Skip to content

Investigate ESET detection of the Windows native package #191

Description

@teng-lin

Upstream migration

Migrated from the archived upstream report: thewh1teagle/rookie#99

Original reporter: @chirsz-ever

Problem

ESET identified an archived @rookie-rs/api Windows native binary as a Win64/PSW.Agent variant. This may have been a heuristic false positive, but the result was not reproduced or cleared. The maintained fork now publishes under rookie-cookies, so current artifacts need an independent check.

Confirmation requested

@chirsz-ever, if possible, please scan a current fork-built Windows artifact and report:

  • the exact rookie-cookies version and artifact filename
  • SHA-256 of the scanned file
  • ESET product and signature/database version
  • exact detection name and whether ESET still flags it

Do not execute or redistribute any artifact you believe is malicious.

Completion criteria

  • Reproduce or rule out the detection against a current, checksum-identified artifact.
  • Verify the artifact corresponds to the tagged source and release workflow.
  • If reproduced, minimize the triggering code/build characteristic and submit the artifact through the vendor's false-positive process when appropriate.
  • Document checksums and the final vendor disposition.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    P2Medium priority

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions