VS Code Marketplace

PSRuleM277hosturlnew

by PRODM278DVT · 22 downloads
165203a4-b7cc-5f83-b068-d54eef2f6db6 | v2025.3.32
100/ 100
CRITICAL risk
Risk verdict
Do not install

Score-based assessment (critical risk, 100/100). No analyst review available.

Analysis record

Analysed
1 months ago
Version
v2025.3.32
Artifact
SHA256 5E5…E8B
Source
Findings (non-IoC)

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

648 detail rows
Showing 25 of 448 · highest severity first

YARA Rule Matches

13 rules
SeverityRuleHitsFilesMetadata
HIGHNjrat

Njrat

2
server/runtimes/unix/lib/net8.0/System.Management.Automation.dllserver/runtimes/win/lib/net8.0/System.Management.Automation.dll
botherder https://github.com/botherder FP 10%
LOWpostinstall system command 59
server/runtimes/linux-x64/native/libpsl-native.soserver/runtimes/unix/lib/net8.0/Modules/Microsoft.PowerShell.Utility/Microsoft.PowerShell.Utility.psd1schemas/PSRule-language.schema.json +56 more
-
LOWpostinstall file manipulation 21
changelog.mdserver/runtimes/win/lib/net8.0/Modules/Microsoft.WSMan.Management/Microsoft.WSMan.Management.psd1server/Microsoft.PSRule.Core.xml +18 more
-
LOWpostinstall network communication 28
ThirdPartyNotices.txtserver/runtimes/win/lib/net8.0/Modules/Microsoft.PowerShell.Security/Security.types.ps1xmlserver/runtimes/linux-arm64/native/libpsl-native.so +25 more
-
LOWpostinstall crypto operations 32
server/Modules/PSRule/PSRule.psd1server/Microsoft.PSRule.Types.xmlout/dist/main.js +29 more
-
LOWpostinstall obfuscation 8
schemas/PSRule-language.schema.jsonserver/runtimes/linux-arm/native/libpsl-native.soserver/Microsoft.PSRule.Core.pdb +5 more
-
LOWpostinstall registry modification 5
server/Microsoft.PSRule.EditorServices.pdbserver/Microsoft.PSRule.CommandLine.deps.jsonserver/runtimes/win/lib/net8.0/Modules/Microsoft.PowerShell.Security/Security.types.ps1xml +2 more
-
LOWUsingShellInterpreterWhenExecutingOSCommands 1
out/dist/main.js
-
LOWpostinstall file download 13
server/Microsoft.PSRule.Core.pdbserver/Microsoft.PSRule.Badges.pdbserver/Microsoft.PSRule.EditorServices.deps.json +10 more
-
LOWNoUseWeakRandom 1
out/dist/main.js
-
LOWpostinstall persistence mechanism 5
server/Microsoft.PSRule.EditorServicesserver/Microsoft.PSRule.SDK.deps.jsonserver/Microsoft.PSRule.CommandLine.deps.json +2 more
-
LOWcredential env files 10
server/Microsoft.PSRule.SDK.pdbserver/Microsoft.PSRule.EditorServices.pdbserver/Microsoft.PSRule.CommandLine.deps.json +7 more
-
LOWDebuggerStatementsShouldNotBeUsed 15
server/runtimes/unix/lib/net8.0/Microsoft.PowerShell.Commands.Utility.dllserver/runtimes/unix/lib/net8.0/Microsoft.PowerShell.ConsoleHost.dllserver/Microsoft.PSRule.EditorServices.xml +12 more
-

Network Indicators

Concrete URLs, domains, IPs, emails, and hashes extracted from the analyzed artifact.

1,043 total
...

Network indicators are queued for lazy loading

Scroll this section into view to load the detailed rows.

Publisher Evidence

Limited evidence

PRODM278DVT

Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.

44
Noisy-finding weight
x1.00
Publisher domain
No domain
Missing
Store verification signal
Not exposed
Not exposed
Extension portfolio
231
Portfolio

13 evidence rows available.

Finding Categories

2
Malware Signatures
446
Obfuscation
1,043
IoC Indicators

YARA Rules Matched

13 rules(200 hits)
Njrat postinstall system command postinstall file manipulation postinstall network communication postinstall crypto operations postinstall obfuscation postinstall registry modification UsingShellInterpreterWhenExecutingOSCommands postinstall file download NoUseWeakRandom postinstall persistence mechanism credential env files DebuggerStatementsShouldNotBeUsed

Security Analysis Summary

Security Analysis Overview

PSRuleM277hosturlnew is a Visual Studio Code Marketplace extension published by PRODM278DVT. Version 2025.3.32 has been analyzed by the Risky Plugins security platform, receiving a risk score of 100/100 (CRITICAL risk) based on 1691 security findings.

Risk Assessment

This extension presents critical security risk. Severe issues were detected, potentially including malware indicators, exposed secrets, or dangerous behaviors. Installation is strongly discouraged until these issues are addressed.

Findings Breakdown

  • Critical: 446 finding(s)
  • High: 2 finding(s)
  • Medium: 1043 finding(s)
  • Low: 200 finding(s)

What Was Analyzed

The security assessment covers multiple analysis categories:

  • Malware Detection: YARA rule matching against 2,400+ malware signatures
  • Secret Detection: Scanning for exposed API keys, tokens, and credentials
  • Static Analysis: Code-level security analysis for common vulnerability patterns
  • Network Analysis: Detection of suspicious network communications and endpoints
  • Obfuscation Detection: Identification of code obfuscation techniques

Developer Information

PSRuleM277hosturlnew is published by PRODM278DVT on the Visual Studio Code Marketplace marketplace.

Recommendation

This extension is not recommended for installation without thorough manual review. Consider alternatives with lower risk scores, or contact the developer to address the identified security concerns.

About This Extension

Validate infrastructure as code (IaC) and DevOps repositories using PSRule.

Frequently Asked Questions