Windows ChatGPT Codex triggers Norton 360 Behavioral Protection (IDP.HELU.PSE80%s_cmd) by simply opening an existing Codex thread

Open 💬 8 comments Opened Jul 11, 2026 by ccapadouca
💡 Likely answer: A maintainer (github-actions[bot], contributor) responded on this thread — see the highlighted reply below.

Windows ChatGPT Codex triggers Norton 360 Behavioral Protection (IDP.HELU.PSE80%s_cmd) by simply opening an existing Codex thread

Environment

Operating System

Windows 11

Application

ChatGPT Codex for Windows
Package: OpenAI.Codex
Version: 26.707.3563.0

Security Software

Norton 360
Summary

Since updating to the new ChatGPT Codex Windows application, Norton 360 repeatedly triggers Behavioral Protection detections.

The detection occurs simply by launching ChatGPT Codex and opening an existing Codex conversation.

No prompt needs to be executed.

No repository action is required.

Detection

Threat:

IDP.HELU.PSE80%s_cmd

Detection Type:

Behavioral Protection

Norton repeatedly reports:

powershell.exe terminated
conhost.exe terminated
temporary file deleted
restart required to quarantine "powershell.exe"

After reboot:

powershell.exe remains intact
no quarantine item exists
detection immediately returns when reopening the Codex conversation.
Reproduction
Start Windows.
Launch ChatGPT Codex.
Open an existing Codex conversation.
Norton immediately raises Behavioral Protection.

Additional triggers observed:

expanding an execution plan
replying /plan
interacting with existing Codex threads

Eventually simply opening the conversation became sufficient.

Investigation performed

Verified:

PowerShell executable still exists.
No PowerShell startup entries.
No suspicious scheduled tasks.
No unknown startup script located.
No pending Windows file rename operations.
Nothing placed into Norton Quarantine.

Observed runtime hierarchy:

explorer.exe
└── ChatGPT.exe
└── codex.exe
└── node_repl.exe

The runtime executable is located under:

%LOCALAPPDATA%\OpenAI\Codex\runtimes\
Expected

Opening a Codex conversation should not trigger security software.

Actual

Norton repeatedly terminates multiple PowerShell processes and reports Behavioral Protection.

Additional information

This appears similar to other recently reported Norton false positives involving the Windows Codex runtime.

View original on GitHub ↗

8 Comments

github-actions[bot] contributor · 9 days ago

Potential duplicates detected. Please review them and close your issue if it is a duplicate.

  • #31419

Powered by Codex Action

ccapadouca · 8 days ago

These may be similar in that AV tools like Windows Defender may be inferring a similar threat pattern, however it needs to be addressed and tested against each tool... Windows Defender, Norton etc

elenagorn21-web · 7 days ago

I can confirm the same issue on Windows 11 with Norton 360. It has made Codex effectively unusable for the second day, and today the detections are happening repeatedly: Codex sessions disconnect and local development servers (including localhost:3000) stop when Norton terminates the shell process.

Latest detection: July 13, 2026 at 12:19
Threat: IDP.HELU.PSE80%s_cmd
Detected by: Behavioral Protection
Status: Repaired
Risk shown by Norton: High

Observed process/file chain in one event:

  • powershell.exe — terminated
  • conhost.exe — terminated
  • csc.exe — terminated
  • cvtres.exe — terminated
  • %TEMP%\__PSScriptPolicyTest_*.ps1 — deleted
  • %TEMP%\0G3YB5K4.DLL — deleted

A second event terminated powershell.exe/conhost.exe and deleted two __PSScriptPolicyTest_*.ps1 files.

I also checked the Codex runtime involved on this machine:
%LOCALAPPDATA%\OpenAI\Codex\runtimes\cua_node\<version>\bin\node_repl.exe
Windows reports this executable as NotSigned.

This appears to be the same Codex -> node_repl -> PowerShell behavior described here, not repository-specific activity. The user has been unable to work reliably for two days. Please prioritize a hotfix, sign the shipped runtime executable, and/or change the PowerShell/.NET compilation pattern so it no longer triggers Norton Behavioral Protection. A documented safe workaround would also be greatly appreciated.

SirMheng · 7 days ago

Got the same issue.

____________________________

Details

Threat name: IDP.HELU.PSE80%s_cmd
Threat type: Miscellaneous - This is malicious software that could harm your data, computer, or network.
Status: Repaired
Detected by: Behavioral Protection
Last Detected: 13/07/2026, 8:19 pm
Startup Item: Yes

Many users
Thousands of users in the Norton Community have used this file.

Mature
This file was released 21 days ago.

High
The file risk is high.
____________________________

Activity

Path | Type | Status
C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process | Terminated
C:\Windows\System32\conhost.exe | Process | Terminated
C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process | Terminated
C:\Windows\System32\conhost.exe | Process | Terminated
C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process | Terminated
C:\Windows\System32\conhost.exe | Process | Terminated
C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process | Terminated
C:\Windows\System32\conhost.exe | Process | Terminated
C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process | Terminated
C:\Windows\System32\conhost.exe | Process | Terminated
C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process | Terminated
C:\Windows\System32\conhost.exe | Process | Terminated
C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process | Terminated
C:\Windows\System32\conhost.exe | Process | Terminated
C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process | Terminated
C:\Windows\System32\conhost.exe | Process | Terminated
0281462B5BFB4BEC609B9795CD49E965 | File | Deleted

BurKorHum · 7 days ago

I can reproduce this issue on a newer ChatGPT/Codex build.

Environment:

  • OS: Windows 11
  • App: ChatGPT — Powered by Codex & OWL
  • App version: 26.707.62119
  • Release date shown by app: 13 Jul 2026
  • Norton 360 Program/AV module: 26.6.11052 (build 26.6.11052.988)
  • Norton installer: 26.6.11114.0
  • Norton virus definitions: 260712-4
  • Norton UI: 1.0.145
  • LiveUpdate channel: Traditional

Reproduction:

  1. Launch ChatGPT/Codex for Windows.
  2. Open an existing Codex conversation1. Launch Chat.
  3. Norton Behavioral Protection immediately triggers IDP.HELU.PSE80%s_cmd.

Latest occurrence:

  • Norton “Last Used”: 13 Jul 2026, 18:35 TRT
  • Associated app timestamp: 2026-07-13T15:36:13.699Z
  • Reference: b27659497356

Norton terminates:

  • C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
  • C:\Windows\System32\conhost.exe

It also deletes a newly generated:

  • %LOCALAPPDATA%\Temp_PSScriptPolicyTest<random>.ps1

Verification performed:

  • All currently installed TiWorker.exe copies found in WinSxS have Valid Microsoft Windows Authenticode signatures.
  • Verified versions include 10.0.26100.1, 10.0.26100.7704, and 10.0.26100.8733.
  • The older 10.0.26100.8648 path retained in Norton's historical event no longer exists.
  • No Norton exclusions were created and no quarantined item was restored.

This is deterministic and has occurred repeatedly immediately after opening Codex. The practical impact is that Norton terminates PowerShell processes required for local Codex operations, potentially interrupting or partially completing tasks.

edgroc · 7 days ago

I can reproduce this independently with Norton 360 seemingly since this week with this new merged ui (Version 26.707.62119).

Windows 11 version 25H2
Norton 360 Program version (AV module): 26.6.11052 (build 26.6.11052.988)
Norton Virus Definitions version: 260712-4
Norton detection:

  • Threat: IDP.HELU.PSE80%s_cmd
  • Detected by: Behavioral Protection
  • Status: Repaired
  • Trigger: launching/opening an existing Codex thread; it happens consistently and repeatedly
  • Processes terminated repeatedly:
  • C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
  • C:\Windows\System32\conhost.exe
  • Norton also deleted a temporary item reported as:
  • 0281462B5BFB4BEC609B9795CD49E965
  • Norton describes the event as a startup item, although PowerShell itself remains present and functional.

PowerShell verification:

  • Windows PowerShell: 5.1.26100.8655
  • PowerShell 7 (pwsh): 7.6.3
  • My interactive/default shell is PowerShell 7, but the processes Norton terminates are Windows PowerShell 5.1.

This appears to match the report exactly. I have not added a Norton exclusion for PowerShell.

rjmatias · 7 days ago

____________________________

Details

Threat name: IDP.HELU.PSE80%s_cmd
Threat type: Miscellaneous - This is malicious software that could harm your data, computer, or network.
Status: Repaired
Detected by: Behavioral Protection
On PC from: 9/1/25, 10:55
Last Used: 7/13/26, 23:06
Startup Item: Yes

Many users
Millions of users in the Norton Community have used this file.

Mature
This file was released 10 months ago.

High
The file risk is high.
____________________________

Activity

Path | Type | Status
C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process | Terminated
C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process | Terminated
C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process | Terminated
C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process | Terminated
C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process | Terminated
0281462B5BFB4BEC609B9795CD49E965 | File | Deleted

edgroc · 5 days ago

The reproducible behavioral Protection detection/repair by Norton 360 has stopped occurring. I don't know what change/changes did it, or whether they will return.

I note that some Windows OS security updates were applied, ChatGPT was updated, as were Norton virus definitions.

On Windows 11 version 25H2 (and recent security updates applied since initial report: (KB5101650) (26200.8875) (KB5100998) (KB5104033) (KB5104032) (KB5104034) )

With ChatGPT Version 26.707.72221
And Norton 360 Program version (AV Module): 26.6.11052 (build 26.6.11052.988)
Virus definitions version: 260715-4