Looks like a false positive, there isn't enough confidence here to make any conclusions. Less involved scans may pick up runtimes for various scripting languages as being generic "malware"