|
From: Jonathan K. B. <jkb...@gm...> - 2025-08-07 21:48:40
|
On Thu, Aug 7, 2025 at 5:27 PM Kenneth Porter <sh...@se...> wrote: > > I tried downloading the lastest EasyRSA release from GitHub only to see > both Firefox and Windows Defender (Win10x x64) report it as malware > "trojan.pigyx". I downloaded it on Linux and uploaded it to VirusTotal > and many AV's think it's malware. What's going on? I have nothing specific to say about EasyRSA (it could have been compromised, I suppose), but 1. False positives happen occasionally. It happened to Tunnelblick years ago [1] and [2]. 2. Many AV vendors just copy others' results, so if one reports it's malware then it is likely that several others will, too. Jon Bullard Tunnelblick Developer [1] https://tunnelblick.net/cNoMalwareInTunnelblick.html [2] https://tunnelblick.net/cNews.html#2018-10-01 |