Windows ChatGPT Codex triggers Norton 360 Behavioral Protection (IDP.HELU.PSE80%s_cmd) by simply opening an existing Codex thread
Windows ChatGPT Codex triggers Norton 360 Behavioral Protection (IDP.HELU.PSE80%s_cmd) by simply opening an existing Codex thread
Environment
Operating System
Windows 11
Application
ChatGPT Codex for Windows
Package: OpenAI.Codex
Version: 26.707.3563.0
Security Software
Norton 360
Summary
Since updating to the new ChatGPT Codex Windows application, Norton 360 repeatedly triggers Behavioral Protection detections.
The detection occurs simply by launching ChatGPT Codex and opening an existing Codex conversation.
No prompt needs to be executed.
No repository action is required.
Detection
Threat:
IDP.HELU.PSE80%s_cmd
Detection Type:
Behavioral Protection
Norton repeatedly reports:
powershell.exe terminated
conhost.exe terminated
temporary file deleted
restart required to quarantine "powershell.exe"
After reboot:
powershell.exe remains intact
no quarantine item exists
detection immediately returns when reopening the Codex conversation.
Reproduction
Start Windows.
Launch ChatGPT Codex.
Open an existing Codex conversation.
Norton immediately raises Behavioral Protection.
Additional triggers observed:
expanding an execution plan
replying /plan
interacting with existing Codex threads
Eventually simply opening the conversation became sufficient.
Investigation performed
Verified:
PowerShell executable still exists.
No PowerShell startup entries.
No suspicious scheduled tasks.
No unknown startup script located.
No pending Windows file rename operations.
Nothing placed into Norton Quarantine.
Observed runtime hierarchy:
explorer.exe
└── ChatGPT.exe
└── codex.exe
└── node_repl.exe
The runtime executable is located under:
%LOCALAPPDATA%\OpenAI\Codex\runtimes\
Expected
Opening a Codex conversation should not trigger security software.
Actual
Norton repeatedly terminates multiple PowerShell processes and reports Behavioral Protection.
Additional information
This appears similar to other recently reported Norton false positives involving the Windows Codex runtime.
8 Comments
Potential duplicates detected. Please review them and close your issue if it is a duplicate.
Powered by Codex Action
These may be similar in that AV tools like Windows Defender may be inferring a similar threat pattern, however it needs to be addressed and tested against each tool... Windows Defender, Norton etc
I can confirm the same issue on Windows 11 with Norton 360. It has made Codex effectively unusable for the second day, and today the detections are happening repeatedly: Codex sessions disconnect and local development servers (including localhost:3000) stop when Norton terminates the shell process.
Latest detection: July 13, 2026 at 12:19
Threat: IDP.HELU.PSE80%s_cmd
Detected by: Behavioral Protection
Status: Repaired
Risk shown by Norton: High
Observed process/file chain in one event:
A second event terminated powershell.exe/conhost.exe and deleted two __PSScriptPolicyTest_*.ps1 files.
I also checked the Codex runtime involved on this machine:
%LOCALAPPDATA%\OpenAI\Codex\runtimes\cua_node\<version>\bin\node_repl.exe
Windows reports this executable as NotSigned.
This appears to be the same Codex -> node_repl -> PowerShell behavior described here, not repository-specific activity. The user has been unable to work reliably for two days. Please prioritize a hotfix, sign the shipped runtime executable, and/or change the PowerShell/.NET compilation pattern so it no longer triggers Norton Behavioral Protection. A documented safe workaround would also be greatly appreciated.
Got the same issue.
____________________________
Details
Threat name: IDP.HELU.PSE80%s_cmd
Threat type: Miscellaneous - This is malicious software that could harm your data, computer, or network.
Status: Repaired
Detected by: Behavioral Protection
Last Detected: 13/07/2026, 8:19 pm
Startup Item: Yes
Many users
Thousands of users in the Norton Community have used this file.
Mature
This file was released 21 days ago.
High
The file risk is high.
____________________________
Activity
Path | Type | Status
C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process | Terminated
C:\Windows\System32\conhost.exe | Process | Terminated
C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process | Terminated
C:\Windows\System32\conhost.exe | Process | Terminated
C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process | Terminated
C:\Windows\System32\conhost.exe | Process | Terminated
C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process | Terminated
C:\Windows\System32\conhost.exe | Process | Terminated
C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process | Terminated
C:\Windows\System32\conhost.exe | Process | Terminated
C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process | Terminated
C:\Windows\System32\conhost.exe | Process | Terminated
C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process | Terminated
C:\Windows\System32\conhost.exe | Process | Terminated
C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process | Terminated
C:\Windows\System32\conhost.exe | Process | Terminated
0281462B5BFB4BEC609B9795CD49E965 | File | Deleted
I can reproduce this issue on a newer ChatGPT/Codex build.
Environment:
Reproduction:
Latest occurrence:
Norton terminates:
It also deletes a newly generated:
Verification performed:
This is deterministic and has occurred repeatedly immediately after opening Codex. The practical impact is that Norton terminates PowerShell processes required for local Codex operations, potentially interrupting or partially completing tasks.
I can reproduce this independently with Norton 360 seemingly since this week with this new merged ui (Version 26.707.62119).
Windows 11 version 25H2
Norton 360 Program version (AV module): 26.6.11052 (build 26.6.11052.988)
Norton Virus Definitions version: 260712-4
Norton detection:
IDP.HELU.PSE80%s_cmdC:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\conhost.exe0281462B5BFB4BEC609B9795CD49E965PowerShell verification:
5.1.26100.8655pwsh):7.6.3This appears to match the report exactly. I have not added a Norton exclusion for PowerShell.
____________________________
Details
Threat name: IDP.HELU.PSE80%s_cmd
Threat type: Miscellaneous - This is malicious software that could harm your data, computer, or network.
Status: Repaired
Detected by: Behavioral Protection
On PC from: 9/1/25, 10:55
Last Used: 7/13/26, 23:06
Startup Item: Yes
Many users
Millions of users in the Norton Community have used this file.
Mature
This file was released 10 months ago.
High
The file risk is high.
____________________________
Activity
Path | Type | Status
C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process | Terminated
C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process | Terminated
C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process | Terminated
C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process | Terminated
C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process | Terminated
0281462B5BFB4BEC609B9795CD49E965 | File | Deleted
The reproducible behavioral Protection detection/repair by Norton 360 has stopped occurring. I don't know what change/changes did it, or whether they will return.
I note that some Windows OS security updates were applied, ChatGPT was updated, as were Norton virus definitions.
On Windows 11 version 25H2 (and recent security updates applied since initial report: (KB5101650) (26200.8875) (KB5100998) (KB5104033) (KB5104032) (KB5104034) )
With ChatGPT Version 26.707.72221
And Norton 360 Program version (AV Module): 26.6.11052 (build 26.6.11052.988)
Virus definitions version: 260715-4