k9s_Windows_i386.tar.gz v0.19.2 Trojan detected

Created on 23 Apr 2020  路  7Comments  路  Source: derailed/k9s






Downloading k9s_Windows_i386.tar.gz v0.19.2 from a browser in Windows 10, Windows Defender reports that a Trojan is detected and blocks the file. Note that k9s_Windows_x86_64.tar.gz is not blocked.

Steps to reproduce the behavior:
Simply download the file from GitHub.

Windows Defender info:
k9s-2020-04-23_13-39-13

  • OS: Windows 10
  • K9s 0.19.2 x386
bug question

Most helpful comment

@guybarrette @AceHack Thank you both for reporting back! I've ran several vulnerability scans on the K9s binaries and it looks like either these are false positive and there is indeed an issue with some of K9s dependencies. From what I can tell the win-x64 images are always yielding clean scans, so I've decided to axe winx86 support in the next drop for the time being.

All 7 comments

@guybarrette Thank you for reporting this! This is surprising and unexpected. I don't have access to a windows machine so I can't test first hand. Is this something that occurred with previous versions of K9s win_386 or is this just on rev 0.19.2? I'll have to investigate further but for now I am going to axe the win_386 from the build in the next drop.

Just tested v0.19.1 and v0.19.0. Both are fine. Looks like the issue is with 0.19.2 only.

@guybarrette Thank you for this update Guy! It might be something went south with the last release win-386 K9s release also possibly this GO virus detection

Here is what I'd like to propose. I am close to drop a new rev 0.19.3. I could disable the i386 build or leave it on in this drop if you can help me validate whether there was an issue building the release or there is something wrong with the build win-i386 binary? Thank you!

@derailed More then happy to test it for you when it's up

I'm getting the same thing when trying to install with chocolatey, it installs version 19.2

I had the same problem with 19.1 and 19.0 from chocolatey, it was installing x86 version. I just installed using scoop which installs x64 19.2 version without any issues.

@guybarrette @AceHack Thank you both for reporting back! I've ran several vulnerability scans on the K9s binaries and it looks like either these are false positive and there is indeed an issue with some of K9s dependencies. From what I can tell the win-x64 images are always yielding clean scans, so I've decided to axe winx86 support in the next drop for the time being.

Was this page helpful?
0 / 5 - 0 ratings

Related issues

rahilb picture rahilb  路  3Comments

ArnaudMsh picture ArnaudMsh  路  3Comments

ctritten picture ctritten  路  3Comments

steffen-geissinger-by picture steffen-geissinger-by  路  3Comments

signaleleven picture signaleleven  路  3Comments