Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Pennywise malware detected. #194

Open
Ghasak opened this issue Jul 25, 2022 · 3 comments
Open

Pennywise malware detected. #194

Ghasak opened this issue Jul 25, 2022 · 3 comments

Comments

@Ghasak
Copy link

Ghasak commented Jul 25, 2022

What is the current behavior?
Maleware detected!, An infected file "Pennywise.app" was detected on your Mac.
A backdoor for this application, which is super dangerous.

Expected behavior

URL attempting to access

Screenshots (Optional But May Be Requested)
Screen Shot 2022-07-25 at 13 14 10

Pennywise Version:
following exactly the brew install
brew install --cask pennywise
==> Downloading https://github.com/kamranahmedse/pennywise/releases/download/v0.8.0/Pennywise-0.8.0.dmg
OS / OS Version:
macOS Monterey
version 12.4

@DevanFischer
Copy link

Same happened to me, what a shame! Was really looking forward to this Helium replacement. Please purge the Malware!!!

@ewolfe
Copy link

ewolfe commented Aug 2, 2022

The malicious SHA is a0c461c94ba9f1573c7253666d218b3343d24bfa5d8ef270ee9bc74b7856e492.

This SHA points to https://www.cisa.gov/uscert/ncas/analysis-reports/ar21-048d and something called Kupay Wallet.

@therealmarv
Copy link

therealmarv commented Sep 7, 2022

Here are the details of https://github.com/kamranahmedse/pennywise/releases/download/v0.8.0/Pennywise-0.8.0.dmg uploaded to www.virustotal.com (various Anti Virus engines used)

https://www.virustotal.com/gui/file/9e6195f1096d399aafd77da74e4461964364fdbeec3b667cd91ecf9704e73b69/detection

Because of the extremely low number of detections I'm pretty confident that this is a false positive. Another sign for false positive: There has been some crypto-stealing malware making the news recently which was also named pennywise (totally unrelated to this software).

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

4 participants