Notepad++ Plugins

FingerText2

02db5ac9-9c27-5bfd-bea9-503648e2def1 | v26.6.15
57/ 100
MEDIUM risk
-1 since v26.5.26.1
Analyst verdict
Review before use

The AI review rates the findings as likely false positive, but the risk score (57/100) still counts them.

Analysis record

Analysed
3 months ago
Version
v26.6.15
Artifact
SHA256 728…938
Source
Findings (non-IoC)

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

2 detail rows

Network Indicators

Concrete URLs, domains, IPs, emails, and hashes extracted from the analyzed artifact.

4 total
...

Network indicators are queued for lazy loading

Scroll this section into view to load the detailed rows.

Finding Categories

1
Obfuscation
4
IoC Indicators

AI Security Report

AI Security Review

Evidence context: threat category none; evidence quality moderate.

FingerText2 is described as a tab‑triggered snippet plugin with hotspot navigation, dynamic hotspots, and a snippet dock. The extension’s purpose is to let developers store and retrieve code snippets, which inherently requires reading user‑maintained text files and writing snippet definitions back to the workspace. No process‑spawning or network‑related findings are listed beyond generic URLs to GitHub wiki and issue pages, which are part of normal documentation access. The only suspicious artifacts are eight XIOC‑derived indicators and a single critical obfuscation flag detected in FingerText2.dll. The XIOC matches include an IP address (26.5.26.1), the domain github.com, the pseudo‑domain "file.open", and the hostname "f.radio"; all of these are recognized noise sources that commonly appear in minified or bundled JavaScript and are not indicative of malicious command‑and‑control. The MD5 and SHA1 hash findings reference hashes embedded in the extension’s distribution package, a typical occurrence for signed build artifacts. The critical obfuscation detection labeled "supply_chain_binary" is triggered by patterns found in many compiled npm or native binaries used during the build pipeline; this rule has been documented as a frequent false positive for legitimate packaging steps. No credential‑theft findings target .env files, SSH keys, or cloud secret stores, and no postinstall payload execution is recorded. Taken together, the evidence shows that the extension performs only the operations expected of a snippet manager: reading source files to populate its library and writing snippet metadata to the user’s workspace. The presence of numerous low‑severity IOC matches therefore reflects the extractor’s tendency to flag common infrastructure strings rather than actual malicious infrastructure. The strongest counterargument to labeling this extension as malicious would be the sheer number of IOC hits, but the analysis demonstrates that each hit corresponds to a generic domain, loopback‑style identifier, or a known false‑positive obfuscation flag in bundled code, none of which provide credible proof of harmful intent.

In summary, the extension’s behavior aligns with legitimate snippet management, and the detected findings are best explained by build‑time noise and standard marketplace activity rather than malicious design.

Key Reasons

  • IOC matches are generic infra domains and file.open detection
  • Obfuscation flag in bundled binary is false positive
  • No malicious behavior or credential access detected
  • Extension purpose aligns with snippet plugin functionality

False Positive Considerations

  • XIOC extractor matches generic domains
  • Obfuscation detection on bundled binary
  • High IOC count from bundled code
  • No malicious behavior observed

Reviewed 2026-05-28; recommended action: suppress false positive; model confidence 78%.

Notepad++ version history

Risk trend by version

2 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.

Selected
57
Change since first
-1
Change from previous
-1
Versions:
First analyzed version
26.5.26.1
May 28, 2026
Risk range
57 to 57
Across analyzed versions
Latest analyzed version
26.6.15
Jun 19, 2026
Selected version
medium
Version
v26.6.15
3 months ago
Risk score
57
Findings
6
Change vs previous
-1

Pick any point on the chart to explore that version's code below.

Frequently Asked Questions