astral-sh / ruff-vscode

A Visual Studio Code extension with support for the Ruff linter.
Other
1.04k stars 52 forks source link

Trojan - Bearfoos.A!ml #259

Closed LLoyderino closed 1 year ago

LLoyderino commented 1 year ago

Hi, I've installed the extension and couple of minutes after my Windows Defender detected a Trojan "Bearfoos.A!ml".

I hope I'm posting on the correct repository, this is a screenshot of the security threat notification indicating "ruff.exe" as affected: Threat

I don't know if it helps but this is my VS Code version: VSC Version

zanieb commented 1 year ago

Thanks for reporting!

It looks like this is commonly reported as a false positive and I can't find more details on what this particular trojan meanshttps://www.microsoft.com/en-us/wdsi/threats/malware-encyclopedia-description?Name=Trojan:Win32/Bearfoos.A!ml&ThreatID=2147731250 has very little detail.

LLoyderino commented 1 year ago

Thanks for reporting!

It looks like this is commonly reported as a false positive and I can't find more details on what this particular trojan meanshttps://www.microsoft.com/en-us/wdsi/threats/malware-encyclopedia-description?Name=Trojan:Win32/Bearfoos.A!ml&ThreatID=2147731250 has very little detail.

I've done a full PC scan with two different antiviruses after deleting the file and nothing else was found, it might be a false positive...

zanieb commented 1 year ago

@LLoyderino please consider checking the file in question with another tool such as https://www.virustotal.com/gui/home/upload

Can you also please show more of the file path? What is the Scripts/ directory here?

zanieb commented 1 year ago

A scan of our latest release artifact for Windows at dist-x86_64-pc-windows-msvc/ruff-win32-x64/extension/bundled/libs/bin/ruff.exe shows no problem.

https://www.virustotal.com/gui/file/153709b9779d94b9bd276c46bbcb5664ff5346fda3432ee6748f5fc0f69d30f7

Let us know if you have more details.