[GH-ISSUE #585] clamscan reports released rpm may have coinminer (even 1.30) #442

Closed
opened 2026-05-07 00:24:14 +02:00 by BreizhHardware · 3 comments

Originally created by @aappddeevv on GitHub (Jan 17, 2023).
Original GitHub issue: https://github.com/binwiederhier/ntfy/issues/585

I'm running clamscan on ntfy binary distributed with the rpm bundle and its reporting

/usr/bin/ntfy: Unix.Packed.Coinminer-6856324-0 FOUND

Not quite sure the details. But I ran this on 1.30 as well.

Originally created by @aappddeevv on GitHub (Jan 17, 2023). Original GitHub issue: https://github.com/binwiederhier/ntfy/issues/585 I'm running clamscan on ntfy binary distributed with the rpm bundle and its reporting ```sh /usr/bin/ntfy: Unix.Packed.Coinminer-6856324-0 FOUND ``` Not quite sure the details. But I ran this on 1.30 as well.
Author
Owner

@binwiederhier commented on GitHub (Jan 17, 2023):

This is a dup of https://github.com/binwiederhier/ntfy/issues/576.
This has been addressed and will likely not happen again in the next release.

<!-- gh-comment-id:1385562764 --> @binwiederhier commented on GitHub (Jan 17, 2023): This is a dup of https://github.com/binwiederhier/ntfy/issues/576. This has been addressed and will likely not happen again in the next release.
Author
Owner

@aappddeevv commented on GitHub (Jan 17, 2023):

My apologies. This is such a rare occurrence it did not even dawn on me to search for it already :-)

<!-- gh-comment-id:1385586240 --> @aappddeevv commented on GitHub (Jan 17, 2023): My apologies. This is such a rare occurrence it did not even dawn on me to search for it already :-)
Author
Owner

@binwiederhier commented on GitHub (Jan 17, 2023):

It is quite annoying. upx is fantastic at making binaries a lot smaller. But somehow upx-compressed Go binaries have been getting flagged by virus scanners for years. 🤷

To be fair, for most people this does not matter, since the deliverable (deb, rpm, tarball, docker) will compress it.

<!-- gh-comment-id:1385632994 --> @binwiederhier commented on GitHub (Jan 17, 2023): It is quite annoying. `upx` is fantastic at making binaries _a lot_ smaller. But somehow upx-compressed Go binaries have been getting flagged by virus scanners for years. :shrug: To be fair, for most people this does not matter, since the deliverable (deb, rpm, tarball, docker) will compress it.
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
starred/ntfy#442
No description provided.