Hacktoberfest 2026: the issues maintainers tagged for October, open and beginner-friendly. Browse Hacktoberfest issues

Windows Defender flags Vite+ shim executables as Trojan:Win32/Wacatac.B!ml

Open
#2,866 0 comments 0 reactions 0 assignees View on GitHub

Maintainers usually reply within 1 day

Nobody has claimed this yet.

Assessment

Difficulty
4/5
Estimated time
3-5 days
Newbie friendliness
48/100
Issue type
Bug
Clarity
Mostly clear
Activity status
Active
Tech stack
rust
Domain
tooling

Research direction

Start by locating the Windows vp-shim.exe generation and packaging entry points, then reproduce installation or update followed by node -v with Microsoft Defender enabled. Check the generated and extracted shim files named in the report and verify that Defender no longer flags them and that the managed node, npm, and vp commands run successfully.

Written by the indexing model from the issue text.

Description

pending triage
Describe the bug

On Windows, Microsoft Defender is detecting Vite+'s shim executable as:

Trojan:Win32/Wacatac.B!ml

This causes executables managed/generated by Vite+ such as vp.exe, node.exe, and npm.exe to be blocked by Windows.

For example, running:

node -v

fails with:

ResourceUnavailable: Program 'node.exe' failed to run: An error occurred trying to start process
'C:\Users\MyUser\AppData\Local\vite-plus\bin\node.exe'
with working directory 'C:\Users\MyUser'.

Operation did not complete successfully because the file contains a virus or potentially unwanted software.

The Defender detection history shows that the original vp-shim.exe extracted during Vite+ installation/update is detected as well as copies of that shim:

ThreatID:   2147735505
ThreatName: Trojan:Win32/Wacatac.B!ml
SeverityID: 5
CategoryID: 8

Affected files observed so far include:

C:\Users\MyUser\AppData\Local\vite-plus\bin\vp.exe
C:\Users\MyUser\AppData\Local\vite-plus\bin\npm.exe
C:\Users\MyUser\AppData\Local\vite-plus\bin\node.exe

C:\Users\MyUser\AppData\Local\Temp\vite-platform-1692847142\package\vp-shim.exe
C:\Users\MyUser\AppData\Local\Temp\vite-platform-955851349\package\vp-shim.exe

The SHA-256 hash of my generated Vite+ node.exe shim is:

9FAA32624BDB13526FE4FFFB41BE524CDC4A4659A151BD5D3850739795030DEC

Because Defender also detects the extracted vp-shim.exe itself, this appears to be a false-positive detection of the Vite+ Windows shim rather than a detection of a Node.js runtime downloaded through Vite+.

Expected behavior:

Vite+ installed/managed executables should be usable on a standard Windows system with Microsoft Defender enabled.

Actual behavior:

Microsoft Defender detects the Vite+ shim as Trojan:Win32/Wacatac.B!ml, quarantines or blocks it, and consequently prevents commands such as node, npm, and potentially vp itself from running.

I am reporting this because other Windows users may suddenly lose access to their Vite+ managed toolchain when Microsoft Defender definitions classify the shim this way.

This issue report was prepared with the assistance of ChatGPT. The detection information, file paths, hashes, and command output were obtained from the affected machine; AI was used to help investigate the issue and structure this report according to the Vite+ issue template.

Reproduction

N/A

Steps to reproduce

Command-line reproduction on a Windows machine with Microsoft Defender enabled.

No project repository is required because the detection affects the Vite+ installation/toolchain shim itself.

If the issue template requires a URL, I can provide a minimal repository, but the reproduction does not depend on project contents.

Steps to reproduce

  1. Install or update Vite+ on Windows.
  2. Configure/use Node through Vite+ so that Vite+ provides its node.exe shim under:
%LOCALAPPDATA%\vite-plus\bin
  1. Ensure Microsoft Defender real-time protection and current malware definitions are enabled.
  2. Run:
node -v
  1. Windows may prevent execution with an error similar to:
Operation did not complete successfully because the file contains a virus or potentially unwanted software.
  1. Inspect Defender detections:
Get-MpThreatDetection |
    Sort-Object InitialDetectionTime -Descending |
    Select-Object -First 10 ThreatID, ThreatStatusID, InitialDetectionTime, Resources
  1. Inspect the threat name:
Get-MpThreat |
    Select-Object ThreatID, ThreatName, SeverityID, CategoryID

On the affected system this reports:

ThreatID    ThreatName                   SeverityID CategoryID
--------    ----------                   ---------- ----------
2147735505  Trojan:Win32/Wacatac.B!ml    5          8
  1. Hash the generated Node shim:
Get-FileHash "$env:LOCALAPPDATA\vite-plus\bin\node.exe" -Algorithm SHA256

Result on the affected system:

SHA256
9FAA32624BDB13526FE4FFFB41BE524CDC4A4659A151BD5D3850739795030DEC

Defender additionally reported detections on temporary Vite+ package files named:

...\vite-platform-...\package\vp-shim.exe

which suggests the detection originates from the Vite+ shim itself rather than from the installed Node runtime.

System Info
Node.js:
  Version    24.21.0
  Source     lts
  Bin Path   C:\Users\MyUser\AppData\Local\vite-plus\data\js_runtime\node\24.21.0\node.exe
  Installed  true
  Mode       managed

vp v1.0.0

Local vite-plus:
  vite-plus  Not found

Tools:
  vite             Not found
  rolldown         Not found
  vitest           Not found
  oxfmt            Not found
  oxlint           Not found
  oxlint-tsgolint  Not found
  tsdown           Not found

Environment:
  Package manager  Not found
  Node.js          v24.21.0
Used Package Manager

npm

Logs

Validations
Dominant language
Rust
Stars
5.8k
Forks
267
Avg merge
20h 7m
Merged PRs (30d)
139

Getting set up

Open in Codespaces

Starts the project's dev container in your browser, under your own GitHub account.

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from voidzero-dev/vite-plus

All issues in voidzero-dev/vite-plus

Similar issues

More Rust issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.