VS Code Marketplace Verified

Jupyter

by Microsoft · 109.6M users · 2.6 rating
2098c015-4ba5-58ba-a964-0f7247497c31 | v2026.6.2026071501
56/ 100
MEDIUM risk
+5 since v2026.6.2026071001
Analyst verdict
Benign but powerful

From the RiskyPlugins AI security review of the observed evidence.

Analysis record

Analysed
2 weeks ago
Version
v2026.6.2026071501
Artifact
SHA256 43F…7DB
Source
Findings (non-IoC)

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

357 detail rows
Showing 25 of 70 · highest severity first

YARA Rule Matches

17 rules
SeverityRuleHitsFilesMetadata
LOWcredential env files 9
changelog.mdpythonFiles/printJupyWidgetEntryPoints.pypythonFiles/vscode_datascience_helpers/kernel/addRunCellHook.py +6 more
-
LOWpostinstall persistence mechanism 37
package.nls.pt-br.jsondist/webviews/webview-side/ipywidgetsKernel/ipywidgetsKernel.jsl10n/bundle.l10n.ko.json +34 more
-
LOWpackage json suspicious scripts 1
package.json
-
LOWpostinstall file manipulation 46
dist/webviews/webview-side/viewers/variableView.jspackage.nls.ru.jsondist/webviews/webview-side/viewers/plotViewer.js +43 more
-
LOWpostinstall network communication 48
l10n/bundle.l10n.it.jsonpackage.nls.ru.jsonl10n/bundle.l10n.tr.json +45 more
-
LOWpostinstall crypto operations 11
dist/webviews/webview-side/viewers/variableView.jsresources/MagicPython.tmLanguage.jsondist/extension.node.js +8 more
-
LOWpostinstall system command 49
l10n/bundle.l10n.it.jsonpackage.nls.ru.jsonl10n/bundle.l10n.tr.json +46 more
-
LOWpostinstall environment access 3
pythonFiles/install_debugpy.pyThirdPartyNotices.txtCodeQL.yml
-
LOWpostinstall registry modification 4
dist/extension.node.jsdist/webviews/webview-side/ipywidgetsKernel/ipywidgetsKernel.jsThirdPartyNotices.txt +1 more
-
LOWpostinstall obfuscation 17
pythonFiles/get-pip.pydist/webviews/webview-side/viewers/dataExplorer.jspythonFiles/vscode_datascience_helpers/getJupyterVariableShape.py +14 more
-
LOWOriginsNotVerified 1
dist/extension.node.js
-
LOWUsingShellInterpreterWhenExecutingOSCommands 1
dist/extension.node.js
-
LOWDebuggerStatementsShouldNotBeUsed 21
package.nls.es.jsonpackage.nls.ja.jsonpackage.nls.cs.json +18 more
-
LOWUsingCommandLineArguments 1
dist/extension.node.js
-
LOWNoUseWeakRandom 5
dist/webviews/webview-side/viewers/dataExplorer.jsdist/webviews/webview-side/ipywidgetsKernel/ipywidgetsKernel.jsdist/webviews/webview-side/viewers/variableView.js +2 more
-
LOWNoUseEval 3
dist/webviews/webview-side/viewers/dataExplorer.jsdist/extension.node.proxy.jsdist/webviews/webview-side/ipywidgetsKernel/ipywidgetsKernel.js
-
LOWpostinstall file download 30
dist/webviews/webview-side/ipywidgetsKernel/ipywidgetsKernel.jsl10n/bundle.l10n.ko.jsondist/webviews/webview-side/viewers/dataExplorer.js +27 more
-

Publisher Evidence

High

Microsoft

Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.

100
Noisy-finding weight
x0.50
Publisher domain
microsoft.com
Trusted match
Store verification signal
Verified publisher
Verified
Extension portfolio
653
Portfolio

11 evidence rows available.

Finding Categories

9
Network

YARA Rules Matched

17 rules(287 hits)
credential env files postinstall persistence mechanism package json suspicious scripts postinstall file manipulation postinstall network communication postinstall crypto operations postinstall system command postinstall environment access postinstall registry modification postinstall obfuscation OriginsNotVerified UsingShellInterpreterWhenExecutingOSCommands DebuggerStatementsShouldNotBeUsed UsingCommandLineArguments NoUseWeakRandom NoUseEval +1 more

AI Security Report

AI Security Review

Evidence context: threat category none; evidence quality strong.

The Jupyter extension, developed by ms-toolsai, provides Jupyter notebook support and interactive programming features. The extension's package.json file lists dependencies such as portfinder, svg-to-pdfkit, and @enonic/fnv-plus, which are used for various tasks like port allocation and PDF generation. Network calls detected in the extension's code, including fetch and socket_io calls, are primarily used for telemetry and communication with Jupyter services. The extension's purpose justifies its filesystem and process access. Credential-access findings do not target actual secrets, and the strongest counterargument to the verdict is that the extension's dependencies and network calls could be misused. However, the extension's code and dependencies are consistent with its stated purpose, and there is no evidence of malicious behavior. The extension is from a verified publisher on the marketplace, which adds to its credibility.

Key Reasons

  • The extension's dependencies and network calls are justified by its purpose.
  • The extension is from a verified publisher on the marketplace.
  • There is no evidence of malicious behavior or credential theft.

Reviewed 2026-05-23; recommended action: no action; model confidence 80%.

VS Code version history

Risk trend by version

13 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.

Selected
56
Change since first
No change
Change from previous
+5
Versions:
First analyzed version
2025.10.2026010601
Jan 19, 2026
Risk range
51 to 56
Across analyzed versions
Latest analyzed version
2026.6.2026071501
Jul 17, 2026
Selected version
medium
Version
v2026.6.2026071501
2 months ago
Risk score
56
Findings
357
Change vs previous
+5

Pick any point on the chart to explore that version's code below.

About This Extension

Jupyter notebook support, interactive programming and computing that supports Intellisense, debugging and more.

Frequently Asked Questions