JetBrains Marketplace Verified

Gradle

by JetBrains · 700.9K users · 4.7 rating
0b983171-8b85-58ef-aae7-4519a21dfd5d | v263.6259.39
67/ 100
HIGH risk
No change since v263.5701.47
Analyst verdict
Review before use

The AI review rates the findings as likely false positive, but the risk score (67/100) still counts them.

Analysis record

Analysed
2 days ago
Version
v262.10968.148
Artifact
SHA256 949…F9D
Source
Findings (non-IoC)

Is Gradle safe?

This is JetBrains' official Gradle plugin for IntelliJ-based IDEs, installed by close to 700,000 developers. It connects the editor to Gradle so you can sync build scripts, run tasks and manage dependencies without leaving the IDE. This extension declares no special permissions, and the scan found no network endpoints for it at all, which fits a plugin that works through the IDE's own build integration.

One high-severity signature did fire. It is named YARA--CAP_HookExKeylogger and it sits inside gradle-plugin/lib/gradle-api-9.6.0.jar. Read literally, that name describes a tool that hooks the keyboard to record what you type. The other 149 hits are low-severity code-smell rules, the sort that match any large Java codebase for calling subprocesses or reading environment variables.

The keylogger signature is a capability rule. It matches Windows API imports that a keylogging family has used, and Gradle's own API jar contains console and input handling code that imports the same things. A real keylogger also needs a place to send what it captures. This plugin records no outbound endpoints, no persistence entries and no writes outside the project folder, so there is no route for stolen keystrokes to leave your machine.

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

41 detail rows
Showing 25 of 40 · highest severity first

YARA Rule Matches

1 rule
SeverityRuleHitsFilesMetadata
HIGHCAP HookExKeylogger 1
gradle-plugin/lib/gradle-api-9.6.0.jar
Brian C. Bell -- @biebsmalwareguy FP 5%

Publisher Evidence

High

JetBrains

Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.

100
Noisy-finding weight
x0.50
Publisher domain
jetbrains.com
Trusted match
Store verification signal
Verified publisher
Verified
Extension portfolio
945
Portfolio

12 evidence rows available.

Finding Categories

1
Malware Signatures

YARA Rules Matched

1 rule
CAP HookExKeylogger

AI Security Report

AI Security Review

Evidence context: threat category none; evidence quality moderate.

What this extension is

Gradle is JetBrains' official build-tool integration for IntelliJ-based IDEs. It runs on the JetBrains Marketplace under the verified JetBrains publisher account, with 692,748 users on version 262.10968.148. Its job is to drive Gradle from inside the editor: syncing build scripts, executing tasks, resolving dependencies.

Filesystem and process access

This build records no manifest permissions, no host permissions and no network endpoints. The 149 findings in the low-severity code-smell bucket match ProcessBuilder, System.getenv and Runtime.exec patterns plus assorted code-quality rules, which is what a scan of any large Java or Kotlin bundle returns. A Gradle plugin spawns a daemon, reads build.gradle and settings.gradle, and writes into the project's build directory. That is the stated purpose. Nothing in the findings pairs a file read with a destination for the data.

Credential access

No secret findings were recorded. Nothing matched .env, .ssh, private keys or cloud credential paths, and no rule flagged access to IDE credential storage. The environment-variable code smells sit only in the low bucket and name no target file.

The one high-severity match

YARA--CAP_HookExKeylogger fired at gradle-plugin/lib/gradle-api-9.6.0.jar. The path matters. That is Gradle's own published API jar, bundled into the plugin's lib directory, and the signature is a capability rule from a public rule set: it describes Windows API imports a keylogging family has used. Gradle's console and input handling code exercises similar APIs, which is enough for this rule to fire.

Supply chain signals

Nothing points at impersonation. The publisher account is JetBrains, the listing is the official JetBrains Marketplace entry, and the user count fits a first-party plugin. No tool-poisoning, obfuscation or dependency findings were recorded. The bundled gradle-api-9.6.0.jar follows Gradle's own release numbering, which is what a genuine integration looks like.

Counterargument

The case for treating this as more than noise is that a keylogger signature is specific. Someone wrote it for a reason, and it is the only high-severity hit here. What weakens that case: the match site is a bundled artifact published by the Gradle project, the extension's own code is not where the signature landed, and a keystroke capture tool needs a sink. Nothing here transmits. No network endpoint is recorded, no persistence or startup-modification finding exists, and no write outside the project directory is described. A jar sitting in a build tool's library folder with no outbound route is not a working keylogger.

Key Reasons

  • Single high-severity hit (YARA--CAP_HookExKeylogger) is located in gradle-api-9.6.0.jar, a bundled artifact published by the Gradle project rather than extension-authored code
  • No network endpoints, IoC hits, obfuscation, tool-poisoning or secret-access findings were recorded for the extension
  • 149 low-severity code-smell findings are process-spawning and environment-variable patterns expected from a build-tool integration
  • Verified first-party JetBrains publisher on the JetBrains Marketplace with 692,748 users on version 262.10968.148, with no typosquat or impersonation signals
  • No persistence, startup modification or outbound data path exists to support an actual keylogging payload

False Positive Considerations

  • CAP_ capability rule firing on Gradle's own bundled API jar instead of extension code
  • Broad code-smell rules matching standard Java subprocess and environment-variable usage
  • Zero corroborating network, exfiltration or persistence findings alongside the signature
  • Signature attributed to a third-party published dependency rather than the plugin's own binaries

Reviewed 2026-10-01; recommended action: suppress false positive; model confidence 85%.

JetBrains version history

Risk trend by version

49 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.

Selected
67
Change since first
+46
Change from previous
No change
Versions:
First analyzed version
253.32098.107
Apr 23, 2026
Risk range
21 to 71
Across analyzed versions
Latest analyzed version
262.10968.148
Sep 29, 2026
Selected version
high
Version
v262.10968.148
2 days ago
Risk score
67
Findings
190
Change vs previous
No change

Pick any point on the chart to explore that version's code below.

About This Extension

Provides integration with Gradle for automation of building, testing, publishing, and deployment of software packages. Create a new Gradle project or import an...

Frequently Asked Questions