[Windows/ESET] Scoop-installed nu.exe 0.115.1 reported as “Suspicious Object”
Nobody has claimed this yet.
- Dominant language
- Rust
- Stars
- 40.5k
- Forks
- 2.3k
- Avg merge
- 1d 19h
- Merged PRs (30d)
- 85
Description
Bug report form
- I have done a basic search of the issue tracker to find any existing issues that are similar.
- I have checked that my version is at least the latest stable release available via my installation method.
Describe the bug
ESET reported one detection for the Windows executable nu.exe installed through Scoop. The ESET event identifies the object as Suspicious Object; it does not provide a malware family name or claim that an exploit was observed.
This report is intended to ask whether the detection is a false positive and whether the published Windows binary, its code signing, or the Scoop package metadata should be reviewed. It does not assert that Nushell is malicious.
How to reproduce
- Install or use Nushell
0.115.1through Scoop on Windows. - Scan the installed
nu.exewith ESET. - Observe the ESET event reporting the executable as
Suspicious Object.
The ESET product edition, version, detection-engine/database version, scan mode, and notification screenshot were not included in the source event, so the exact detection may not be reproducible without those details.
Expected behavior
A genuine Nushell release binary installed through Scoop should not be reported as suspicious by ESET. If this is a false positive, users should be able to install and run Nushell without the executable being blocked or quarantined.
Configuration
| key | value |
|---|---|
| OS | Windows 11 |
| installation method | Scoop |
| Nushell version | 0.115.1 |
| executable size | 50.2 MB |
| security product | ESET |
| ESET product/version | Not provided in the source event |
| detection reason | Suspicious Object |
| detection count | 1 |
| detection time | 2026-09-16 08:26:22 (timezone not provided) |
The output of version | transpose key value | to md --pretty was not included in the source event.
Additional context
The local username and machine name have been omitted from this public report. The alert identified the file as:
C:\Users\<username>\scoop\apps\nu\0.115.1\nu.exe
Hashes copied from the ESET event exactly as reported. The source did not specify the hash algorithms:
- Hash 1:
90E392149504EF8D38D827D88EFB7AE6B7AED26F7ECC189494B445154AE40507 - Hash 2:
E115C6C50F3BD74BB9BFFC27EDD6E3C9
Earlier issue searches found reports involving Microsoft Defender and older Nushell versions; this issue is specifically about the ESET detection for Scoop-installed Nushell 0.115.1.
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start with the published Windows nu.exe 0.115.1 binary installed through Scoop and the two hashes recorded in the report. Check whether the ESET “Suspicious Object” detection can be reproduced with the missing ESET product, engine, scan-mode, and notification details, then review the binary’s code signing and Scoop package metadata; done means determining whether the report indicates a false positive or a distribution issue.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- rust
- Domain
- release, security
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Active
- Clarity
- Needs clarification
- Newbie friendliness
- 35/100