Skip to content

Microsoft Defender for Mac flagging latest version (python-2020.3.69010) inject_dll_x86.exe as malware #10677

@ftssa-sec

Description

@ftssa-sec

Hello, in our environment yesterday around 9pm EST we received a high volume of alerts flagging the inject_dll_x86.exe file in this extension on a number of our Macs, this may be related to the latest update which I see was on 3/19. Windows Defender ATP is flagging this as malware, looking at previous tickets for older versions, this has been a false positive.

affected file paths:

flagged as: Gen:Trojan.Heur.RP.nyY@a0lLHJi
/.vscode/extensions/ms-python.python-2020.3.69010/pythonFiles/lib/python/debugpy/no_wheels/debugpy/_vendored/pydevd/pydevd_attach_to_process/inject_dll_x86.exe/

flagged as: Gen:Trojan.Heur.RP.nyY@aKhVwOf
/vscode/extensions/ms-python.python-2020.3.69010/pythonFiles/lib/python/debugpy/wheels/debugpy/_vendored/pydevd/pydevd_attach_to_process/inject_dll_x86.exe/

Environment data

  • VS Code version: 1.43.0
  • Extension version (available under the Extensions sidebar): 2020.3.69010
  • OS and version: mac OS 10.14.6

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugIssue identified by VS Code Team member as probable bug

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions