Describe the bug
On Windows, Microsoft Defender is detecting Vite+'s shim executable as:
Trojan:Win32/Wacatac.B!ml
This causes executables managed/generated by Vite+ such as vp.exe, node.exe, and npm.exe to be blocked by Windows.
For example, running:
fails with:
ResourceUnavailable: Program 'node.exe' failed to run: An error occurred trying to start process
'C:\Users\MyUser\AppData\Local\vite-plus\bin\node.exe'
with working directory 'C:\Users\MyUser'.
Operation did not complete successfully because the file contains a virus or potentially unwanted software.
The Defender detection history shows that the original vp-shim.exe extracted during Vite+ installation/update is detected as well as copies of that shim:
ThreatID: 2147735505
ThreatName: Trojan:Win32/Wacatac.B!ml
SeverityID: 5
CategoryID: 8
Affected files observed so far include:
C:\Users\MyUser\AppData\Local\vite-plus\bin\vp.exe
C:\Users\MyUser\AppData\Local\vite-plus\bin\npm.exe
C:\Users\MyUser\AppData\Local\vite-plus\bin\node.exe
C:\Users\MyUser\AppData\Local\Temp\vite-platform-1692847142\package\vp-shim.exe
C:\Users\MyUser\AppData\Local\Temp\vite-platform-955851349\package\vp-shim.exe
The SHA-256 hash of my generated Vite+ node.exe shim is:
9FAA32624BDB13526FE4FFFB41BE524CDC4A4659A151BD5D3850739795030DEC
Because Defender also detects the extracted vp-shim.exe itself, this appears to be a false-positive detection of the Vite+ Windows shim rather than a detection of a Node.js runtime downloaded through Vite+.
Expected behavior:
Vite+ installed/managed executables should be usable on a standard Windows system with Microsoft Defender enabled.
Actual behavior:
Microsoft Defender detects the Vite+ shim as Trojan:Win32/Wacatac.B!ml, quarantines or blocks it, and consequently prevents commands such as node, npm, and potentially vp itself from running.
I am reporting this because other Windows users may suddenly lose access to their Vite+ managed toolchain when Microsoft Defender definitions classify the shim this way.
This issue report was prepared with the assistance of ChatGPT. The detection information, file paths, hashes, and command output were obtained from the affected machine; AI was used to help investigate the issue and structure this report according to the Vite+ issue template.
Reproduction
N/A
Steps to reproduce
Command-line reproduction on a Windows machine with Microsoft Defender enabled.
No project repository is required because the detection affects the Vite+ installation/toolchain shim itself.
If the issue template requires a URL, I can provide a minimal repository, but the reproduction does not depend on project contents.
Steps to reproduce
- Install or update Vite+ on Windows.
- Configure/use Node through Vite+ so that Vite+ provides its
node.exe shim under:
%LOCALAPPDATA%\vite-plus\bin
- Ensure Microsoft Defender real-time protection and current malware definitions are enabled.
- Run:
- Windows may prevent execution with an error similar to:
Operation did not complete successfully because the file contains a virus or potentially unwanted software.
- Inspect Defender detections:
Get-MpThreatDetection |
Sort-Object InitialDetectionTime -Descending |
Select-Object -First 10 ThreatID, ThreatStatusID, InitialDetectionTime, Resources
- Inspect the threat name:
Get-MpThreat |
Select-Object ThreatID, ThreatName, SeverityID, CategoryID
On the affected system this reports:
ThreatID ThreatName SeverityID CategoryID
-------- ---------- ---------- ----------
2147735505 Trojan:Win32/Wacatac.B!ml 5 8
- Hash the generated Node shim:
Get-FileHash "$env:LOCALAPPDATA\vite-plus\bin\node.exe" -Algorithm SHA256
Result on the affected system:
SHA256
9FAA32624BDB13526FE4FFFB41BE524CDC4A4659A151BD5D3850739795030DEC
Defender additionally reported detections on temporary Vite+ package files named:
...\vite-platform-...\package\vp-shim.exe
which suggests the detection originates from the Vite+ shim itself rather than from the installed Node runtime.
System Info
Node.js:
Version 24.21.0
Source lts
Bin Path C:\Users\MyUser\AppData\Local\vite-plus\data\js_runtime\node\24.21.0\node.exe
Installed true
Mode managed
vp v1.0.0
Local vite-plus:
vite-plus Not found
Tools:
vite Not found
rolldown Not found
vitest Not found
oxfmt Not found
oxlint Not found
oxlint-tsgolint Not found
tsdown Not found
Environment:
Package manager Not found
Node.js v24.21.0
Used Package Manager
npm
Logs
Validations
Describe the bug
On Windows, Microsoft Defender is detecting Vite+'s shim executable as:
Trojan:Win32/Wacatac.B!mlThis causes executables managed/generated by Vite+ such as
vp.exe,node.exe, andnpm.exeto be blocked by Windows.For example, running:
node -vfails with:
The Defender detection history shows that the original
vp-shim.exeextracted during Vite+ installation/update is detected as well as copies of that shim:Affected files observed so far include:
The SHA-256 hash of my generated Vite+
node.exeshim is:Because Defender also detects the extracted
vp-shim.exeitself, this appears to be a false-positive detection of the Vite+ Windows shim rather than a detection of a Node.js runtime downloaded through Vite+.Expected behavior:
Vite+ installed/managed executables should be usable on a standard Windows system with Microsoft Defender enabled.
Actual behavior:
Microsoft Defender detects the Vite+ shim as
Trojan:Win32/Wacatac.B!ml, quarantines or blocks it, and consequently prevents commands such asnode,npm, and potentiallyvpitself from running.I am reporting this because other Windows users may suddenly lose access to their Vite+ managed toolchain when Microsoft Defender definitions classify the shim this way.
This issue report was prepared with the assistance of ChatGPT. The detection information, file paths, hashes, and command output were obtained from the affected machine; AI was used to help investigate the issue and structure this report according to the Vite+ issue template.
Reproduction
N/A
Steps to reproduce
Command-line reproduction on a Windows machine with Microsoft Defender enabled.
No project repository is required because the detection affects the Vite+ installation/toolchain shim itself.
If the issue template requires a URL, I can provide a minimal repository, but the reproduction does not depend on project contents.
Steps to reproduce
node.exeshim under:node -vOn the affected system this reports:
Result on the affected system:
Defender additionally reported detections on temporary Vite+ package files named:
which suggests the detection originates from the Vite+ shim itself rather than from the installed Node runtime.
System Info
Used Package Manager
npm
Logs
Validations