As I understand it, this happens because the JS library used in the project contains text that talks about Ukraine and is probably not a real security threat.
It could be dangerous if your time zone is from (UTC +2) to (UTC +12).
Russian antiviruses as DR.web and Kasperski triggering on it.
The developer of Drafft is not to blame.
This is so stupid
----------------------------------------------------------------------------------
Original post
I want to share some observations about potential security risks related to recent Drafft installers. I am not an expert, but multiple antivirus alerts and suspicious behaviors have raised concerns. Below is a detailed breakdown for transparency. Please verify if others have experienced similar issues
1. Drafft v1.4.5 (Itch.io Installer)
- Antivirus Alert (Dr.Web):
- Blocked during installation due to "Process Hollowing" (attempted modification of system files).
- Installer freezes, creating unresponsive processes.
- Post-Scan Findings:
- Dr.Web flagged anomalies in
System32\backgroundTaskHost.exe
.
- Dr.Web flagged anomalies in
- VirusTotal Results:
- Installer v1.4.5 Hash:
b89ea9ddaa22f9fc7034762fca55573f28a8017ef761c909b301d4c742204497
- View Report
- Installer v1.4.5 Hash:
2. Windows Portable Version (Itch.io)
- Antivirus Alerts:
- Both Windows Defender and Dr.Web triggered warnings during extraction.
- VirusTotal Results:
- Portable ZIP Hash:
a7ca47afe5f367ff593a3ac5be0265bc79ebcec3d0c4a8f94a531de616aebe59
- Portable ZIP Hash:
3. Drafft v2.0.21 (Drafft.dev → GitHub)
- Installer:
Drafft-2-Installer-2.0.21-win-x64.exe
- Flagged for JS.Siggen5.44590 (malicious JavaScript library).
- VirusTotal Results:
- Installer v2.0.21 Hash:
c6127bf4963ab7c5802cf9abb5d4a24c483221476a8fe1f6f5109c14c4840e2d
- View Report
- Installer v2.0.21 Hash:
Request to the Community
- If you’ve installed recent Drafft versions, please:
- Run antivirus scans.
- Check for unusual system behavior.
- Share your findings here to clarify if this is a false positive or a genuine threat.
P.S. to developer, It seems to me that the site https://drafft.dev/ is not the right setting, since without paying for a subscription you can easily get access to the installer download program (I realized this only after a while, when I saw that there are price lists). And also on the main page there are buttons "Download" at the top and a button "Download for windows" in the middle of the screen, I do not work, I just do nothing, a working link to download is only after going to "All downloads →"