Kaspersky flags claude-mem plugin reading credentials via PowerShell every 30s
nintavur_wings · reddit · 2026-09-13
A Reddit user warns anyone using claude-mem (a Claude Code memory plugin): Kaspersky popped a high-severity Trojan alert (VHO:Trojan.MSIL.Rozena.gen, heuristic) tied to a DLL compiled on the fly by PowerShell.
Investigation revealed claude-mem runs dynamic Cvia PowerShell to invoke the native Win32 CredRead API and polls Claude Code's login token every 30 seconds. Even if it's a heuristic false positive with no malicious intent, the author argues that dynamically shimming credentials in a tight loop is bad practice and uninstalled it immediately. The post includes the AV log, Claude Code's own review, and a second assessment by Gemini.
More from coding & agent
- MiniMax Design plugs into Blender via MCP to drive AI video from 3D references — Hailuo_AI · 2026-09-14
- A TypeScript-to-Rust migration revives the classic Rewrite It In Rust meme — DanielLockyer · 2026-09-14
- gemini-cli PR fixes nested .gitignore trailing-slash patterns wrongly anchored — dylanyunlon · 2026-09-14
- Building a 'race your own ghosts' game with Gemini's Astra agent — LexicalLegend · 2026-09-14
- ChainForge's evalstats brings statistical rigor to LLM eval visualization after six months of work — IanArawjo · 2026-09-14
- RiftPoint: a Rust-backed multiversal checkpointer for LangGraph agents — goldenphoenix713 · 2026-09-14