being flagged as a trojan
Closed this issue · 4 comments
I am aware of this, as someone else on reddit reported as well. My honest guess would be its just a false positive from the library codes used to compile the binary file.
Let me try to compile one using virtual environment and minimal packages and see if that helps.
For future reference I will suggest anyone to have their own peace of mind, please compile your own exe from the main.py if possible. It's not much difficult, just install a python version and follow the steps in main page.
@invcble
It might be a good idea to pin this in case anyone else comes looking. I skimmed the code and didn't find anything malicious, so I assume it's the registry and documents access that is making that one vendor think it's a password stealer.
EDIT: Did a Tria.ge run on the latest binary from releases. Despite it being labelled as "suspicious," it doesn't show anything unexpected. It's only marked suspicious because it adds itself to run in the registry when you check the button to load at start, and because it seems to restart itself when you change the theme.
https://tria.ge/250204-mhz7wsvqbl/behavioral1