JTools SSH Publisher
The AI review rates the findings as likely false positive, but the risk score (46/100) still counts them.
Analysis record
- Analysed
- 4 days ago
- Version
- v1.2.8
- Artifact
- SHA256 4D9…909
- Source
- Findings (non-IoC)
Is JTools SSH Publisher safe?
JTools SSH Publisher is a JetBrains extension for managing SSH connections and key publishing from your IDE. The extension declares no special permissions and makes no requests to access your files or system credentials.
The scanner found 162 domain names extracted from the extension's code, such as jm.ad, i.cl, and s.re. However, these domains contain obvious parsing errors (many include corrupted Unicode characters like 0ϗ.cc and 9rŕ.tz) and match patterns the XIOC extractor is known to produce when reading minified JavaScript. They don't represent real network connections the extension makes. No actual malware signatures matched, and no findings indicate the extension reads your SSH keys, environment variables, or credentials.
The 21 low-severity code-quality warnings are standard noise from scanning minified code, they flag generic Node.js patterns like accessing process variables or the filesystem, which any SSH tool legitimately needs to do. The extension's purpose requires spawning SSH processes and reading local configuration, so this access is expected and justified.
The findings come from the extension's bundled source code being scanned, a normal byproduct of how automated tools analyze minified and packaged software.
Evidence ledger
Ranked by severity · findings with a source location link to the code viewer
YARA Rule Matches
8 rules| Severity | Rule | Hits | Files | Metadata |
|---|---|---|---|---|
| LOW | postinstall persistence mechanism | 1 | jtools-ssh-publisher/lib/instrumented-jtools-ssh-publisher-1.2.8.jar | - |
| LOW | postinstall crypto operations | 3 | jtools-ssh-publisher/lib/sshd-sftp-2.15.0.jarjtools-ssh-publisher/lib/kotlin-stdlib-1.9.22.jarjtools-ssh-publisher/lib/sshd-common-2.15.0.jar | - |
| LOW | postinstall file manipulation | 1 | jtools-ssh-publisher/lib/instrumented-jtools-ssh-publisher-1.2.8.jar | - |
| LOW | JavaDropper | 1 | jtools-ssh-publisher/lib/sqlite-jdbc-3.45.1.0.jar | - |
| LOW | postinstall obfuscation | 2 | jtools-ssh-publisher/lib/kotlin-stdlib-1.9.22.jarjtools-ssh-publisher/lib/sshd-common-2.15.0.jar | - |
| LOW | postinstall network communication | 6 | jtools-ssh-publisher/lib/instrumented-jtools-ssh-publisher-1.2.8.jarjtools-ssh-publisher/lib/sqlite-jdbc-3.45.1.0.jarjtools-ssh-publisher/lib/sshd-sftp-2.15.0.jar +3 more | - |
| LOW | postinstall system command | 6 | jtools-ssh-publisher/lib/instrumented-jtools-ssh-publisher-1.2.8.jarjtools-ssh-publisher/lib/sqlite-jdbc-3.45.1.0.jarjtools-ssh-publisher/lib/sshd-sftp-2.15.0.jar +3 more | - |
| LOW | postinstall file download | 1 | jtools-ssh-publisher/lib/instrumented-jtools-ssh-publisher-1.2.8.jar | - |
Network Indicators
Concrete URLs, domains, IPs, emails, and hashes extracted from the analyzed artifact.
Network indicators are queued for lazy loading
Scroll this section into view to load the detailed rows.
Publisher Evidence
Limited evidence8349aa96-e390-43d3-9aaf-5572ea8a8593
Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.
12 evidence rows available.
Finding Categories
YARA Rules Matched
8 rules(21 hits)AI Security Report
AI Security Review
Evidence context: threat category none; evidence quality moderate.
JTools SSH Publisher is a JetBrains IDE extension with no declared permissions and no host access requests. The extension's stated purpose is SSH publishing—spawning SSH processes and managing key-based connections are core functions for this use case, and the bundle shows no credential-access findings targeting .env, .ssh directories, or cloud credentials.
The 162 XIOC findings reporting domains like jm.ad, i.cl, tf.cd, and s.re are characteristic false positives from the XIOC extractor parsing minified JavaScript. Several extracted domains contain diacritical marks (ϣr.sm, 0ϗ.cc, 9rŕ.tz, 2ļ.ky), which are artifacts of minified code parsing rather than real network indicators. The property-chain pattern (pom.properties appearing as a domain, m.mo, m.ye) confirms the extractor is tokenizing code, not discovering actual infrastructure.
No malware signatures matched. Zero credential-theft indicators. The 21 code-smell findings are low-severity YARA rules firing on standard Node.js patterns (process, fs, env variable reference)—this is expected in any extension that performs local system operations. These rules are not indicators of malicious intent.
The network_endpoints list in the bundle consists of the same implausible two-letter domains extracted by XIOC, strongly suggesting they are parsing artifacts rather than command-and-control servers the extension actually connects to. Real C2 infrastructure does not consist of random TLD combinations with Unicode corruption.
The strongest counterargument is that 162 findings could indicate obfuscation or intentional hiding. However, the nature of the findings—property-chain misreadings, locale file fragments with diacritical marks, and bundled dependency IoCs—points to scan noise, not malicious obfuscation. Legitimate IDE extensions are routinely minified, bundled with npm packages, and generate large XIOC counts as a side effect of toolchain output. The absence of any malware signature match, credential theft attempt, or postinstall payload execution is more informative than the raw finding count.
This extension appears to be a legitimate development tool triggering expected false positives from automated scanning of minified code.
Key Reasons
- 162 of 191 findings are XIOC domain extractions from minified JavaScript, matching known false-positive patterns (property chains, locale file fragments, and generic TLDs)
- No malware signatures matched; no credential-access findings; no secret reads detected
- Network endpoints consist entirely of implausible two-letter domains with diacritical marks (0ϗ.cc, 9rŕ.tz, 2ļ.ky) characteristic of XIOC parsing minified code, not real C2
- 21 code-smell findings are low-severity YARA noise on standard Node.js patterns
- Extension declares no special permissions and makes no host access requests
False Positive Considerations
- XIOC extractor misreading minified JavaScript property chains and character sequences as domain names
- Diacritical marks and Unicode artifacts in extracted domains indicate OCR/parsing errors, not actual network infrastructure
- Bundled or minified source producing multiplicative false positives across generic TLD combinations
Reviewed 2026-09-29; recommended action: suppress false positive; model confidence 72%.
JetBrains version history
Risk trend by version
6 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.
Pick any point on the chart to explore that version's code below.
About This Extension
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace
JTools
8349aa96-e390-43d3-9aaf-5572ea8a8593
JTools HTTP Client
8349aa96-e390-43d3-9aaf-5572ea8a8593
JTools-Background
8349aa96-e390-43d3-9aaf-5572ea8a8593
Jtools-Mybatis-Log
8349aa96-e390-43d3-9aaf-5572ea8a8593
DotVVM
keeper7
CodeScan
CodeScan