nushell / nushell/nushell

[Windows/ESET] Scoop-installed nu.exe 0.115.1 reported as “Suspicious Object”

Open
#19,032 2 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
Rust
Stars
40.5k
Forks
2.3k
Avg merge
1d 19h
Merged PRs (30d)
85

Description

Bug report form
  • I have done a basic search of the issue tracker to find any existing issues that are similar.
  • I have checked that my version is at least the latest stable release available via my installation method.
Describe the bug

ESET reported one detection for the Windows executable nu.exe installed through Scoop. The ESET event identifies the object as Suspicious Object; it does not provide a malware family name or claim that an exploit was observed.

This report is intended to ask whether the detection is a false positive and whether the published Windows binary, its code signing, or the Scoop package metadata should be reviewed. It does not assert that Nushell is malicious.

How to reproduce
  1. Install or use Nushell 0.115.1 through Scoop on Windows.
  2. Scan the installed nu.exe with ESET.
  3. Observe the ESET event reporting the executable as Suspicious Object.

The ESET product edition, version, detection-engine/database version, scan mode, and notification screenshot were not included in the source event, so the exact detection may not be reproducible without those details.

Expected behavior

A genuine Nushell release binary installed through Scoop should not be reported as suspicious by ESET. If this is a false positive, users should be able to install and run Nushell without the executable being blocked or quarantined.

Configuration
key value
OS Windows 11
installation method Scoop
Nushell version 0.115.1
executable size 50.2 MB
security product ESET
ESET product/version Not provided in the source event
detection reason Suspicious Object
detection count 1
detection time 2026-09-16 08:26:22 (timezone not provided)

The output of version | transpose key value | to md --pretty was not included in the source event.

Additional context

The local username and machine name have been omitted from this public report. The alert identified the file as:

C:\Users\<username>\scoop\apps\nu\0.115.1\nu.exe

Hashes copied from the ESET event exactly as reported. The source did not specify the hash algorithms:

  • Hash 1: 90E392149504EF8D38D827D88EFB7AE6B7AED26F7ECC189494B445154AE40507
  • Hash 2: E115C6C50F3BD74BB9BFFC27EDD6E3C9

Earlier issue searches found reports involving Microsoft Defender and older Nushell versions; this issue is specifically about the ESET detection for Scoop-installed Nushell 0.115.1.

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start with the published Windows nu.exe 0.115.1 binary installed through Scoop and the two hashes recorded in the report. Check whether the ESET “Suspicious Object” detection can be reproduced with the missing ESET product, engine, scan-mode, and notification details, then review the binary’s code signing and Scoop package metadata; done means determining whether the report indicates a false positive or a distribution issue.

Written by the indexing model from the issue text.

Assessment

Tech stack
rust
Domain
release, security
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Active
Clarity
Needs clarification
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.