google-gemini / google-gemini/gemini-cli
stuff is getting detected as stealers
- Dominant language
- TypeScript
- Stars
- 107k
- Forks
- 14.6k
- Avg merge
- 2d 3h
- Merged PRs (30d)
- 45
Description
### What happened?
The file C:\Users\myusername\AppData\Local\Temp\gemini-client-error-Turn.run-sendMessageStream-2025-12-21T19-21-57-891Z.json is infected with Generic.PyStealer.AD.3D27F607 and was moved to quarantine.
C:\Users\myusername\.gemini\tmp\9254d63da2c65066db8b3be0025f794448de789ae80341e24e7e0bb4a8556d3c\chats\session-2025-12-21T19-19-819dd6d9.json is infected with Generic.PyStealer.AD.C43124FA and was moved to quarantine.
### What did you expect to happen?
i expect it to not get detected
### Client information
Client Information
CLI Version 0.21.3 │
│ Git Commit d0cdeda00 │
│ Model auto-gemini-3 │
│ Sandbox no sandbox │
│ OS win32 │
│ Auth Method OAuth │
│ User Email ********@gmail.com │
│ IDE Client VS Code
### Login information
_No response_
### Anything else we need to know?
_No response_
Contributor guide
Assessment
This issue has not been assessed yet.