Windows Defender severe detection on bundled Codex Browser Use plugin

Resolved 💬 1 comment Opened Apr 30, 2026 by gotpcproblems Closed Apr 30, 2026

Product: OpenAI Codex Desktop for Windows
Date/time: 2026-04-29 around 9:25 PM America/Phoenix
Windows Defender detection: Trojan:JS/DrillApp.A!MTB
Alert level: Severe
Status: Active initially; Defender remediation later reported ActionSuccess=True

Affected file:
C:\Users\Brian\.codex\tmp\bundled-marketplaces\openai-bundled\plugins\browser-use\scripts\browser-client.mjs

Additional remediated copies reported by Defender:
C:\Users\Brian\.codex\plugins\cache\openai-bundled\browser-use\0.1.0-alpha1\scripts\browser-client.mjs
C:\Users\Brian\.codex\tmp\arg0\codex-arg0vLLBtz\plugins\openai-bundled\plugins\browser-use\scripts\browser-client.mjs

Defender details:
ThreatID: 2147964955
Detection times:

  • 2026-04-29 21:25:44
  • 2026-04-29 21:26:01

ActionSuccess: True
CleaningActionID: 2
ThreatStatusID: 3
ProcessName shown by Defender: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe

Context:
The file appears to be part of the bundled OpenAI Browser Use plugin used by Codex Desktop for browser automation. The user and assistant stopped using the plugin after the alert. Please confirm whether this is a known false positive, a compromised bundle/cache, or something requiring remediation.

Requested action:
Please advise whether to delete the Codex plugin cache, reinstall Codex Desktop, collect logs, or submit the file/hash through a specific OpenAI security channel.

View original on GitHub ↗

This issue has 1 comment on GitHub. Read the full discussion on GitHub ↗