So just now I ran into a few issues with running my PNPM Vitest tasks. Out of nowhere it suddenly started flagging the unit test run of my Angular application. (Context: its a Node/Typescript project that runs various PNPM tasks for which it needs to install certain Node Modules)
It saw my vitest config.ts file as threat by advanced threat defense, it saw a few in appdata/roaming/npm/node_modules/pnpm as threat by advanced threat defense (pn, pn.exe, pnpm, pnpm.exe, pnpx, pnpx.exe, pnx, pnx.exe)
I updated the PNPM version yesterday and ran a few tasks with that already. I updated a few packages today (but we have it set up so that it can't run post install scrips whilly nilly and have a timeout in freshness of packages as well in that project folder). But nothing weird was added. For some issue I had to remove my node_modules folder and redownload packages, but I don't see anything weird in them either.
When running, it uses Angular CLI, it runs Vitest, which spawns the Vitest UI (so it opens the browser) and since Vitest 5.0 it has authentication, so it opens the localhost URL with a token in the header. And its HTTP not HTTPS, which is what might've triggered the false positive.
An example URL was: UI started at http://localhost:51204/__vitest__/?token=xxxx
The Threat timeline from ATD security layer mentions: Detection ID: SuspiciousBehavior.3221F9637C384935
Right now I've disabled protection on the PNPM files, but I'd rather not do that, since there might still be future malware involved. Also the vitest config file is blocked (but I can't seem to restore it from quarantine).