anomalyco / anomalyco/opencode
opencode detected as malware by Cortex XDR
Nobody has claimed this yet.
- Dominant language
- TypeScript
- Stars
- 209k
- Forks
- 27.5k
- PR merge metrics
- PR metrics pending
Description
Description
Cortex XDR, installed and centrally managed by my company on my work laptop, detects the OpenCode executable as malware and blocks it from running.
Since Cortex XDR is managed by the company, I cannot whitelist or add a local exception for OpenCode.
This effectively prevents using OpenCode in corporate environments where Cortex XDR endpoint protection is enforced.
It may be a false positive, but it would be useful to investigate what in the distributed binary/build is triggering the detection and whether the binary could be submitted to Palo Alto Networks for false-positive analysis.
Plugins
No response
OpenCode version
1.18.31
Steps to reproduce
- Install OpenCode.
- Run opencode.
- Cortex XDR detects the executable as malware.
- Cortex XDR blocks its execution.
Screenshot and/or share link
Operating System
MacOS 26.7 (screenshot says 26.6, I updated the OS after this issue and it is still happening)
Terminal
No response
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start by reproducing the block with OpenCode 1.18.31 on macOS using Cortex XDR, then investigate what in the distributed executable or build triggers the detection. Done means identifying a likely cause and determining whether the executable can be submitted to Palo Alto Networks for false-positive analysis.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- macos
- Domain
- security
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Active
- Clarity
- Mostly clear
- Newbie friendliness
- 45/100