HarbourMasters / HarbourMasters/Ghostship

Windows antivirus and VirusTotal.com triggered over Mary-Celeste-Alfa release.

Open
#203 9 comments 0 reactions 0 assignees View on GitHub
Dominant language
C
Stars
749
Forks
51
Avg merge
15h 39m
Merged PRs (30d)
29

Description

Hello.
Windows Defenders is triggered over the lastest release, Mary-Celeste-Alfa.
Supposedly, it contains a Trojan script named Wacatac.h!ml

Can someone confirm this is false positive, please ? Considering GitHub was recently hacked via malicious Visual Studio Code extensions and thousands of repos got busted with malwares and credentials stolen, I am not taking a single risk unzipping or running something that triggers my antivirus.

Thank you.

Image

Contributor guide

No contributing guide indexed for this repository

Research direction

Start by inspecting the Mary-Celeste-Alfa release artifact and the reported Wacatac.h!ml detection, then compare the release contents with the project source and build context. Done means establishing whether the alert is a false positive or identifying the affected artifact and documenting the evidence and next action.

Written by the indexing model from the issue text.

Assessment

Domain
release, security
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Quiet
Clarity
Needs clarification
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.