跳到正文
RCreddit.com·

Headsup if you are using claude-mem: kaspersky flagged it reading credentials via PowerShell

AI 摘要

A user reported that Kaspersky antivirus flagged "claude-mem" for suspicious activity involving PowerShell. The antivirus detected a high-threat Trojan, specifically VHO:Trojan.MSIL.Rozena.gen, attempting to read credentials. The malicious object, identified as xi3ofare.dll, was found in a temporary directory. This led the user to immediately uninstall claude-mem due to security concerns, despite not being a security expert.

时间与来源

时间显示为 UTC

显示时区:UTC

本地时区尚不可用,暂时显示 UTC。

发布当时偏移:UTC+02026年9月13日 11:24 UTC

收录当时偏移:UTC+02026年9月13日 17:01 UTC

发布
2026年9月13日 11:24
收录
2026年9月13日 17:01
来源类型
开发者社区
档位
社区
信源状态
正常

档位是按信源手工设定的编辑判断,不是逐条打分。

Im not a security expert, but this behavior looks not good and it is enough that I decided to uninstall claude-mem immediately.

kaspersky popped up with a high severity Trojan alert linked to a temporary DLL compiled on the fly by PowerShell. When looking into what triggered it, it turns out claude-mem runs dynamic C# using PowerShell to invoke native Win32 "CredRead" and poll Claude Code's login token every 30 seconds.

Even tho, if the intent wasnt malicious and its technically a heuristic false positive, running dynamic PowerShell shims to grab credentials in a tight loop is rough practice and triggered my AV for good reason.

* Event: Malicious object detected User: PC_NAME_PC\USER User type: Initiator Application name: powershell.exe Application path: C:\Windows\System32\WindowsPowerShell\v1.0 Component: File Anti-Virus Result description: Detected Type: Trojan Name: VHO:Trojan.MSIL.Rozena.gen Precision: Heuristic analysis Threat level: High Object type: File Object name: xi3ofare.dll Object path: C:\Users\USER\AppData\Local\Temp MD5 of an object: 3ADE4292B262029396E64A4AC7A01B9E Reason: Cloud Protection

来源·reddit.com