Kaspersky flags claude-mem plugin reading credentials via PowerShell every 30s

nintavur_wings · reddit · 2026-09-13

A Reddit user warns anyone using claude-mem (a Claude Code memory plugin): Kaspersky popped a high-severity Trojan alert (VHO:Trojan.MSIL.Rozena.gen, heuristic) tied to a DLL compiled on the fly by PowerShell.

Investigation revealed claude-mem runs dynamic Cvia PowerShell to invoke the native Win32 CredRead API and polls Claude Code's login token every 30 seconds. Even if it's a heuristic false positive with no malicious intent, the author argues that dynamically shimming credentials in a tight loop is bad practice and uninstalled it immediately. The post includes the AV log, Claude Code's own review, and a second assessment by Gemini.

Original post →

More from coding & agent

coding & agent channel →