Headsup if you are using claude-mem: kaspersky flagged it reading credentials via PowerShell
A user reported that Kaspersky antivirus flagged "claude-mem" for suspicious activity involving PowerShell. The antivirus detected a high-threat Trojan, specifically VHO:Trojan.MSIL.Rozena.gen, attempting to read credentials. The malicious object, identified as xi3ofare.dll, was found in a temporary directory. This led the user to immediately uninstall claude-mem due to security concerns, despite not being a security expert.
时间与来源
时间显示为 UTC
显示时区:UTC
本地时区尚不可用,暂时显示 UTC。
发布当时偏移:UTC+02026年9月13日 11:24 UTC
收录当时偏移:UTC+02026年9月13日 17:01 UTC
- 发布
- 2026年9月13日 11:24
- 收录
- 2026年9月13日 17:01
- 来源类型
- 开发者社区
- 档位
- 社区
- 信源状态
- 正常
档位是按信源手工设定的编辑判断,不是逐条打分。
Im not a security expert, but this behavior looks not good and it is enough that I decided to uninstall claude-mem immediately.
kaspersky popped up with a high severity Trojan alert linked to a temporary DLL compiled on the fly by PowerShell. When looking into what triggered it, it turns out claude-mem runs dynamic C# using PowerShell to invoke native Win32 "CredRead" and poll Claude Code's login token every 30 seconds.
Even tho, if the intent wasnt malicious and its technically a heuristic false positive, running dynamic PowerShell shims to grab credentials in a tight loop is rough practice and triggered my AV for good reason.
* Event: Malicious object detected User: PC_NAME_PC\USER User type: Initiator Application name: powershell.exe Application path: C:\Windows\System32\WindowsPowerShell\v1.0 Component: File Anti-Virus Result description: Detected Type: Trojan Name: VHO:Trojan.MSIL.Rozena.gen Precision: Heuristic analysis Threat level: High Object type: File Object name: xi3ofare.dll Object path: C:\Users\USER\AppData\Local\Temp MD5 of an object: 3ADE4292B262029396E64A4AC7A01B9E Reason: Cloud Protection