google-gemini/gemini-cli

stuff is getting detected as stealers

Open

#15404 opened on Dec 21, 2025

View on GitHub
 (3 comments) (0 reactions) (1 assignee)TypeScript (103,992 stars) (13,657 forks)batch import
area/securityhelp wantedkind/bugpriority/p1priority/p2status/bot-triagedtype/bug

Description

What happened?

The file C:\Users\myusername\AppData\Local\Temp\gemini-client-error-Turn.run-sendMessageStream-2025-12-21T19-21-57-891Z.json is infected with Generic.PyStealer.AD.3D27F607 and was moved to quarantine.

C:\Users\myusername.gemini\tmp\9254d63da2c65066db8b3be0025f794448de789ae80341e24e7e0bb4a8556d3c\chats\session-2025-12-21T19-19-819dd6d9.json is infected with Generic.PyStealer.AD.C43124FA and was moved to quarantine.

What did you expect to happen?

i expect it to not get detected

Client information

CLI Version 0.21.3 │ │ Git Commit d0cdeda00 │ │ Model auto-gemini-3 │ │ Sandbox no sandbox │ │ OS win32 │ │ Auth Method OAuth │ │ User Email ********@gmail.com │ │ IDE Client VS Code

Login information

No response

Anything else we need to know?

No response

Contributor guide