opencode icon indicating copy to clipboard operation
opencode copied to clipboard

Threat Found. Trojan:Script/Wacatac.H!ml

Open defmarshal opened this issue 1 month ago • 9 comments

Description

Tried to open using Wezterm. typing opencode on console and press enter Windows Defender showing threat pop up Opencode is not opening.

Plugins

No response

OpenCode version

1.1.8

Steps to reproduce

Tried to open using Wezterm. typing opencode on console and press enter Windows Defender showing threat pop up Opencode is not opening.

Screenshot and/or share link

No response

Operating System

Windows 11

Terminal

Wezterm

defmarshal avatar Jan 10 '26 17:01 defmarshal

This issue might be a duplicate of existing issues. Please check:

  • #7655: Running opencode is flagged as trojan on windows - Same Wacatac.H!ml detection on Windows 11 with Wezterm
  • #7592: [False Positive?] Windows Defender detects Trojan:Win32/Wacatac.H!ml - Same trojan detection blocking OpenCode
  • #3415: Windows Defender falsely flags new releases as trojans - Umbrella issue tracking recurring Wacatac false positives
  • #3406: v0.15.16 was infected by a virus and removed by Windows Security - Same Wacatac trojan family issue
  • #1103: opencode-windows-x64.zip file contains virus - Older report of Windows antivirus blocking OpenCode

This appears to be part of a recurring pattern of Windows Defender false positives. Feel free to ignore if your specific case differs.

github-actions[bot] avatar Jan 10 '26 17:01 github-actions[bot]

i am getting the same issue every time i open opencode Image

TheDarkSkyXD avatar Jan 10 '26 21:01 TheDarkSkyXD

It seems that the installer archive is clean: https://www.virustotal.com/gui/file/8AB962BEF658B7E003DD0B982EE912F1EFD9FAADB988AA28582E9E0D2976D76C/detection.

Makishima avatar Jan 11 '26 07:01 Makishima

I have the same error for latest version

marcinsiennicki95 avatar Jan 11 '26 13:01 marcinsiennicki95

Same error: Windows Defender detects Trojan:Script/Wacatac.H!ml

affected elements file: C:\TMP.3aebb6a10f17efcd-00000001.dll

and blocks opencode 😱

More about Trojan https://www.microsoft.com/en-us/wdsi/threats/malware-encyclopedia-description?name=Trojan%3AScript%2FWacatac.H!ml&threatid=2147814524

magicprinc avatar Jan 11 '26 14:01 magicprinc

affected elements file: C:\TMP.3aebb6a10f17efcd-00000001.dll

The dll's name is different every time which makes it impossible to add as exclusion in Windows Defender/Security. So yeah, "just ignore it" LOL...

okazakov avatar Jan 11 '26 18:01 okazakov

The only way I was able to continue using OpenCode was to uninstall it, then install the previous version 1.1.7 But before you launch it, set "autoupdate" : "notify" in ~/.config/opencode/opencode.jsonc If you don't, OpenCode will auto upgrade to the latest on launch and get blocked again.

okazakov avatar Jan 11 '26 18:01 okazakov

Same error: Windows Defender detects Trojan:Script/Wacatac.H!ml

affected elements file: C:\TMP.3aebb6a10f17efcd-00000001.dll

and blocks opencode 😱

More about Trojan https://www.microsoft.com/en-us/wdsi/threats/malware-encyclopedia-description?name=Trojan%3AScript%2FWacatac.H!ml&threatid=2147814524

OK, so VirusTotal identifies THREE different threats in this DLL (the DLL name is different every time you try and run the latest openCode, which is suspicious on its own). I know false positives for OpenCode is a regular occurrencee, but on this occasions, think this deserves a serious look from the developers. https://www.virustotal.com/gui/file/c7155d1809bf7036fdff80f1d362183c8130ae4714951d78e0f0615a5bc83bc9

Image

okazakov avatar Jan 11 '26 22:01 okazakov

It seems that the installer archive is clean: https://www.virustotal.com/gui/file/8AB962BEF658B7E003DD0B982EE912F1EFD9FAADB988AA28582E9E0D2976D76C/detection.

You've checked the installer, but it's not the installer that triggers the threat detection. It's this DLL and only when you launch OpenCode: https://www.virustotal.com/gui/file/c7155d1809bf7036fdff80f1d362183c8130ae4714951d78e0f0615a5bc83bc9

okazakov avatar Jan 11 '26 22:01 okazakov