Headsup if you are using claude-mem: kaspersky flagged it reading credentials via PowerShell
A user reported that Kaspersky antivirus flagged "claude-mem" for suspicious activity involving PowerShell. The antivirus detected a high-threat Trojan, specifically VHO:Trojan.MSIL.Rozena.gen, attempting to read credentials. The malicious object, identified as xi3ofare.dll, was found in a temporary directory. This led the user to immediately uninstall claude-mem due to security concerns, despite not being a security expert.
Time & source
Times shown in UTC
Display time zone: UTC
Local time zone unavailable; showing UTC.
PublishedOffset at this time: UTC+0Sep 13, 2026, 11:24 UTC
IngestedOffset at this time: UTC+0Sep 13, 2026, 17:01 UTC
- Published
- Sep 13, 2026, 11:24
- Ingested
- Sep 13, 2026, 17:01
- Source type
- Dev community
- Tier
- Community
- Source status
- Healthy
Tier is a per-source editorial setting, not a per-item score.
Im not a security expert, but this behavior looks not good and it is enough that I decided to uninstall claude-mem immediately.
kaspersky popped up with a high severity Trojan alert linked to a temporary DLL compiled on the fly by PowerShell. When looking into what triggered it, it turns out claude-mem runs dynamic C# using PowerShell to invoke native Win32 "CredRead" and poll Claude Code's login token every 30 seconds.
Even tho, if the intent wasnt malicious and its technically a heuristic false positive, running dynamic PowerShell shims to grab credentials in a tight loop is rough practice and triggered my AV for good reason.
* Event: Malicious object detected User: PC_NAME_PC\USER User type: Initiator Application name: powershell.exe Application path: C:\Windows\System32\WindowsPowerShell\v1.0 Component: File Anti-Virus Result description: Detected Type: Trojan Name: VHO:Trojan.MSIL.Rozena.gen Precision: Heuristic analysis Threat level: High Object type: File Object name: xi3ofare.dll Object path: C:\Users\USER\AppData\Local\Temp MD5 of an object: 3ADE4292B262029396E64A4AC7A01B9E Reason: Cloud Protection