agentscope-ai / agentscope-ai/QwenPaw
[Bug]: Malware Bytes found Trojan Loader in Desktop Version WIndows
- Vorherrschende Sprache
- TypeScript
- Sterne
- 35k
- Forks
- 3.1k
- Ø Merge
- 1 T. 13 Std.
- Gemergte PRs (30 T.)
- 228
Beschreibung
## QwenPaw Version
Please note, I am English speaker and I DID look at the Alibaba security vulnerability report page and its way too confusing. IS this really malware or a false positive? I'm uninstalling until I hear back from your team.
PS. I love your work. Thanks for all you do.
Brendan
Latest desktop version
## Description
Malwarebytes
www.malwarebytes.com
Trojan Loader found
-Log Details-
Scan Date: 8/7/2026
Scan Time: 2:22 AM
Log File: 158604c8-91b3-11f1-9ca9-c0e434afe8ec.json
-Software Information-
Version: 5.6.2.268
Components Version: 160.0.5677
Update Package Version: 1.0.112990
License: Premium
-System Information-
OS: Windows 11 (Build 26200.8973)
CPU: x64
File System: NTFS
User: System
-Scan Summary-
Scan Type: Threat Scan
Scan Initiated By: Scheduler
Result: Completed
Objects Scanned: 276,289
Threats Detected: 1
Threats Quarantined: 1
Scan Duration: 4 min, 1 sec
-Scan Options-
Memory: Enabled
Startup: Enabled
File system: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Detect
PUM: Detect
-Scan Details-
Process: 0
(No malicious items detected)
Module: 0
(No malicious items detected)
Registry Key: 0
(No malicious items detected)
Registry Value: 0
(No malicious items detected)
Registry Data: 0
(No malicious items detected)
Data Stream: 0
(No malicious items detected)
Folder: 0
(No malicious items detected)
File: 1
Trojan.Loader, C:\USERS\INSIG\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\PROGRAMS\QWENPAW DESKTOP (DEBUG).LNK, Quarantined, 4133, 1419408, 1.0.112990, , ame, , D17F5BD257057A9093E21DE35A0A28B8, 95CED02037FEE41C61B45841B2B0248F43170BA8AFE0ED65ACF58ADFCB5B715C
Physical Sector: 0
(No malicious items detected)
WMI: 0
(No malicious items detected)
(end)
**Related PR(s):** #(optional)
**Security considerations:** [If applicable, e.g. auth, env/config exposure]
## Component(s) Affected
- [ ] Core / Backend (app, agents, config, providers, utils, local_models)
- [ ] Console (frontend web UI)
- [ ] Channels (DingTalk, Feishu, QQ, Discord, iMessage, etc.)
- [ ] Skills
- [ ] CLI
- [ ] Documentation (website)
- [ ] Tests
- [ ] CI/CD
- [ ] Scripts / Deploy
## Environment
- **QwenPaw version:** [e.g. 0.x.x or git commit]
- **OS:** [e.g. macOS 14, Ubuntu 22.04, Windows 11]
- **Install method:** [pip / one-line install / Docker / from source]
- **Python version (if applicable):** [e.g. 3.10]
## Steps to Reproduce
1.
2.
3.
## Actual vs Expected
- **Actual:**
- **Expected:**
## Logs / Screenshots
[Paste relevant log output or attach screenshots. Use code blocks for logs.]
```
(paste logs here)
```
## Additional Notes
[Optional: workarounds, similar issues, etc.]
Beitragsleitfaden
Rechercherichtung
Start by reviewing the Malwarebytes log in the issue, especially the quarantined QwenPaw Desktop shortcut, and confirm the exact Windows desktop build and installation context with the reporter. Done means determining whether the detection is a false positive or a real malware issue and documenting the team’s response; the payload names no source files, tests, or entry points.
Vom Indexierungsmodell aus dem Issue-Text verfasst.
Bewertung
- Bereich
- desktop, operating-systems, security
- Issue-Typ
- Bug
- Schwierigkeit
- 4/5
- Geschätzter Aufwand
- 3-5 Tage
- Aktivitätsstatus
- Aktiv
- Klarheit
- Muss geklärt werden
- Anfängerfreundlichkeit
- 20/100