arnoappenzeller / PiPifier

PiPifier is a native macOS 10.12 Safari extension that lets you use every HTML5 video in Picture in Picture mode
MIT License
756 stars 60 forks source link

Bitcoin mining malware detected in PiPifier.app #56

Closed pieterdd closed 6 years ago

pieterdd commented 6 years ago

So this just happened on my machine…

malware popup

Avast matched a file in PiPifier.app with MacOS:BitCoinMiner-AS [Trj]. What's going on here?

arnoappenzeller commented 6 years ago

I'm not sure from which source you got PiPifier but in the Mac AppStore Version and here the Github Version (where you can see the source - the only Versions I provide) is no Bitcoin miner. In addition avast points to libswiftDispatch.dylib which is part of the Swift programming language standard library. I would rather see this as a false positive

pieterdd commented 6 years ago

If I remember correctly, I got my copy from the App Store (as evidenced by the 'Open' button instead of 'Get'):

app

It's possible that some other process messed with it, or that Avast detected a false positive. Regardless, I just wanted to report it so that you're aware this is happening. If other people have this too, they'll probably find this thread via Google and add their reports.

arnoappenzeller commented 6 years ago

No worries - I guess there are a lot of extension that are doing nasty things like mining or affiliate hijacking... So thanks for the report!

What version of Avast are you using? If I have some spare time I'll check it out and maybe get in touch with them and find out what's causing this

jesperstig commented 6 years ago

It's not hijacked by another process.

The exact same just happened to me. It must be a false positive by Avast

arnoappenzeller commented 6 years ago

Wow... this is becoming scary.

I just contacted Avast about this - I hope they fix it soon. Not looking forward to the AppStore reviews and mails from people thinking the app is mining Bitcoin...

arnoappenzeller commented 6 years ago

Seems PiPifier is not the only one affected:

arnoappenzeller commented 6 years ago

This is a confirmed false positive (see (here)[https://forum.avast.com/index.php?topic=216164.0])

Should be fixed by Avast soon