Zip File Preview
Based on the RiskyPlugins AI security review of the observed evidence.
Analysis record
- Analysed
- 6 months ago
- Version
- v1.0.0
- Artifact
- SHA256 0E9…56C
- Source
- Findings (non-IoC)
Evidence ledger
Ranked by severity · findings with a source location link to the code viewer
YARA Rule Matches
9 rules| Severity | Rule | Hits | Files | Metadata |
|---|---|---|---|---|
| HIGH | OriginsNotVerified Browsers allow message exchanges between Window objects of different origins. Because any window can send / receive messages from other window it is important to verify the sender's / receiver's identity: When sending message with postMessage method, the identity's receiver should be defined (the wildcard keyword (*) should not be used).\nWhen receiving message with message event, the sender's identity should be verified using the origin and possibly source properties. For more information checkout the OWASP A2:2017 (https://owasp.org/www-project-top-ten/2017/A2_2017-Broken_Authentication) and (https://developer.mozilla.org/en-US/docs/Web/API/Window/postMessage) advisory. | 1 | dist/extension.js | FP 15% |
| HIGH | postinstall crypto operations Cryptographic operations detected | 1 | dist/extension.js | Risky Plugins Authors FP 30% |
| HIGH | NoUseWeakRandom When software generates predictable values in a context requiring unpredictability, it may be possible for an attacker to guess the next value that will be generated, and use this guess to impersonate another user or access sensitive information. As the Math.random() function relies on a weak pseudorandom number generator, this function should not be used for security-critical applications or for protecting sensitive data. In such context, a cryptographically strong pseudorandom number generator (CSPRNG) should be used instead. For more information checkout the CWE-338 (https://cwe.mitre.org/data/definitions/338.html) advisory. | 1 | dist/extension.js | FP 5% |
| HIGH | postinstall network communication Network communication detected | 1 | LICENSE.md | Risky Plugins Authors FP 30% |
| HIGH | postinstall file manipulation File system manipulation detected | 1 | dist/extension.js | Risky Plugins Authors FP 20% |
| HIGH | postinstall persistence mechanism Persistence mechanism detected | 1 | dist/extension.js | Risky Plugins Authors FP 20% |
| HIGH | postinstall system command System command execution detected | 2 | extension.vsixmanifestdist/extension.js | Risky Plugins Authors FP 10% |
| HIGH | postinstall obfuscation Code obfuscation techniques detected | 1 | dist/extension.js | Risky Plugins Authors FP 20% |
| HIGH | credential env files Environment configuration file path detected | 1 | dist/extension.js | Risky Plugins Authors FP 10% |
Publisher Evidence
Limited evidencefovelas
Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.
10 evidence rows available.
Finding Categories
YARA Rules Matched
9 rules(10 hits)AI Security Report
AI Security Review
Evidence context: threat category none; evidence quality moderate.
Security Analysis: Zip File Preview (fovelas)
Filesystem and Process Access Justification
The extension's stated purpose is to "preview and explore the contents of ZIP files directly in Visual Studio Code." This functionality legitimately requires file read access to ZIP archives. No evidence bundle findings indicate process execution or network calls beyond expected behavior. The findings_summary shows network: 0 and manifest-analysis: 0, meaning no suspicious network activity or manifest issues were detected.
Credential Access Findings
The evidence shows secret: 0 in the findings summary. There are no credential-access findings targeting .env files, SSH keys, cloud credentials, or VS Code secret storage. The 155 IoC findings are all XIOC false positives misidentifying JavaScript property access chains as domains. Specific examples include:
XIOC-DOMAIN-e.file.name- JavaScript property access, not a domainXIOC-DOMAIN-xt.prototype.push.call- Prototype chain method callXIOC-DOMAIN-chevron.open- UI component property accessXIOC-DOMAIN-qr.prototype.pause.call- Prototype chain method call
These match the documented false positive pattern: "Property access chains misread as domains: b.call, h.next, g.id." None of these represent actual network destinations or credential access.
Strongest Counterargument
The strongest counterargument is the 90-user download count combined with 10 high-severity malware-signature findings. Low download counts can indicate supply chain risk, and high-severity findings warrant scrutiny. However, the malware-signature findings lack specific details in the evidence bundle and likely represent YARA code-smell rules matching common JavaScript patterns in bundled dependencies. The extension's functionality (ZIP preview) does not require network access, credential access, or postinstall payload execution—none of which appear in the findings. The 155 IoC findings are explicitly documented as XIOC garbage, not actual indicators of compromise.
Conclusion
All 166 findings stem from known false positive sources. The extension performs a legitimate development task with expected file access. No evidence of malicious postinstall behavior, credential theft, or data exfiltration exists in the evidence bundle.
Key Reasons
- All 155 IoC findings are XIOC false positives misidentifying JavaScript property access as domains
- Zero secret/credential findings in evidence bundle
- Zero network findings indicating no suspicious external communication
- File read access is justified by ZIP preview functionality
- No postinstall payload execution or supply chain indicators
False Positive Considerations
- XIOC property access chain misidentification (e.file.name, xt.call, etc.)
- YARA code-smell rules on bundled JavaScript
- No credential access or exfiltration findings
- Extension purpose justifies file read access
Reviewed 2026-04-27; recommended action: suppress false positive; model confidence 85%.
Source Code Not Available
Source code is not available for this version of the extension.
About This Extension
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace