JetBrains Marketplace

JTools SSH Publisher

0009c0a3-7137-5c07-b6cb-a9d214e5593d | v1.2.8
46/ 100
MEDIUM risk
+8 since v1.2.7
Analyst verdict
Review before use

The AI review rates the findings as likely false positive, but the risk score (46/100) still counts them.

Analysis record

Analysed
4 days ago
Version
v1.2.8
Artifact
SHA256 4D9…909
Source
Findings (non-IoC)

Is JTools SSH Publisher safe?

JTools SSH Publisher is a JetBrains extension for managing SSH connections and key publishing from your IDE. The extension declares no special permissions and makes no requests to access your files or system credentials.

The scanner found 162 domain names extracted from the extension's code, such as jm.ad, i.cl, and s.re. However, these domains contain obvious parsing errors (many include corrupted Unicode characters like 0ϗ.cc and 9rŕ.tz) and match patterns the XIOC extractor is known to produce when reading minified JavaScript. They don't represent real network connections the extension makes. No actual malware signatures matched, and no findings indicate the extension reads your SSH keys, environment variables, or credentials.

The 21 low-severity code-quality warnings are standard noise from scanning minified code, they flag generic Node.js patterns like accessing process variables or the filesystem, which any SSH tool legitimately needs to do. The extension's purpose requires spawning SSH processes and reading local configuration, so this access is expected and justified.

The findings come from the extension's bundled source code being scanned, a normal byproduct of how automated tools analyze minified and packaged software.

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

29 detail rows

YARA Rule Matches

8 rules
SeverityRuleHitsFilesMetadata
LOWpostinstall persistence mechanism 1
jtools-ssh-publisher/lib/instrumented-jtools-ssh-publisher-1.2.8.jar
-
LOWpostinstall crypto operations 3
jtools-ssh-publisher/lib/sshd-sftp-2.15.0.jarjtools-ssh-publisher/lib/kotlin-stdlib-1.9.22.jarjtools-ssh-publisher/lib/sshd-common-2.15.0.jar
-
LOWpostinstall file manipulation 1
jtools-ssh-publisher/lib/instrumented-jtools-ssh-publisher-1.2.8.jar
-
LOWJavaDropper 1
jtools-ssh-publisher/lib/sqlite-jdbc-3.45.1.0.jar
-
LOWpostinstall obfuscation 2
jtools-ssh-publisher/lib/kotlin-stdlib-1.9.22.jarjtools-ssh-publisher/lib/sshd-common-2.15.0.jar
-
LOWpostinstall network communication 6
jtools-ssh-publisher/lib/instrumented-jtools-ssh-publisher-1.2.8.jarjtools-ssh-publisher/lib/sqlite-jdbc-3.45.1.0.jarjtools-ssh-publisher/lib/sshd-sftp-2.15.0.jar +3 more
-
LOWpostinstall system command 6
jtools-ssh-publisher/lib/instrumented-jtools-ssh-publisher-1.2.8.jarjtools-ssh-publisher/lib/sqlite-jdbc-3.45.1.0.jarjtools-ssh-publisher/lib/sshd-sftp-2.15.0.jar +3 more
-
LOWpostinstall file download 1
jtools-ssh-publisher/lib/instrumented-jtools-ssh-publisher-1.2.8.jar
-

Network Indicators

Concrete URLs, domains, IPs, emails, and hashes extracted from the analyzed artifact.

162 total
...

Network indicators are queued for lazy loading

Scroll this section into view to load the detailed rows.

Publisher Evidence

Limited evidence

8349aa96-e390-43d3-9aaf-5572ea8a8593

Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.

34
Noisy-finding weight
x1.00
Publisher domain
No domain
Missing
Store verification signal
Not exposed
Not exposed
Extension portfolio
5
Portfolio

12 evidence rows available.

Finding Categories

162
IoC Indicators

YARA Rules Matched

8 rules(21 hits)
postinstall persistence mechanism postinstall crypto operations postinstall file manipulation JavaDropper postinstall obfuscation postinstall network communication postinstall system command postinstall file download

AI Security Report

AI Security Review

Evidence context: threat category none; evidence quality moderate.

JTools SSH Publisher is a JetBrains IDE extension with no declared permissions and no host access requests. The extension's stated purpose is SSH publishing—spawning SSH processes and managing key-based connections are core functions for this use case, and the bundle shows no credential-access findings targeting .env, .ssh directories, or cloud credentials.

The 162 XIOC findings reporting domains like jm.ad, i.cl, tf.cd, and s.re are characteristic false positives from the XIOC extractor parsing minified JavaScript. Several extracted domains contain diacritical marks (ϣr.sm, 0ϗ.cc, 9rŕ.tz, 2ļ.ky), which are artifacts of minified code parsing rather than real network indicators. The property-chain pattern (pom.properties appearing as a domain, m.mo, m.ye) confirms the extractor is tokenizing code, not discovering actual infrastructure.

No malware signatures matched. Zero credential-theft indicators. The 21 code-smell findings are low-severity YARA rules firing on standard Node.js patterns (process, fs, env variable reference)—this is expected in any extension that performs local system operations. These rules are not indicators of malicious intent.

The network_endpoints list in the bundle consists of the same implausible two-letter domains extracted by XIOC, strongly suggesting they are parsing artifacts rather than command-and-control servers the extension actually connects to. Real C2 infrastructure does not consist of random TLD combinations with Unicode corruption.

The strongest counterargument is that 162 findings could indicate obfuscation or intentional hiding. However, the nature of the findings—property-chain misreadings, locale file fragments with diacritical marks, and bundled dependency IoCs—points to scan noise, not malicious obfuscation. Legitimate IDE extensions are routinely minified, bundled with npm packages, and generate large XIOC counts as a side effect of toolchain output. The absence of any malware signature match, credential theft attempt, or postinstall payload execution is more informative than the raw finding count.

This extension appears to be a legitimate development tool triggering expected false positives from automated scanning of minified code.

Key Reasons

  • 162 of 191 findings are XIOC domain extractions from minified JavaScript, matching known false-positive patterns (property chains, locale file fragments, and generic TLDs)
  • No malware signatures matched; no credential-access findings; no secret reads detected
  • Network endpoints consist entirely of implausible two-letter domains with diacritical marks (0ϗ.cc, 9rŕ.tz, 2ļ.ky) characteristic of XIOC parsing minified code, not real C2
  • 21 code-smell findings are low-severity YARA noise on standard Node.js patterns
  • Extension declares no special permissions and makes no host access requests

False Positive Considerations

  • XIOC extractor misreading minified JavaScript property chains and character sequences as domain names
  • Diacritical marks and Unicode artifacts in extracted domains indicate OCR/parsing errors, not actual network infrastructure
  • Bundled or minified source producing multiplicative false positives across generic TLD combinations

Reviewed 2026-09-29; recommended action: suppress false positive; model confidence 72%.

JetBrains version history

Risk trend by version

6 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.

Selected
46
Change since first
+7
Change from previous
+8
Versions:
First analyzed version
1.2.3
Apr 5, 2026
Risk range
38 to 46
Across analyzed versions
Latest analyzed version
1.2.8
Aug 2, 2026
Selected version
medium
Version
v1.2.8
2 months ago
Risk score
46
Findings
191
Change vs previous
+8

Pick any point on the chart to explore that version's code below.

About This Extension

A powerful SSH client plugin for IntelliJ IDEA with terminal, file browser, and batch upload capabilities. 功能强大的 SSH 客户端插件,支持终端、文件浏览器和批量上传功能。 Source Code / 源码 Features...

Frequently Asked Questions