VS Code Marketplace

Zip File Preview

by fovelas · 258 users
0003ae2c-2da2-526e-923b-3c99baa95e31 | v1.0.0
37/ 100
LOW risk
Analyst verdict
No high-risk signal observed

Based on the RiskyPlugins AI security review of the observed evidence.

Analysis record

Analysed
6 months ago
Version
v1.0.0
Artifact
SHA256 0E9…56C
Source
Findings (non-IoC)

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

11 detail rows

YARA Rule Matches

9 rules
SeverityRuleHitsFilesMetadata
HIGHOriginsNotVerified

Browsers allow message exchanges between Window objects of different origins. Because any window can send / receive messages from other window it is important to verify the sender's / receiver's identity: When sending message with postMessage method, the identity's receiver should be defined (the wildcard keyword (*) should not be used).\nWhen receiving message with message event, the sender's identity should be verified using the origin and possibly source properties. For more information checkout the OWASP A2:2017 (https://owasp.org/www-project-top-ten/2017/A2_2017-Broken_Authentication) and (https://developer.mozilla.org/en-US/docs/Web/API/Window/postMessage) advisory.

1
dist/extension.js
FP 15%
HIGHpostinstall crypto operations

Cryptographic operations detected

1
dist/extension.js
Risky Plugins Authors FP 30%
HIGHNoUseWeakRandom

When software generates predictable values in a context requiring unpredictability, it may be possible for an attacker to guess the next value that will be generated, and use this guess to impersonate another user or access sensitive information. As the Math.random() function relies on a weak pseudorandom number generator, this function should not be used for security-critical applications or for protecting sensitive data. In such context, a cryptographically strong pseudorandom number generator (CSPRNG) should be used instead. For more information checkout the CWE-338 (https://cwe.mitre.org/data/definitions/338.html) advisory.

1
dist/extension.js
FP 5%
HIGHpostinstall network communication

Network communication detected

1
LICENSE.md
Risky Plugins Authors FP 30%
HIGHpostinstall file manipulation

File system manipulation detected

1
dist/extension.js
Risky Plugins Authors FP 20%
HIGHpostinstall persistence mechanism

Persistence mechanism detected

1
dist/extension.js
Risky Plugins Authors FP 20%
HIGHpostinstall system command

System command execution detected

2
extension.vsixmanifestdist/extension.js
Risky Plugins Authors FP 10%
HIGHpostinstall obfuscation

Code obfuscation techniques detected

1
dist/extension.js
Risky Plugins Authors FP 20%
HIGHcredential env files

Environment configuration file path detected

1
dist/extension.js
Risky Plugins Authors FP 10%

Publisher Evidence

Limited evidence

fovelas

Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.

24
Noisy-finding weight
x1.00
Publisher domain
No domain
Missing
Store verification signal
Not exposed
Not exposed
Extension portfolio
Unknown
Portfolio

10 evidence rows available.

Finding Categories

10
Malware Signatures

YARA Rules Matched

9 rules(10 hits)
OriginsNotVerified postinstall crypto operations NoUseWeakRandom postinstall network communication postinstall file manipulation postinstall persistence mechanism postinstall system command postinstall obfuscation credential env files

AI Security Report

AI Security Review

Evidence context: threat category none; evidence quality moderate.

Security Analysis: Zip File Preview (fovelas)

Filesystem and Process Access Justification

The extension's stated purpose is to "preview and explore the contents of ZIP files directly in Visual Studio Code." This functionality legitimately requires file read access to ZIP archives. No evidence bundle findings indicate process execution or network calls beyond expected behavior. The findings_summary shows network: 0 and manifest-analysis: 0, meaning no suspicious network activity or manifest issues were detected.

Credential Access Findings

The evidence shows secret: 0 in the findings summary. There are no credential-access findings targeting .env files, SSH keys, cloud credentials, or VS Code secret storage. The 155 IoC findings are all XIOC false positives misidentifying JavaScript property access chains as domains. Specific examples include:

  • XIOC-DOMAIN-e.file.name - JavaScript property access, not a domain
  • XIOC-DOMAIN-xt.prototype.push.call - Prototype chain method call
  • XIOC-DOMAIN-chevron.open - UI component property access
  • XIOC-DOMAIN-qr.prototype.pause.call - Prototype chain method call

These match the documented false positive pattern: "Property access chains misread as domains: b.call, h.next, g.id." None of these represent actual network destinations or credential access.

Strongest Counterargument

The strongest counterargument is the 90-user download count combined with 10 high-severity malware-signature findings. Low download counts can indicate supply chain risk, and high-severity findings warrant scrutiny. However, the malware-signature findings lack specific details in the evidence bundle and likely represent YARA code-smell rules matching common JavaScript patterns in bundled dependencies. The extension's functionality (ZIP preview) does not require network access, credential access, or postinstall payload execution—none of which appear in the findings. The 155 IoC findings are explicitly documented as XIOC garbage, not actual indicators of compromise.

Conclusion

All 166 findings stem from known false positive sources. The extension performs a legitimate development task with expected file access. No evidence of malicious postinstall behavior, credential theft, or data exfiltration exists in the evidence bundle.

Key Reasons

  • All 155 IoC findings are XIOC false positives misidentifying JavaScript property access as domains
  • Zero secret/credential findings in evidence bundle
  • Zero network findings indicating no suspicious external communication
  • File read access is justified by ZIP preview functionality
  • No postinstall payload execution or supply chain indicators

False Positive Considerations

  • XIOC property access chain misidentification (e.file.name, xt.call, etc.)
  • YARA code-smell rules on bundled JavaScript
  • No credential access or exfiltration findings
  • Extension purpose justifies file read access

Reviewed 2026-04-27; recommended action: suppress false positive; model confidence 85%.

About This Extension

Preview and explore the contents of ZIP files directly in Visual Studio Code.

Frequently Asked Questions