actions / runner-images

GitHub Actions runner images
MIT License
10.01k stars 3.02k forks source link

Bearfoos malware detected #10702

Open stoopman opened 2 days ago

stoopman commented 2 days ago

Description

Azure Defender for Cloud reports the following security alert when building the win22/20240922.1 image:

'Bearfoos' malware was detected on this device. An attacker might be attempting to move laterally to this device from another device on the network. Defender detected 'Bearfoos' malware in bindgen.exe which was modified by the remotely invoked process powershell.exe via WinRs

Platforms affected

Runner images affected

Image version and build link

windows-latest

Is it regression?

Unsure

Expected behavior

No malware detection

Actual behavior

Azure Defender for Cloud reports the following security alert when building the win22/20240922.1 image:

'Bearfoos' malware was detected on this device. An attacker might be attempting to move laterally to this device from another device on the network. Defender detected 'Bearfoos' malware in bindgen.exe which was modified by the remotely invoked process powershell.exe >via WinRs

Repro steps

Run the build of the windows 2022 image and have Azure Defender scan the build VM

vidyasagarnimmagaddi commented 2 days ago

Hi @stoopman , Thank you for bringing this issue to us. We are looking into this issue and will update you on this issue after investigating