JTools-Background
The AI review rates the findings as likely false positive, but the risk score (40/100) still counts them.
Analysis record
- Analysed
- 5 days ago
- Version
- v0.0.2
- Artifact
- SHA256 2DC…90F
- Source
- Findings (non-IoC)
Evidence ledger
Ranked by severity · findings with a source location link to the code viewer
Publisher Evidence
Limited evidence8349aa96-e390-43d3-9aaf-5572ea8a8593
Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.
12 evidence rows available.
Finding Categories
AI Security Report
AI Security Review
Evidence context: threat category none; evidence quality moderate.
JTools-Background is a JetBrains plugin, published at version 0.0.2 with 86 users. It declares no permissions and no host permissions, which is the first thing worth noting: nothing in the manifest asks for filesystem or process privileges.
The code findings all point at one file, jtools-background/lib/kotlin-stdlib-1.9.21.jar. Three YARA rules fired against that JAR: postinstall_crypto_operations, postinstall_obfuscation, and postinstall_network_communication. That JAR is the Kotlin standard library, a bundled dependency, and those three rules match any Kotlin or Java archive that contains crypto constants, compression tables, and HTTP client classes. A standard library is going to contain all three. None of the matches are in code the extension author wrote, and the postinstall prefix is misleading here because a JAR embedded in a plugin does not run at install time.
There are no credential-access findings. Nothing reads .env files, .git/config, SSH keys, or cloud credential stores. The secrets category is empty, and the filesystem findings are limited to the bundled library. For a tool whose job is to run something in the background of an IDE, that is the scope you would expect.
The nine XIOC domain entries are the other noise source. They read zl0t.bm, 2ļ.ky, wrx.gf, 3u.id, i.kg, k.qa, ߩ.st, q7ɖ.lv, and pom.properties. Those are not endpoints. Two contain non-Latin characters, one contains ߩ, and pom.properties is a Maven build file rather than a hostname. Short strings that look like hostnames get pulled out of compiled bytecode constantly, and this list is that failure mode. i.kg and k.qa are a single letter plus a country TLD, which is what a property access chain or a byte sequence looks like to the extractor. None of them appear in a network call, and the network category is empty.
The strongest counterargument is the publisher identity and the freshness. The developer is recorded only as a UUID, the version is 0.0.2, and 86 downloads is a profile that typosquats share. That is a reason to look twice, and it is why this review is not a clean statement about reputation. Reputation is not the same as capability, and the capability evidence here is empty: no malware signature, no exfiltration path, no credential read, no injected process. A low-profile plugin with no permissions and only standard-library noise behind it does not add up to harmful behavior.
Key Reasons
- All three code-smell hits are postinstall YARA rules matching the bundled kotlin-stdlib-1.9.21.jar, a standard library rather than extension code.
- The nine XIOC domain entries are extractor fragments, including non-Latin characters (2ļ.ky, q7ɖ.lv, ߩ.st) and the Maven filename pom.properties.
- No malware, credential, secret, obfuscation, manifest, or network findings appear anywhere in the bundle.
- The plugin declares no permissions and no host permissions, so it requests no filesystem or process privileges.
False Positive Considerations
- YARA postinstall_crypto_operations, postinstall_obfuscation, and postinstall_network_communication matching a bundled kotlin-stdlib-1.9.21.jar
- XIOC domain extraction producing bytecode fragments like i.kg, k.qa, and the Maven filename pom.properties
- Non-Latin characters (ļ, ɖ, ߩ) inside extracted domain strings
- Nine IoC hits generated from a single bundled dependency rather than extension code
Reviewed 2026-09-29; recommended action: suppress false positive; model confidence 85%.
About This Extension
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace
JTools
8349aa96-e390-43d3-9aaf-5572ea8a8593
JTools HTTP Client
8349aa96-e390-43d3-9aaf-5572ea8a8593
JTools SSH Publisher
8349aa96-e390-43d3-9aaf-5572ea8a8593
Jtools-Mybatis-Log
8349aa96-e390-43d3-9aaf-5572ea8a8593
DotVVM
keeper7
CodeScan
CodeScan