arduino / arduino/Arduino

Zillya Trojan.CrisisHT.Win32.210 and Exploit.Zip.Heuristic-java.csrvpr detected by VirusTotal

Open
#10,536 1 comment 0 reactions 1 assignee Claimed by @rsora View on GitHub
security Type: Bug
Dominant language
Java
Stars
14.6k
Forks
7k
PR merge metrics
No merged PRs in 30d

Description

I have just downloaded ARDUINO 1.8.13 from the [official website](https://www.arduino.cc/download_handler.php?f=/arduino-1.8.13-windows.exe) and ran it through VirusTotal. I was surprised to find that VirusTotal detects a trojan in the installer.

Then I downloaded the same version from [github](https://github.com/arduino/Arduino/releases/download/1.8.13/arduino-1.8.13.tar.xz) and then ran it through VirusTotal. This time it detected Exploit.Zip.Heuristic-java.csrvpr.

![Arduino-1 8 13-Trojan CrisisHT Win32 210](https://user-images.githubusercontent.com/10776430/88085846-00bd0f80-cbb9-11ea-95d5-944eb0ba9a21.jpg)
![Arduino-1 8 13-Exploit Zip Heuristic-java csrvpr](https://user-images.githubusercontent.com/10776430/88085861-0581c380-cbb9-11ea-9acb-04bf20ce7af8.jpg)

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.