The AI review rates the findings as likely false positive, but the risk score (65/100) still counts them.
Analysis record
- Analysed
- 5 days ago
- Version
- v6.8.0
- Artifact
- SHA256 129…DE0
- Source
- Findings (non-IoC)
No Findings
All security checks passed
Publisher Evidence
LowIBM
Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.
12 evidence rows available.
No Threats Detected
This extension passed all security checks
AI Security Report
AI Security Review
Evidence context: threat category none; evidence quality strong.
The zopeneditor extension from IBM provides language server support for COBOL, PL/I, HLASM, and REXX development on IBM Z systems. The extension declares no special permissions or host permissions in its manifest, relying on standard VS Code extension APIs for workspace access and language server management.
The four critical obfuscation findings all target native Node.js addon files in extension/prebuilds/keyring.*.node across Darwin, Linux, and Windows platforms. These are compiled binary modules for the @electron/keyring package, which provides secure credential storage integration with the operating system's keychain. Compiled native addons naturally appear as opaque binary data to static analysis, triggering false positives for obfuscation detection. This is expected behavior for any extension using native modules for secure storage.
The 2,350 medium-severity IoC findings originate from network_endpoints entries like "0-.mp", "0n.fk", "1e.gl" — fragments that resemble hex substrings or minified identifier artifacts rather than valid domains. The IoC extractor regularly misidentifies such patterns from bundled JavaScript as indicators of compromise. No actual network connections to suspicious infrastructure appear in the findings.
The 462 low-severity code-smell findings stem from YARA rules matching common Node.js patterns (fetch, exec, fs, crypto, process.env) across the extension's bundled dependencies. These rules fire broadly on legitimate code and carry no malicious signal.
No findings indicate postinstall payload execution, credential theft from .env or SSH keys, source code exfiltration, or supply chain poisoning. The extension's filesystem and process access aligns with its stated purpose: language servers require reading workspace files, spawning compiler processes, and potentially accessing mainframe credentials through the keyring integration.
Strongest counterargument: the critical severity labels on native binary files could suggest intentional obfuscation. This fails because the files are platform-specific builds of a well-known open source keyring module, distributed as prebuilt binaries to avoid requiring a C++ toolchain on user machines. The detection reflects analyzer limitations, not publisher intent.
Key Reasons
- Verified publisher (IBM) with 95k+ users on OpenVSX
- Critical obfuscation findings are legitimate native keyring binaries
- IoC findings are extractor artifacts from minified JavaScript
- Code-smell findings are known YARA noise on bundled dependencies
- No evidence of postinstall payloads, credential theft, or exfiltration
False Positive Considerations
- OBFUSCATION-NATIVE_BINARY_ADDON on legitimate compiled Node.js keyring addons
- IoC extractor garbage domains from minified/bundled JavaScript
- YARA code-smell rules firing on standard Node.js patterns
- Bundled dependencies multiplicative false positives
Reviewed 2026-09-26; recommended action: suppress false positive; model confidence 95%.
Open VSX version history
Risk trend by version
2 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.
Pick any point on the chart to explore that version's code below.
Source Code Not Available
Source code is not available for this version of the extension.
About This Extension
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace