unreliable AV actor. Virustotal and defender are legitimate AV tools that do real good, but they just feed files into many different AV vendors. It is possible to get false positives or bad results from some of the vendors. Take a look at a few of the following similar threads I have found: - [ ] https://github.com/SoftFever/OrcaSlicer/issues/1144 - [ ] https://github.com/getsops/sops/issues/1331 - [ ] https://github.com/ggerganov/llama.cpp/issues/898 I dont want to downplay this but I have taking a look around the code and PRs here and everything appears to be in good order. We will probably start providing hashes for built binaries at some point in our build pipeline to help ease some concerns. You can also follow our build instructions and checkout and build the code for yourself and scan it again to see what you think.
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: github-starred/newt#2