Skip to main content

VirusTotal results: DeckBridge 0.17.0

Results checked September 29, 2026. VirusTotal scores may change.

Detection details​

DownloadDetectionsVendors and labels
Windows portable ZIP1/51Bkav Pro: W32.Malware.A8967BE6
Windows installer3/68Arctic Wolf: Unsafe; Bkav Pro: W32.Malware.A8967BE6; SecureAge: Malicious
macOS Intel DMG1/58Microsoft: Trojan:Script/Wacatac.C!ml

Windows ZIP scan recorded thirteen timeouts.

Bundled components​

ComponentDetectionsFinding
Windows Tauri launcher3/71MaxSecure, Microsoft, Trapmine
Tauri NSIS utility DLL2/71Cynet, MaxSecure
Windows relay2/71Bkav Pro, Elastic
Windows tray1/71SecureAge
Windows native DLL0/67Extracted during relay startup
Windows HIDAPI DLL0/70Extracted during relay startup
macOS relay, launcher, tray0/63 eachBundled inside flagged DMG
macOS native and HIDAPI dylibs0/57, 0/63Extracted during relay startup

Tauri builds NSIS installers. Its utility DLL received two detections. Windows launcher received three detections. Windows portable ZIP omits Tauri packaging. Its relay still received detections. NSIS alone cannot explain every alert.

Txiki compiles DeckBridge's relay. QuickJS runs inside Txiki. No separate QuickJS binary ships. Compiled bytecode and compressed libraries ship embedded. Relay extracts libraries into cache. Those extracted libraries scanned clean. Such packaging could trigger heuristics. Current scans cannot isolate causes.

VirusTotal also displays d9jf6.exe. That alias refers to installer. Matching SHA-256 confirms file identity.

Assessment​

Few scanners agree on detections. Labels alone cannot establish malware. These detections are likely false positives. Reviewed source explains observed update checks. Reviewed source explains mDNS advertisement. No clear malicious behavior appeared. This assessment cannot prove safety.

Installer sandbox showed no network traffic. ZIP sandbox contacted GitHub releases. DeckBridge checks updates through GitHub. macOS sandbox also showed startup activity. Some macOS traffic remained unattributed. DeckBridge advertises mDNS services.

Release workflow requires ClamAV scanning. Published artifacts passed that check. Windows installer remains unsigned. Its NSIS packaging can trigger heuristics.

Verify your download​

Download files from official 0.17.0 release. Compare SHA-256 against release checksums.

0222989a41d85d10a39c31dbfa9d5d03c7bbfff254b015d8a5f5af407ed3b493 deckbridge-v0.17.0-windows-x86_64.zip
222cdc96420cd29802f2d38699f8fe97d5e91015ca2ef33dd52d2b7b63ab3c2e DeckBridge_0.17.0_x64-setup.exe
be7bae75feb6681027644545f32d835988ba8c5f1209a5ed429f1a64bb782855 DeckBridge_0.17.0_x64.dmg

Matching hashes confirm identical bytes. They cannot prove malware absence. Keep antivirus protection enabled. Report unexpected warnings through GitHub issues. Include filename, hash, vendor, and label.