Skip to content

[Windows/ESET] Scoop-installed nu.exe 0.115.1 reported as “Suspicious Object” #19032

Description

@pedoc

Bug report form

  • I have done a basic search of the issue tracker to find any existing issues that are similar.
  • I have checked that my version is at least the latest stable release available via my installation method.

Describe the bug

ESET reported one detection for the Windows executable nu.exe installed through Scoop. The ESET event identifies the object as Suspicious Object; it does not provide a malware family name or claim that an exploit was observed.

This report is intended to ask whether the detection is a false positive and whether the published Windows binary, its code signing, or the Scoop package metadata should be reviewed. It does not assert that Nushell is malicious.

How to reproduce

  1. Install or use Nushell 0.115.1 through Scoop on Windows.
  2. Scan the installed nu.exe with ESET.
  3. Observe the ESET event reporting the executable as Suspicious Object.

The ESET product edition, version, detection-engine/database version, scan mode, and notification screenshot were not included in the source event, so the exact detection may not be reproducible without those details.

Expected behavior

A genuine Nushell release binary installed through Scoop should not be reported as suspicious by ESET. If this is a false positive, users should be able to install and run Nushell without the executable being blocked or quarantined.

Configuration

key value
OS Windows 11
installation method Scoop
Nushell version 0.115.1
executable size 50.2 MB
security product ESET
ESET product/version Not provided in the source event
detection reason Suspicious Object
detection count 1
detection time 2026-09-16 08:26:22 (timezone not provided)

The output of version | transpose key value | to md --pretty was not included in the source event.

Additional context

The local username and machine name have been omitted from this public report. The alert identified the file as:

C:\Users\<username>\scoop\apps\nu\0.115.1\nu.exe

Hashes copied from the ESET event exactly as reported. The source did not specify the hash algorithms:

  • Hash 1: 90E392149504EF8D38D827D88EFB7AE6B7AED26F7ECC189494B445154AE40507
  • Hash 2: E115C6C50F3BD74BB9BFFC27EDD6E3C9

Earlier issue searches found reports involving Microsoft Defender and older Nushell versions; this issue is specifically about the ESET detection for Scoop-installed Nushell 0.115.1.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions