JetBrains Marketplace Verified

ANSI Log Viewer

by jakub-jirak · 1.5K users
0022c5ac-47e1-5299-9ff4-753b9d7df11d | v2025.3.8
21/ 100
LOW risk
Analyst verdict
No high-risk signal observed

Based on the RiskyPlugins AI security review of the observed evidence.

Analysis record

Analysed
3 days ago
Version
v2025.3.8
Artifact
SHA256 8F9…FED
Source
Findings (non-IoC)

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

2 detail rows

YARA Rule Matches

1 rule
SeverityRuleHitsFilesMetadata
LOWpostinstall system command 1
ansi-log-viewer/lib/instrumented-ansi-log-viewer-2025.3.8.jar
-

Network Indicators

Concrete URLs, domains, IPs, emails, and hashes extracted from the analyzed artifact.

2 total
...

Network indicators are queued for lazy loading

Scroll this section into view to load the detailed rows.

Publisher Evidence

Low

jakub-jirak

Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.

82
Noisy-finding weight
x1.00
Publisher domain
jakubjirak.com
Observed
Store verification signal
Verified publisher
Verified
Extension portfolio
24
Portfolio

12 evidence rows available.

Finding Categories

2
IoC Indicators

YARA Rules Matched

1 rule
postinstall system command

AI Security Report

AI Security Review

Evidence context: threat category none; evidence quality weak.

The ANSI Log Viewer extension from JetBrains (developer: Jakub Jirák) presents minimal security findings that do not indicate malicious behavior. The evidence bundle contains only three findings total: two medium-severity IoC domains (t.bj and d.ly) and one info-level metadata hash in the JAR file.

Filesystem and Process Access Justification: The findings bundle contains zero code-smell findings, zero manifest-analysis findings, and zero network findings. There is no evidence of postinstall payload execution, child_process.exec calls, or shell command execution. An ANSI Log Viewer's stated purpose is to display formatted log files, which legitimately requires file read access. The absence of any findings related to file system manipulation, process spawning, or capability escalation indicates the extension operates within expected bounds for its purpose. The metadata finding at ansi-log-viewer/lib/instrumented-ansi-log-viewer-2025.3.8.jar is simply a hash of the extension's JAR file, which is expected for a JetBrains extension.

Credential Access Findings: There are zero credential-related findings in this bundle. No secret findings, no credential_* YARA rule matches, and no evidence of access to .env files, .git/config, SSH keys, or cloud credentials. The findings_summary explicitly shows "secret":"0" and "code-smell":"0". This absence is significant because malicious IDE extensions typically exhibit credential theft patterns, which are completely missing here.

Strongest Counterargument: The two medium-severity IoC domains (t.bj and d.ly) extracted from files could indicate malicious communication channels. However, the XIOC extractor is a documented noise source that produces massive false-positive volumes. Short domains like these are commonly used in legitimate code for URL shorteners, CDN endpoints, or API services. Without evidence of how these domains are used—no network findings, no exfiltration patterns, no postinstall execution—they cannot confirm malicious intent. The lack of corroborating findings (no malware signatures, no obfuscation, no behavioral anomalies) strongly suggests these are extraction artifacts rather than actual threat indicators.

The extension has 1,246 users on the JetBrains marketplace, which undergoes more review than VS Code. The complete absence of behavioral threat patterns combined with noisy IoC extraction supports a false positive classification.

Key Reasons

  • No code-smell, malware signature, or credential access findings
  • XIOC domain extraction is known to produce false positives
  • No evidence of postinstall payload execution or exfiltration patterns
  • Extension has legitimate purpose with no behavioral anomalies
  • Zero secret or credential-related findings in evidence bundle

False Positive Considerations

  • XIOC domain extraction false positives
  • Short domain names common in legitimate code
  • No behavioral evidence of malicious activity
  • No code-smell or malware signature findings

Reviewed 2026-05-06; recommended action: suppress false positive; model confidence 75%.

About This Extension

Adds ANSI color rendering (SGR, 256-color, truecolor) to configured extensions (default *.log). Features: Configurable file extensions Folding ANSI escape sequences...

Frequently Asked Questions