Big Data Tools Azure
The AI review rates the findings as likely false positive, but the risk score (69/100) still counts them.
Analysis record
- Analysed
- Today
- Version
- v263.6259.39
- Artifact
- SHA256 FB8…E88
- Source
- Findings (non-IoC)
Evidence ledger
Ranked by severity · findings with a source location link to the code viewer
YARA Rule Matches
1 rule| Severity | Rule | Hits | Files | Metadata |
|---|---|---|---|---|
| HIGH | PlugX detect PlugX in memory | 1 | bigdatatools-azure/lib/intellij.libraries.azure.storage.jar | JPCERT/CC Incident Response Group FP 5% |
Publisher Evidence
HighJetBrains
Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.
12 evidence rows available.
Finding Categories
YARA Rules Matched
1 ruleAI Security Report
AI Security Review
Evidence context: threat category none; evidence quality moderate.
The only high-severity finding is a YARA rule hit labeled YARA--PlugX on a file inside the plugin: bigdatatools-azure/lib/com.azure-azure-storage-blob.jar. That path is Microsoft's official Azure Storage Blob client for Java, shipped inside the plugin so it can reach Azure storage accounts without a separate install step. PlugX is a genuine backdoor family, so the label deserves attention, but this rule matches short byte sequences that turn up across large compressed Java archives. A single match sitting inside a vendor SDK, with no supporting evidence anywhere else, is the standard shape of a broad signature landing on bundled build output.
The extension declares no permissions and no network endpoints in what we can inspect, and the wider scan returned zero indicators of compromise, zero flagged destinations, zero obfuscation, and zero secret-access findings. Big Data Tools Azure connects an IDE to Azure Blob Storage and Data Lake, so it browses remote containers, streams files, and writes results back into a project. Reading and writing workspace files is the stated job here, and the process behavior needed to do it is the job too, not a capability bolted on top. Nothing in the file set behaves like an installer that pulls down and runs a second stage.
No finding targets credentials. There is nothing against .env files, .ssh keys, .git/config, or cloud credential stores, and nothing touching the IDE's secret storage or credential providers. The 42 code-smell matches and 6 informational hits are low-severity patterns that fire on ordinary JVM and JavaScript code, and none of them describe reading secrets or moving them off the machine.
The strongest argument against calling this clean is that PlugX is not a noise rule in general. It names a real implant, and a bundled JAR is exactly where a tampered dependency could hide. That argument would carry weight if the match sat on an unnamed archive, or if there were any second signal: an outbound endpoint, a permission request, a download-and-execute step, or a mismatch between the JAR path and its expected Maven coordinate. None of those exist in this scan. The path resolves to com.azure:azure-storage-blob, the naming an unmodified Azure SDK dependency produces, and the surrounding plugin carries no behavior that would use a backdoor. One signature on one library, with zero corroborating findings, points at the scanner rather than the code it read.
Put together: a verified publisher, JetBrains, more than a million installs on the JetBrains Marketplace, no declared permissions, no endpoints, one signature hit on an official Microsoft library, and a long tail of low-severity code smells. The signature is a rule reacting to a bundled dependency.
Key Reasons
- The YARA--PlugX hit sits inside bigdatatools-azure/lib/com.azure-azure-storage-blob.jar, Microsoft's official Azure Storage Blob SDK bundled as a dependency, a known target of broad JAR signature rules.
- Zero ioc, network, obfuscation, secret, dependency, and tool-poisoning findings across the whole scan.
- Published by JetBrains on the JetBrains Marketplace with 1,055,561 users, an official first-party extension.
- All remaining findings are low-severity code smells (42) and informational notes (6), the noise floor of any non-trivial Java project.
- No permissions, host permissions, or network endpoints declared, so there is no capability channel for exfiltration.
False Positive Considerations
- YARA--PlugX is a broad rule matching generic byte patterns that also occur in large compressed Java archives such as the official Azure SDK JAR.
- 42 code-smell findings are low-severity and fire on ordinary JVM and JavaScript code without describing any harmful behavior.
- Bundled third-party libraries inside lib/ produce signature and rule matches unrelated to the plugin's own code.
- Official JetBrains first-party extension on its own marketplace, which contradicts a supply-chain or typosquatting pattern.
Reviewed 2026-10-01; recommended action: suppress false positive; model confidence 90%.
JetBrains version history
Risk trend by version
50 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.
Pick any point on the chart to explore that version's code below.
About This Extension
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace
Gradle
JetBrains
Kotlin Onboarding: Collections
JetBrains
Python Community Edition
JetBrains
Web Browser (JCEF)
JetBrains
Time Tracking Dashboard Widgets
JetBrains
Kotlin Onboarding 2: Object-Oriented Programming
JetBrains