Spacy: Virus alert for english model (en_core_web_sm-2.0.0)

Created on 8 Nov 2018  Â·  4Comments  Â·  Source: explosion/spaCy

How to reproduce the behaviour

strings.json in 'en_core_web_sm-2.0.0/en_core_web_sm/en_core_web_sm-2.0.0/vocab' triggers an alert with avast (JS:Downloader-FPP [Trj]).

See also: https://www.virustotal.com/fr/file/21c0157d2d05e3deafe86c936f45874ab612defbaeb59c0c91e0b6940958ffc7/analysis/

I guess some part of the json (like certains urls e.g. http://www.al-jazirah.com.sa/cars/29112006/rood55.htm" or words) triggers the antivirus.

Your Environment

  • Platform: Windows-10-10.0.17134-SP0
  • spaCy version: 2.0.16
  • Python version: 3.5.4
models third-party

Most helpful comment

Good news, bad news.
The good news is that Avast no longer flags the file as a malware. The bad news is that now Qihoo-360, a Chinese security firm, does.
False positive report sent.

All 4 comments

Thanks for sharing this – I've been wondering what was going on! I suspect this must have been a recent addition, like a new exploit being discovered that used a strings.json or included some of the strings, because it only started coming up the other day. (A user reported that the model would only install without strings.json and turning off their antivirus helped. We also received a separate email with a similar report.)

Not sure what we should do about this 🤔

I've reported it as a false positive. Hopefully its just a minor fix - on their part.

Good news, bad news.
The good news is that Avast no longer flags the file as a malware. The bad news is that now Qihoo-360, a Chinese security firm, does.
False positive report sent.

This thread has been automatically locked since there has not been any recent activity after it was closed. Please open a new issue for related bugs.

Was this page helpful?
0 / 5 - 0 ratings