keybase / keybase/keybase-issues
Windows Security detected & quaratntined keybaserq.exe as Trojan:Script/Wacatac.B!ml
- Dominant language
- No language data
- Stars
- 899
- Forks
- 40
- PR merge metrics
- No merged PRs in 30d
Description
Windows Security detected & quaratntined keybaserq.exe as Trojan:Script/Wacatac.B!ml
It states
"This program is dangerous and executes commands from an attacker.
\AppData\Local\Keybase\keybaserq.exe"
also reported here on reddit;
https://www.reddit.com/r/Keybase/comments/1d2tvyb/keybaserqexe_detected_as_a_trojan_by_windows/
Very likely a false positive, and not the first time this has happened with Keybase. However as precaution I will not allow the process until either this is openly stated and/or a "clean" update is pushed.
Contributor guide
No contributing guide indexed for this repository
Research direction
The report only identifies Windows Security's quarantine of AppData\Local\Keybase\keybaserq.exe and links to a Reddit discussion; it names no source file, test, or entry point. Start by reviewing the reported detection and the linked discussion, with project context needed to determine whether the executable is legitimate. Done would require a confirmed explanation or a clean update, neither of which is defined in the issue.
Written by the indexing model from the issue text.
Assessment
- Domain
- security
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 20/100