[GH-ISSUE #4141] 1.8.3.0 Malware reported on attempted install #2634

Closed
opened 2026-02-22 18:30:32 -05:00 by yindo · 1 comment
Owner

Originally created by @idiston on GitHub (Jul 14, 2025).
Original GitHub issue: https://github.com/Mintplex-Labs/anything-llm/issues/4141

Summary

Attempt to install AnythingLLM 1.8.3.0

Details

Bitdefender reports ~/temp/nsq4B09.tmp/7z-out/resources/app.asar as infected with Generic.Trojan.Electron.Malvert.A.528BFF99

PoC

Windows 11 Pro
Version: 10.0.26100 Build 26100

Impact

File quarantined. Application install doesnt complete

Originally created by @idiston on GitHub (Jul 14, 2025). Original GitHub issue: https://github.com/Mintplex-Labs/anything-llm/issues/4141 ### Summary Attempt to install AnythingLLM 1.8.3.0 ### Details Bitdefender reports ~/temp/nsq4B09.tmp/7z-out/resources/app.asar as infected with Generic.Trojan.Electron.Malvert.A.528BFF99 ### PoC Windows 11 Pro Version: 10.0.26100 Build 26100 ### Impact File quarantined. Application install doesnt complete
yindo closed this issue 2026-02-22 18:30:32 -05:00
Author
Owner

@timothycarambat commented on GitHub (Jul 14, 2025):

This is because you are using Bitdefender. There is no malware (you can inspect the asar if you like?) there is even a pinned comment about this on the repo right next to the button you clicked to create this issue. https://github.com/Mintplex-Labs/anything-llm/issues/4124

There is nothing we can do to resolve it, since the nature of doing the authenticated web scraping apparently matches some flag they use in their library. We have already submit a false positive submission and there is no further action we can take

@timothycarambat commented on GitHub (Jul 14, 2025): This is because you are using Bitdefender. There is no malware (you can inspect the asar if you like?) there is even a pinned comment about this on the repo right next to the button you clicked to create this issue. https://github.com/Mintplex-Labs/anything-llm/issues/4124 There is nothing we can do to resolve it, since the nature of doing the authenticated web scraping apparently matches some flag they use in their library. We have already submit a false positive submission and there is no further action we can take
yindo changed title from 1.8.3.0 Malware reported on attempted install to [GH-ISSUE #4141] 1.8.3.0 Malware reported on attempted install 2026-06-05 14:47:39 -04:00
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: Mintplex-Labs/anything-llm#2634