Windows Defender severe detection on bundled Codex Browser Use plugin
Product: OpenAI Codex Desktop for Windows
Date/time: 2026-04-29 around 9:25 PM America/Phoenix
Windows Defender detection: Trojan:JS/DrillApp.A!MTB
Alert level: Severe
Status: Active initially; Defender remediation later reported ActionSuccess=True
Affected file:
C:\Users\Brian\.codex\tmp\bundled-marketplaces\openai-bundled\plugins\browser-use\scripts\browser-client.mjs
Additional remediated copies reported by Defender:
C:\Users\Brian\.codex\plugins\cache\openai-bundled\browser-use\0.1.0-alpha1\scripts\browser-client.mjs
C:\Users\Brian\.codex\tmp\arg0\codex-arg0vLLBtz\plugins\openai-bundled\plugins\browser-use\scripts\browser-client.mjs
Defender details:
ThreatID: 2147964955
Detection times:
- 2026-04-29 21:25:44
- 2026-04-29 21:26:01
ActionSuccess: True
CleaningActionID: 2
ThreatStatusID: 3
ProcessName shown by Defender: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
Context:
The file appears to be part of the bundled OpenAI Browser Use plugin used by Codex Desktop for browser automation. The user and assistant stopped using the plugin after the alert. Please confirm whether this is a known false positive, a compromised bundle/cache, or something requiring remediation.
Requested action:
Please advise whether to delete the Codex plugin cache, reinstall Codex Desktop, collect logs, or submit the file/hash through a specific OpenAI security channel.
This issue has 1 comment on GitHub. Read the full discussion on GitHub ↗