Codex Desktop triggers repeated Bitdefender PowerShell detections
What version of the Codex App are you using (From “About Codex” dialog)?
26.616.32156 (Released June 19, 2026)
What subscription do you have?
Plus
What platform is your computer?
Windows 11
What issue are you seeing?
Hello,
I'm experiencing an issue with the latest Codex Desktop release on Windows 11.
Version: 26.616.32156 (Released June 19, 2026)
OS: Windows 11
Antivirus: Bitdefender Total Security
Every time I start Codex Desktop, Bitdefender begins showing repeated notifications (approximately once per minute) reporting:
"Malicious command line detected"
The detection refers to a PowerShell process launched with an encoded command:
C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
-NoProfile -NonInteractive -ExecutionPolicy Bypass -EncodedCommand ...
The interesting part is that:
If Codex Desktop is closed, the notifications stop immediately.
If Codex Desktop is opened again, the notifications resume.
The encoded script appears to contain references such as:
CodexShellIconNative
CODEX_NATIVE_DESKTOP_APP_ICON_PATH
The script seems related to extracting Windows application icons rather than performing malicious actions.
This looks like either:
A false positive triggered by Bitdefender, or
A background task in Codex that repeatedly retries an operation which Bitdefender blocks.
Could you please confirm whether this behavior is expected and whether there is a known compatibility issue with Bitdefender?
I can provide screenshots, logs, and the full Bitdefender detection details if needed.
Thank you.
Best regards,
Gianluca
What steps can reproduce the bug?
Feedback ID: 019edfec-1b0c-7983-b2ae-10e1b3d8dfaf
What is the expected behavior?
_No response_
Additional information
_No response_
This issue has 1 comment on GitHub. Read the full discussion on GitHub ↗