Brooooooklyn / Brooooooklyn/Image

[Bug] Flagged as malicious

Closed
#246 0 comments 0 reactions 0 assignees View on GitHub
bug
Dominant language
Rust
Stars
416
Forks
13
Avg merge
10d 23h
Merged PRs (30d)
2

Description

### Search before asking

- [x] I searched in the [issues](https://github.com/Brooooooklyn/Image/issues) and found nothing similar.

### Image version

1.11.0 and above

### System version

N/A

### Node.js version

N/A

### Minimal reproduce step

N/A

### What did you expect to see?

N/A

### What did you see instead?

N/A

### Anything else?

Wanted to use @napi-rs/image in plugin that requires mandatory virustotal.com scan pass.
Starting from version 11.1.0 and every version above that windows library file - image.win32-x64-msvc.node get flagged as malicious.

1.11.0
Kaspersky - Trojan.Win32.DLLhijack.amom

1.12.0
Kaspersky - Trojan.Win32.DLLhijack.agjz
TrendMicro - Trojan.Win64.DLLHIJACK.TL0101HJ26ZP

1.13.0
Alibaba - Trojan:Win32/DLLhijack.0edaadad
Sophos - Mal/Generic-S
TrendMicro - Trojan.Win64.DLLHIJACK.TL0101HJ26ZP
TrendMicro-HouseCall - Trojan.Win64.DLLHIJACK.TL0101HJ26ZP

1.14.0
Alibaba - Trojan:Win32/DLLhijack.990f19e1
Kaspersky - Trojan.Win32.DLLhijack.ajou
Kingsoft - Win32.Trojan.DLLhijack.ajou
Sophos - Mal/Generic-S
TrendMicro-HouseCall - Trojan.Win64.DLLHIJACK.TL0101HE26ZD

### Are you willing to submit a PR?

- [ ] I'm willing to submit a PR!

Contributor guide

No contributing guide indexed for this repository

Research direction

Start by investigating the Windows artifact image.win32-x64-msvc.node from @napi-rs/image releases 1.11.0 through 1.14.0 and reproduce the listed VirusTotal detections. Compare the affected release binaries and document whether newer builds still trigger the named scanners; done means the Windows library passes the required scan or the false-positive cause is clearly identified.

Written by the indexing model from the issue text.

Assessment

Tech stack
node.js, rust
Domain
operating-systems, release, security
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Active
Clarity
Needs clarification
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.