Windows Defender flags Vite+ shim executables as Trojan:Win32/Wacatac.B!ml
Maintainers usually reply within 1 day
Nobody has claimed this yet.
Assessment
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Newbie friendliness
- 48/100
Research direction
Start by locating the Windows vp-shim.exe generation and packaging entry points, then reproduce installation or update followed by node -v with Microsoft Defender enabled. Check the generated and extracted shim files named in the report and verify that Defender no longer flags them and that the managed node, npm, and vp commands run successfully.
Written by the indexing model from the issue text.
Description
Describe the bug
On Windows, Microsoft Defender is detecting Vite+'s shim executable as:
Trojan:Win32/Wacatac.B!ml
This causes executables managed/generated by Vite+ such as vp.exe, node.exe, and npm.exe to be blocked by Windows.
For example, running:
node -v
fails with:
ResourceUnavailable: Program 'node.exe' failed to run: An error occurred trying to start process
'C:\Users\MyUser\AppData\Local\vite-plus\bin\node.exe'
with working directory 'C:\Users\MyUser'.
Operation did not complete successfully because the file contains a virus or potentially unwanted software.
The Defender detection history shows that the original vp-shim.exe extracted during Vite+ installation/update is detected as well as copies of that shim:
ThreatID: 2147735505
ThreatName: Trojan:Win32/Wacatac.B!ml
SeverityID: 5
CategoryID: 8
Affected files observed so far include:
C:\Users\MyUser\AppData\Local\vite-plus\bin\vp.exe
C:\Users\MyUser\AppData\Local\vite-plus\bin\npm.exe
C:\Users\MyUser\AppData\Local\vite-plus\bin\node.exe
C:\Users\MyUser\AppData\Local\Temp\vite-platform-1692847142\package\vp-shim.exe
C:\Users\MyUser\AppData\Local\Temp\vite-platform-955851349\package\vp-shim.exe
The SHA-256 hash of my generated Vite+ node.exe shim is:
9FAA32624BDB13526FE4FFFB41BE524CDC4A4659A151BD5D3850739795030DEC
Because Defender also detects the extracted vp-shim.exe itself, this appears to be a false-positive detection of the Vite+ Windows shim rather than a detection of a Node.js runtime downloaded through Vite+.
Expected behavior:
Vite+ installed/managed executables should be usable on a standard Windows system with Microsoft Defender enabled.
Actual behavior:
Microsoft Defender detects the Vite+ shim as Trojan:Win32/Wacatac.B!ml, quarantines or blocks it, and consequently prevents commands such as node, npm, and potentially vp itself from running.
I am reporting this because other Windows users may suddenly lose access to their Vite+ managed toolchain when Microsoft Defender definitions classify the shim this way.
This issue report was prepared with the assistance of ChatGPT. The detection information, file paths, hashes, and command output were obtained from the affected machine; AI was used to help investigate the issue and structure this report according to the Vite+ issue template.
Reproduction
N/A
Steps to reproduce
Command-line reproduction on a Windows machine with Microsoft Defender enabled.
No project repository is required because the detection affects the Vite+ installation/toolchain shim itself.
If the issue template requires a URL, I can provide a minimal repository, but the reproduction does not depend on project contents.
Steps to reproduce
- Install or update Vite+ on Windows.
- Configure/use Node through Vite+ so that Vite+ provides its
node.exeshim under:
%LOCALAPPDATA%\vite-plus\bin
- Ensure Microsoft Defender real-time protection and current malware definitions are enabled.
- Run:
node -v
- Windows may prevent execution with an error similar to:
Operation did not complete successfully because the file contains a virus or potentially unwanted software.
- Inspect Defender detections:
Get-MpThreatDetection |
Sort-Object InitialDetectionTime -Descending |
Select-Object -First 10 ThreatID, ThreatStatusID, InitialDetectionTime, Resources
- Inspect the threat name:
Get-MpThreat |
Select-Object ThreatID, ThreatName, SeverityID, CategoryID
On the affected system this reports:
ThreatID ThreatName SeverityID CategoryID
-------- ---------- ---------- ----------
2147735505 Trojan:Win32/Wacatac.B!ml 5 8
- Hash the generated Node shim:
Get-FileHash "$env:LOCALAPPDATA\vite-plus\bin\node.exe" -Algorithm SHA256
Result on the affected system:
SHA256
9FAA32624BDB13526FE4FFFB41BE524CDC4A4659A151BD5D3850739795030DEC
Defender additionally reported detections on temporary Vite+ package files named:
...\vite-platform-...\package\vp-shim.exe
which suggests the detection originates from the Vite+ shim itself rather than from the installed Node runtime.
System Info
Node.js:
Version 24.21.0
Source lts
Bin Path C:\Users\MyUser\AppData\Local\vite-plus\data\js_runtime\node\24.21.0\node.exe
Installed true
Mode managed
vp v1.0.0
Local vite-plus:
vite-plus Not found
Tools:
vite Not found
rolldown Not found
vitest Not found
oxfmt Not found
oxlint Not found
oxlint-tsgolint Not found
tsdown Not found
Environment:
Package manager Not found
Node.js v24.21.0
Used Package Manager
npm
Logs
Validations
- Read the Contributing Guidelines.
- Check that there isn't already an issue for the same bug.
- Confirm this is a Vite+ issue and not an upstream issue (Vite, Vitest, tsdown, Rolldown, or Oxc).
- The provided reproduction is a minimal reproducible example.
- Dominant language
- Rust
- Stars
- 5.8k
- Forks
- 267
- Avg merge
- 20h 7m
- Merged PRs (30d)
- 139
Getting set up
Starts the project's dev container in your browser, under your own GitHub account.
- No Dockerfile or Docker Compose file
- No pull request template
- Read the contributing guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from voidzero-dev/vite-plus
-
pending triage
Difficulty 2/5 1-3 hours Newbie friendliness 84/100
voidzero-dev/vite-plus#2854 ·
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 84/100
voidzero-dev/vite-plus#2849 ·
Maintainers usually reply within 1 day
-
pending triage
Difficulty 2/5 1-3 hours Newbie friendliness 75/100
voidzero-dev/vite-plus#2801 · 1 reaction ·
Maintainers usually reply within 1 day
-
enhancement
Difficulty 2/5 1-3 hours Newbie friendliness 62/100
voidzero-dev/vite-plus#2097 · 10 comments · 2 reactions ·
Maintainers usually reply within 1 day
-
Difficulty 4/5 3-5 days Newbie friendliness 48/100
voidzero-dev/vite-plus#2850 · 1 comment ·
Maintainers usually reply within 1 day
All issues in voidzero-dev/vite-plus
Similar issues
-
Change output crossing a compactsize boundary leaves the fee slightly below the requested feerateOpenbug
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
bitcoindevkit/bdk_wallet#578 ·
Maintainers usually reply within 8 days
-
Difficulty 2/5 1-3 hours Newbie friendliness 88/100
Maintainers usually reply within 2 days
-
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
521xueweihan/HelloGitHub#3832 ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 84/100
-
Difficulty 2/5 1-3 hours Newbie friendliness 82/100
canonical/opentelemetry-collector-operator#409 ·
Maintainers usually reply within 1 day