opencode icon indicating copy to clipboard operation
opencode copied to clipboard

Windows antivirus alert when running OpenCode.

Open iceriver20002000 opened this issue 1 month ago • 10 comments

Question

Image

iceriver20002000 avatar Jan 13 '26 12:01 iceriver20002000

This issue might be a duplicate of existing issues. Please check:

  • #7919: Windows Defender reports Trojan:Win32/Wacatac.H!ml when launching the latest version of OpenCode
  • #7592: [False Positive?] Windows Defender detects Trojan:Win32/Wacatac.H!ml when running opencode
  • #7821: Windows Defender says Found Trojan
  • #7669: Threat Found. Trojan:Script/Wacatac.H!ml
  • #7655: Running opencode is flagged as trojan on windows - Installed through Node Package Manager
  • #3415: Windows Defender falsely flags new releases as trojans
  • #3406: v0.15.16 was infected by a virus and removed by Windows Security

Feel free to ignore if none of these address your specific case.

github-actions[bot] avatar Jan 13 '26 12:01 github-actions[bot]

Image

I encountered exactly the same bug.

Trojan:Script/Wacatac.C!ml

BaseBlank avatar Jan 13 '26 13:01 BaseBlank

any chance? 😭

magicprinc avatar Jan 13 '26 14:01 magicprinc

The current solution is to use the old version and disable any upgrades. Alternatively, you can ignore the warnings from Windows Defender and continue using the system, but I do not recommend this approach. It’s best to wait patiently for the author to fix this issue.

BaseBlank avatar Jan 13 '26 14:01 BaseBlank

Alternatively, you can ignore the warnings from Windows Defender and continue using the system

Well... you can't ignore it. The DLL that triggers Windows Defender keeps changing name every time Windows Defender blocks it. It's kinda chicken & egg situation that prevents us from adding it into exclusions. You don't know the name of the DLL until you run OpenCode, and once you run it, Windows Defender blocks the file and removes it. And you can go in circles indefinitely.

okazakov avatar Jan 14 '26 04:01 okazakov

The current solution is to use the old version and disable any upgrades. Alternatively, you can ignore the warnings from Windows Defender and continue using the system, but I do not recommend this approach. It’s best to wait patiently for the author to fix this issue.

What is the latest version that does not have this problem?

norm2782 avatar Jan 14 '26 04:01 norm2782