Developer finds unsigned Rust app installer flagged by antivirus while its extracted binary is not
A developer building Auricle, a Windows music player written in Rust and Slint, discovered that its Inno Setup installer received 3 out of 70 detections on VirusTotal as of September 15, 2026, while the application executable extracted from that same installer scored zero detections. The flagging vendors were Microsoft, SecureAge, and Skyhigh, and all scanned artifacts remained unsigned at the time of analysis. The developer extracted and verified the installer contents using innounp, confirming no custom code sections were present and that the installer hash matched the GitHub release metadata. A sandbox run noted an unsigned DLL loaded into an LSASS process, but that DLL was not bundled with the installer and its origin could not be confirmed. Review requests with hashes and scan evidence have been submitted to all three vendors, and code signing for the project is still pending.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in