When running the Anti-Virus for VMware Tanzu Tile, a false positive signature (Html.Phishing.SVGDynamicFunction-10060409-0) released in the ClamAV database may cause legitimate Java and JavaScript files to be incorrectly removed. This file loss can result in application outages.
When the signature is triggered, logs similar to the following will appear in /var/vcap/sys/log/antivirus/clamdscan.log:
/run/containerd/state/io.containerd.runtime.v2.task/k8s.io/<TASK_ID>/rootfs/usr/share/java/confluent-control-center/control-center-frontend-next-gen-2.3.0.jar: Html.Phishing.SVGDynamicFunction-10060409-0 FOUND
/run/containerd/state/io.containerd.runtime.v2.task/k8s.io/<TASK_ID>/rootfs/usr/share/java/confluent-control-center/control-center-frontend-next-gen-2.3.0.jar: Removed.
/var/vcap/store/containerd/io.containerd.snapshotter.v1.overlayfs/snapshots/<SNAPSHOT_ID>/fs/usr/share/java/confluent-control-center/control-center-frontend-next-gen-2.3.0.jar: Html.Phishing.SVGDynamicFunction-10060409-0 FOUND
/var/vcap/store/containerd/io.containerd.snapshotter.v1.overlayfs/snapshots/<SNAPSHOT_ID>/fs/usr/share/java/confluent-control-center/control-center-frontend-next-gen-2.3.0.jar: Removed.
To search for these logs on the VMs:
Anti-Virus Scanning
VMware Tanzu Kubernetes Grid Integrated Edition (TKGI)
Elastic Application Runtime(TAS)
On August 6, 2026, ClamAV released daily definition update version 28084, which added the new detection signature Html.Phishing.SVGDynamicFunction-10060409-0 (Release Notice 28084).
Scheduled scans in Anti-Virus Scanning running version 28084 detected impacted binary files and packages, moving or deleting them depending on the Antivirus tile configuration. However, this detection was a false positive.
Just one day later, on August 7, ClamAV officially removed this signature in database version 28085 (Release Notice 28085).
Updating the database file to version 28085 or higher resolves the issue. Since this signature has been removed from the official ClamAV detection list, scanners will no longer flag these files.
If the network is online, the Anti-Virus Mirror automatically checks for and downloads latest virus database updates every two hours.
For air-gapped (offline) networks, the definition files can be updated manually per the Broadcom Documentation, after which the mirror distributes them to the scanners.
However, if any VMs were impacted by prior detections and had files moved or deleted, you will need to recreate the affected VMs or redeploy the application to restore the missing binaries to their correct directories.
If your environment has been impacted by this issue, please open a Tanzu Support ticket.