keybase / keybase/keybase-issues

Windows Security detected & quaratntined keybaserq.exe as Trojan:Script/Wacatac.B!ml

Open
#4,263 1 comment 1 reaction 0 assignees View on GitHub
Dominant language
No language data
Stars
899
Forks
40
PR merge metrics
No merged PRs in 30d

Description

Windows Security detected & quaratntined keybaserq.exe as Trojan:Script/Wacatac.B!ml

It states
"This program is dangerous and executes commands from an attacker.
\AppData\Local\Keybase\keybaserq.exe"

also reported here on reddit;
https://www.reddit.com/r/Keybase/comments/1d2tvyb/keybaserqexe_detected_as_a_trojan_by_windows/

Very likely a false positive, and not the first time this has happened with Keybase. However as precaution I will not allow the process until either this is openly stated and/or a "clean" update is pushed.

Contributor guide

No contributing guide indexed for this repository

Research direction

The report only identifies Windows Security's quarantine of AppData\Local\Keybase\keybaserq.exe and links to a Reddit discussion; it names no source file, test, or entry point. Start by reviewing the reported detection and the linked discussion, with project context needed to determine whether the executable is legitimate. Done would require a confirmed explanation or a clean update, neither of which is defined in the issue.

Written by the indexing model from the issue text.

Assessment

Domain
security
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
20/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.