Extension sonar-rust-plugin reconized as malware Trojan.GenericKD.76426429

Some security tools are pointing the file bellow as Infected by Trojan.GenericKD.76426429

VirusTotal Analyze

/opt/sonarqube/lib/extensions/sonar-rust-plugin-1.0.2.734.jar

I assumed it as a false positive, as I saw in some other posts about other plugins with the same false positive. But I would like to share and see more opinions

Hi @jrmagots,

Thank you for reporting this. We are aware of this, and it is indeed a false-positive.
Nevertheless, we have released sonar-rust 1.0.3.786 that removes this problem.

It is available now on SonarQube Cloud, SonarQube Server 2025 release 3, and SonarQube Community Build 25.6

Denis

2 Likes

This topic was automatically closed 7 days after the last reply. New replies are no longer allowed.