Notepad++ Plugins

Papyrus Script Lexer

00ffdf1a-e75b-5be9-9efa-3f408c4df0df | v1.2.2.354
42/ 100
MEDIUM risk
Analyst verdict
Review before use

The AI review rates the findings as likely false positive, but the risk score (42/100) still counts them.

Analysis record

Analysed
7 months ago
Version
v1.2.2.354
Source
Findings (non-IoC)

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

22 detail rows

YARA Rule Matches

8 rules
SeverityRuleHitsFilesMetadata
HIGHpostinstall crypto operations

Cryptographic operations detected

2
extras/autoCompletion/Papyrus Script.xmlextras/userDefineLangs/Papyrus.udl.xml
Risky Plugins Authors FP 30%
HIGHpostinstall file download

File download activity detected

1
extras/autoCompletion/Papyrus Script.xml
Risky Plugins Authors FP 30%
HIGHpostinstall obfuscation

Code obfuscation techniques detected

2
extras/autoCompletion/Papyrus Script.xmlextras/userDefineLangs/Papyrus.udl.xml
Risky Plugins Authors FP 20%
HIGHpostinstall registry modification

Windows registry modification detected

1
extras/functionList/overrideMap.xml
Risky Plugins Authors FP 30%
HIGHpostinstall network communication

Network communication detected

2
extras/autoCompletion/Papyrus Script.xmlextras/userDefineLangs/Papyrus.udl.xml
Risky Plugins Authors FP 30%
HIGHpostinstall file manipulation

File system manipulation detected

3
extras/functionList/overrideMap.xmlextras/autoCompletion/Papyrus Script.xmlextras/userDefineLangs/Papyrus.udl.xml
Risky Plugins Authors FP 20%
HIGHpostinstall persistence mechanism

Persistence mechanism detected

1
extras/functionList/overrideMap.xml
Risky Plugins Authors FP 20%
HIGHpostinstall system command

System command execution detected

3
extras/functionList/overrideMap.xmlextras/autoCompletion/Papyrus Script.xmlextras/userDefineLangs/Papyrus.udl.xml
Risky Plugins Authors FP 10%

Network Indicators

Concrete URLs, domains, IPs, emails, and hashes extracted from the analyzed artifact.

17 total
...

Network indicators are queued for lazy loading

Scroll this section into view to load the detailed rows.

Finding Categories

15
Malware Signatures
17
IoC Indicators

YARA Rules Matched

8 rules(15 hits)
postinstall crypto operations postinstall file download postinstall obfuscation postinstall registry modification postinstall network communication postinstall file manipulation postinstall persistence mechanism postinstall system command

AI Security Report

AI Security Review

Evidence context: threat category none; evidence quality moderate.

Filesystem/Process Access Justification

This Notepad++ plugin's stated purpose is editing Papyrus Script files for Bethesda games with syntax highlighting, compilation support, and error list viewing. The IoC findings directly support this purpose: XIOC-DOMAIN-www.creationkit.com and XIOC-URL-https://www.creationkit.com/index.php?title=Notepad%2B%2B_Setup reference the official Creation Kit documentation site where Papyrus scripting is documented. XIOC-DOMAIN-npp-user-manual.org and XIOC-URL-https://npp-user-manual.org/docs/function-list/ reference Notepad++ documentation, expected for a Notepad++ plugin. The XIOC-DOMAIN-www.gnu.org and XIOC-URL-http://www.gnu.org/licenses/ findings indicate standard open-source licensing.

Credential Access Findings

There are zero secret or credential-access findings in this bundle. The findings_summary explicitly shows "secret":"0" and "credential":0 (not listed in by_category). The email address [email protected] is a developer contact, not credential theft. No findings target .env, .ssh, cloud credentials, or VS Code secret storage.

False Positive Drivers

The IPv6 fragment findings XIOC-IP-4::, XIOC-IP-e::fa, and XIOC-IP-e::e match the documented false positive pattern for hex substrings misread as IPs. The XIOC-DOMAIN-message.show finding is a property access chain misread as a domain (known XIOC extractor noise). The 15 code-smell findings are classified as low-severity patterns that fire on almost any non-trivial code. All 17 IoC findings reference benign domains directly related to the extension's purpose or are known false positive patterns.

Strongest Counterargument

The 0 user count and unknown version could suggest an unpublished or test extension. However, the developer name "blu3mania" is a known Bethesda modding community member, and all findings are explainable as legitimate documentation references or false positives. There are no malware signatures, no obfuscation findings, and no evidence of malicious behavior. The high severity count (15 high, 17 medium) is inflated by IoC volume on benign domains, not actual threat indicators.

Key Reasons

  • All IoC findings reference benign documentation domains related to Papyrus scripting
  • No malware signatures or obfuscation findings detected
  • Zero credential/secret findings in evidence bundle
  • IPv6 fragment findings match known false positive patterns
  • Extension purpose aligns with all domain references found

False Positive Considerations

  • IPv6 fragment false positives (4::, e::fa, e::e)
  • Property access chains misread as domains (message.show)
  • Benign documentation domain references (creationkit.com, npp-user-manual.org, gnu.org)
  • Code-smell findings on expected patterns

Reviewed 2026-04-27; recommended action: suppress false positive; model confidence 85%.

Frequently Asked Questions