Defender alerting on 4.1.0 ModuleOnly.zip

Has anyone else seen this? Defender is identifying the “PSAppDeployToolkit_ModuleOnly.zip” from the GitHub repo as a Trojan:Script/Wacatac.H!ml. Our security team is unable to identify the specific reason or file that Defender is yelling.

We have no issues with the either of the template .zip files, just the module. We are worried that or techs will also get dinged if they run Install-module.

Hi there! I’m most certain this would be a false positive. Can you try downloading again to see if you still receive it? If so, can you please provide full Defender logs for the detection?

EDIT: As a side-note, I ran the zip file through VirusTotal and received no alerts or detections.