OpenVSX Registry Verified

IBM Z Open Editor

by IBM
284317db-a14b-58aa-96fa-fd8e72295f8e | v6.8.0
65/ 100
MEDIUM risk
No change since v6.7.1
Analyst verdict
Review before use

The AI review rates the findings as likely false positive, but the risk score (65/100) still counts them.

Analysis record

Analysed
5 days ago
Version
v6.8.0
Artifact
SHA256 129…DE0
Source
Findings (non-IoC)

No Findings

All security checks passed

Publisher Evidence

Low

IBM

Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.

55
Noisy-finding weight
x1.00
Publisher domain
No domain
Missing
Store verification signal
Verified publisher
Verified
Extension portfolio
4
Portfolio

12 evidence rows available.

No Threats Detected

This extension passed all security checks

AI Security Report

AI Security Review

Evidence context: threat category none; evidence quality strong.

The zopeneditor extension from IBM provides language server support for COBOL, PL/I, HLASM, and REXX development on IBM Z systems. The extension declares no special permissions or host permissions in its manifest, relying on standard VS Code extension APIs for workspace access and language server management.

The four critical obfuscation findings all target native Node.js addon files in extension/prebuilds/keyring.*.node across Darwin, Linux, and Windows platforms. These are compiled binary modules for the @electron/keyring package, which provides secure credential storage integration with the operating system's keychain. Compiled native addons naturally appear as opaque binary data to static analysis, triggering false positives for obfuscation detection. This is expected behavior for any extension using native modules for secure storage.

The 2,350 medium-severity IoC findings originate from network_endpoints entries like "0-.mp", "0n.fk", "1e.gl" — fragments that resemble hex substrings or minified identifier artifacts rather than valid domains. The IoC extractor regularly misidentifies such patterns from bundled JavaScript as indicators of compromise. No actual network connections to suspicious infrastructure appear in the findings.

The 462 low-severity code-smell findings stem from YARA rules matching common Node.js patterns (fetch, exec, fs, crypto, process.env) across the extension's bundled dependencies. These rules fire broadly on legitimate code and carry no malicious signal.

No findings indicate postinstall payload execution, credential theft from .env or SSH keys, source code exfiltration, or supply chain poisoning. The extension's filesystem and process access aligns with its stated purpose: language servers require reading workspace files, spawning compiler processes, and potentially accessing mainframe credentials through the keyring integration.

Strongest counterargument: the critical severity labels on native binary files could suggest intentional obfuscation. This fails because the files are platform-specific builds of a well-known open source keyring module, distributed as prebuilt binaries to avoid requiring a C++ toolchain on user machines. The detection reflects analyzer limitations, not publisher intent.

Key Reasons

  • Verified publisher (IBM) with 95k+ users on OpenVSX
  • Critical obfuscation findings are legitimate native keyring binaries
  • IoC findings are extractor artifacts from minified JavaScript
  • Code-smell findings are known YARA noise on bundled dependencies
  • No evidence of postinstall payloads, credential theft, or exfiltration

False Positive Considerations

  • OBFUSCATION-NATIVE_BINARY_ADDON on legitimate compiled Node.js keyring addons
  • IoC extractor garbage domains from minified/bundled JavaScript
  • YARA code-smell rules firing on standard Node.js patterns
  • Bundled dependencies multiplicative false positives

Reviewed 2026-09-26; recommended action: suppress false positive; model confidence 95%.

Open VSX version history

Risk trend by version

2 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.

Selected
65
Change since first
No change
Change from previous
No change
Versions:
First analyzed version
6.7.1
Sep 12, 2026
Risk range
65 to 65
Across analyzed versions
Latest analyzed version
6.8.0
Sep 26, 2026
Selected version
medium
Version
v6.8.0
5 days ago
Risk score
65
Findings
2863
Change vs previous
No change

Pick any point on the chart to explore that version's code below.

About This Extension

Provides COBOL, PL/I, HLASM, and REXX language servers, as well as tools for IBM Z development.

Frequently Asked Questions