Bug report form
Describe the bug
ESET reported one detection for the Windows executable nu.exe installed through Scoop. The ESET event identifies the object as Suspicious Object; it does not provide a malware family name or claim that an exploit was observed.
This report is intended to ask whether the detection is a false positive and whether the published Windows binary, its code signing, or the Scoop package metadata should be reviewed. It does not assert that Nushell is malicious.
How to reproduce
- Install or use Nushell
0.115.1 through Scoop on Windows.
- Scan the installed
nu.exe with ESET.
- Observe the ESET event reporting the executable as
Suspicious Object.
The ESET product edition, version, detection-engine/database version, scan mode, and notification screenshot were not included in the source event, so the exact detection may not be reproducible without those details.
Expected behavior
A genuine Nushell release binary installed through Scoop should not be reported as suspicious by ESET. If this is a false positive, users should be able to install and run Nushell without the executable being blocked or quarantined.
Configuration
| key |
value |
| OS |
Windows 11 |
| installation method |
Scoop |
| Nushell version |
0.115.1 |
| executable size |
50.2 MB |
| security product |
ESET |
| ESET product/version |
Not provided in the source event |
| detection reason |
Suspicious Object |
| detection count |
1 |
| detection time |
2026-09-16 08:26:22 (timezone not provided) |
The output of version | transpose key value | to md --pretty was not included in the source event.
Additional context
The local username and machine name have been omitted from this public report. The alert identified the file as:
C:\Users\<username>\scoop\apps\nu\0.115.1\nu.exe
Hashes copied from the ESET event exactly as reported. The source did not specify the hash algorithms:
- Hash 1:
90E392149504EF8D38D827D88EFB7AE6B7AED26F7ECC189494B445154AE40507
- Hash 2:
E115C6C50F3BD74BB9BFFC27EDD6E3C9
Earlier issue searches found reports involving Microsoft Defender and older Nushell versions; this issue is specifically about the ESET detection for Scoop-installed Nushell 0.115.1.
Bug report form
Describe the bug
ESET reported one detection for the Windows executable
nu.exeinstalled through Scoop. The ESET event identifies the object asSuspicious Object; it does not provide a malware family name or claim that an exploit was observed.This report is intended to ask whether the detection is a false positive and whether the published Windows binary, its code signing, or the Scoop package metadata should be reviewed. It does not assert that Nushell is malicious.
How to reproduce
0.115.1through Scoop on Windows.nu.exewith ESET.Suspicious Object.The ESET product edition, version, detection-engine/database version, scan mode, and notification screenshot were not included in the source event, so the exact detection may not be reproducible without those details.
Expected behavior
A genuine Nushell release binary installed through Scoop should not be reported as suspicious by ESET. If this is a false positive, users should be able to install and run Nushell without the executable being blocked or quarantined.
Configuration
Suspicious ObjectThe output of
version | transpose key value | to md --prettywas not included in the source event.Additional context
The local username and machine name have been omitted from this public report. The alert identified the file as:
C:\Users\<username>\scoop\apps\nu\0.115.1\nu.exeHashes copied from the ESET event exactly as reported. The source did not specify the hash algorithms:
90E392149504EF8D38D827D88EFB7AE6B7AED26F7ECC189494B445154AE40507E115C6C50F3BD74BB9BFFC27EDD6E3C9Earlier issue searches found reports involving Microsoft Defender and older Nushell versions; this issue is specifically about the ESET detection for Scoop-installed Nushell
0.115.1.