google-gemini / google-gemini/gemini-cli

stuff is getting detected as stealers

Open
#15,404 8 comments 0 reactions 1 assignee Claimed by @theshloksschauhan View on GitHub
area/security help wanted kind/bug priority/p2 status/bot-triaged type/bug
Dominant language
TypeScript
Stars
107k
Forks
14.6k
Avg merge
2d 3h
Merged PRs (30d)
45

Description

### What happened?

The file C:\Users\myusername\AppData\Local\Temp\gemini-client-error-Turn.run-sendMessageStream-2025-12-21T19-21-57-891Z.json is infected with Generic.PyStealer.AD.3D27F607 and was moved to quarantine.

C:\Users\myusername\.gemini\tmp\9254d63da2c65066db8b3be0025f794448de789ae80341e24e7e0bb4a8556d3c\chats\session-2025-12-21T19-19-819dd6d9.json is infected with Generic.PyStealer.AD.C43124FA and was moved to quarantine.

### What did you expect to happen?

i expect it to not get detected

### Client information

Client Information

CLI Version 0.21.3 │
│ Git Commit d0cdeda00 │
│ Model auto-gemini-3 │
│ Sandbox no sandbox │
│ OS win32 │
│ Auth Method OAuth │
│ User Email ********@gmail.com │
│ IDE Client VS Code

### Login information

_No response_

### Anything else we need to know?

_No response_

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.