Potential malicious download / compromised resource via Kdenlive app

Hi team,

I’m reaching out to report a security issue regarding Kdenlive on Windows. On June 21st, 2026, while the app was running, my Windows Defender blocked a malicious drop triggered directly by kdenlive.exe (which I later confirmed via Windows Event Viewer).

  • Process: C:\Program Files\Kdenlive\bin\kdenlive.exe

  • Threat detected: Trojan:Win32/Woreflint.A

  • Dropped file: PROD_Start_DriverPack.hta

It looks like one of the third-party repositories, online add-ons, or resource feeds that Kdenlive pulls from has been compromised or contains a malicious link. As a temporary workaround to protect my system, I have completely blocked internet access (outbound rule) for Kdenlive in my Windows Firewall.

Please review the remote store/download feeds to prevent other users from getting infected.

Best regards.

Hello, please report by following these instructions if you are confident you’re using a genuine version of Kdenlive and if you have more (possibly sensitive) information to give.

I don’t have a Windows device with Kdenlive, nor do I know where you got the executable from, so I can’t really help much more.

For a quick sanity check, verify / remember if you downloaded it from a official source (e.g. Downloads - Kdenlive ) and try to see if you installed any add-on from the online store (probably from https://store.kde.org) as they are user-content and not explicitly vetted by the team and check them; if something feels suspicious, it’ll be more appropriate to report the add-ons directly.

Hi @Innova_3D_infografia, and welcome to the forum and community.

Thanks for bringing this to our attention! We are taking the security of Kdenlive and the systems it is running on very seriously.

Kdenlive does not perform any downloads, uploads, or phone-home activities in the background without explicit user authorization. It is completely autonomous and runs without being online (as you confirmed).

Kdenlive allows downloading of effects, project presets/profiles, render presets/profiles from KDE Store through the respective widget. It also has the ability to download resources from Pixabay, Pexels, Internet Archives (movies only), and Freesound via the Online Resources option. But this needs to be triggered by the user through an action.

Have you used these functions before Windows Defender alerted you to it?

Which version of Kdenlive are you using?

Did, at any point, a warning message come up about a .kdenlive project file trying to download something?

Did you receive (email, DM, link) or download a .kdenlive project file whose source you cannot verify or do not explicitly trust?

Thank you for reporting.

Please update to the latest Kdenlive version 26.04.2. It looks like DriverPack.hta attacked the Kdenlive project file and loaded some additional files.

Hi Eugen,

Thanks for the reply! Actually, I was already running the latest version 26.04.2 (installed it via the official Windows Installer a few days ago).

Your explanation makes perfect sense. I suspect the .kdenlive project file I was working on had been compromised or targeted previously while running an older version of Kdenlive on this machine. When I opened it in the new version, Windows Defender immediately caught the execution attempt and removed DriverPack.hta.

Thank you and the rest of the team for your amazing work and for looking into this!