Skip to content

Windows Defender flags Vite+ shim executables as Trojan:Win32/Wacatac.B!ml #2866

Description

@johanndev

Describe the bug

On Windows, Microsoft Defender is detecting Vite+'s shim executable as:

Trojan:Win32/Wacatac.B!ml

This causes executables managed/generated by Vite+ such as vp.exe, node.exe, and npm.exe to be blocked by Windows.

For example, running:

node -v

fails with:

ResourceUnavailable: Program 'node.exe' failed to run: An error occurred trying to start process
'C:\Users\MyUser\AppData\Local\vite-plus\bin\node.exe'
with working directory 'C:\Users\MyUser'.

Operation did not complete successfully because the file contains a virus or potentially unwanted software.

The Defender detection history shows that the original vp-shim.exe extracted during Vite+ installation/update is detected as well as copies of that shim:

ThreatID:   2147735505
ThreatName: Trojan:Win32/Wacatac.B!ml
SeverityID: 5
CategoryID: 8

Affected files observed so far include:

C:\Users\MyUser\AppData\Local\vite-plus\bin\vp.exe
C:\Users\MyUser\AppData\Local\vite-plus\bin\npm.exe
C:\Users\MyUser\AppData\Local\vite-plus\bin\node.exe

C:\Users\MyUser\AppData\Local\Temp\vite-platform-1692847142\package\vp-shim.exe
C:\Users\MyUser\AppData\Local\Temp\vite-platform-955851349\package\vp-shim.exe

The SHA-256 hash of my generated Vite+ node.exe shim is:

9FAA32624BDB13526FE4FFFB41BE524CDC4A4659A151BD5D3850739795030DEC

Because Defender also detects the extracted vp-shim.exe itself, this appears to be a false-positive detection of the Vite+ Windows shim rather than a detection of a Node.js runtime downloaded through Vite+.

Expected behavior:

Vite+ installed/managed executables should be usable on a standard Windows system with Microsoft Defender enabled.

Actual behavior:

Microsoft Defender detects the Vite+ shim as Trojan:Win32/Wacatac.B!ml, quarantines or blocks it, and consequently prevents commands such as node, npm, and potentially vp itself from running.

I am reporting this because other Windows users may suddenly lose access to their Vite+ managed toolchain when Microsoft Defender definitions classify the shim this way.

This issue report was prepared with the assistance of ChatGPT. The detection information, file paths, hashes, and command output were obtained from the affected machine; AI was used to help investigate the issue and structure this report according to the Vite+ issue template.

Reproduction

N/A

Steps to reproduce

Command-line reproduction on a Windows machine with Microsoft Defender enabled.

No project repository is required because the detection affects the Vite+ installation/toolchain shim itself.

If the issue template requires a URL, I can provide a minimal repository, but the reproduction does not depend on project contents.

Steps to reproduce

  1. Install or update Vite+ on Windows.
  2. Configure/use Node through Vite+ so that Vite+ provides its node.exe shim under:
%LOCALAPPDATA%\vite-plus\bin
  1. Ensure Microsoft Defender real-time protection and current malware definitions are enabled.
  2. Run:
node -v
  1. Windows may prevent execution with an error similar to:
Operation did not complete successfully because the file contains a virus or potentially unwanted software.
  1. Inspect Defender detections:
Get-MpThreatDetection |
    Sort-Object InitialDetectionTime -Descending |
    Select-Object -First 10 ThreatID, ThreatStatusID, InitialDetectionTime, Resources
  1. Inspect the threat name:
Get-MpThreat |
    Select-Object ThreatID, ThreatName, SeverityID, CategoryID

On the affected system this reports:

ThreatID    ThreatName                   SeverityID CategoryID
--------    ----------                   ---------- ----------
2147735505  Trojan:Win32/Wacatac.B!ml    5          8
  1. Hash the generated Node shim:
Get-FileHash "$env:LOCALAPPDATA\vite-plus\bin\node.exe" -Algorithm SHA256

Result on the affected system:

SHA256
9FAA32624BDB13526FE4FFFB41BE524CDC4A4659A151BD5D3850739795030DEC

Defender additionally reported detections on temporary Vite+ package files named:

...\vite-platform-...\package\vp-shim.exe

which suggests the detection originates from the Vite+ shim itself rather than from the installed Node runtime.

System Info

Node.js:
  Version    24.21.0
  Source     lts
  Bin Path   C:\Users\MyUser\AppData\Local\vite-plus\data\js_runtime\node\24.21.0\node.exe
  Installed  true
  Mode       managed

vp v1.0.0

Local vite-plus:
  vite-plus  Not found

Tools:
  vite             Not found
  rolldown         Not found
  vitest           Not found
  oxfmt            Not found
  oxlint           Not found
  oxlint-tsgolint  Not found
  tsdown           Not found

Environment:
  Package manager  Not found
  Node.js          v24.21.0

Used Package Manager

npm

Logs

Validations

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Type

Fields

Priority

None yet

Effort

None yet

Target date

None yet

Start date

None yet

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions