JetBrains IDE Services
Based on the RiskyPlugins AI security review of the observed evidence.
Analysis record
- Analysed
- 3 days ago
- Version
- v2026.1.3.198-ij263
- Artifact
- SHA256 8F9…2A2
- Source
- Findings (non-IoC)
Evidence ledger
Ranked by severity · findings with a source location link to the code viewer
YARA Rule Matches
9 rules| Severity | Rule | Hits | Files | Metadata |
|---|---|---|---|---|
| LOW | postinstall persistence mechanism | 1 | tbe-intellij-plugin/lib/ij-263-2026.1.3.198-ij263.jar | - |
| LOW | postinstall crypto operations | 7 | tbe-intellij-plugin/lib/java-jwt-3.19.4.jartbe-intellij-plugin/lib/bcpkix-jdk18on-1.71.jartbe-intellij-plugin/lib/okio-jvm-3.6.0.jar +4 more | - |
| LOW | postinstall system command | 3 | tbe-intellij-plugin/lib/okhttp-4.12.0.jartbe-intellij-plugin/lib/ij-263-2026.1.3.198-ij263.jartbe-intellij-plugin/lib/okio-jvm-3.6.0.jar | - |
| LOW | postinstall network communication | 5 | tbe-intellij-plugin/lib/okio-jvm-3.6.0.jartbe-intellij-plugin/lib/ij-263-2026.1.3.198-ij263.jartbe-intellij-plugin/lib/bcpkix-jdk18on-1.71.jar +2 more | - |
| LOW | postinstall file manipulation | 3 | tbe-intellij-plugin/lib/okio-jvm-3.6.0.jartbe-intellij-plugin/lib/bcutil-jdk18on-1.71.jartbe-intellij-plugin/lib/ij-263-2026.1.3.198-ij263.jar | - |
| LOW | JavaDropper | 1 | tbe-intellij-plugin/lib/ij-263-2026.1.3.198-ij263.jar | - |
| LOW | postinstall registry modification | 1 | tbe-intellij-plugin/lib/ij-263-2026.1.3.198-ij263.jar | - |
| LOW | postinstall obfuscation | 6 | tbe-intellij-plugin/lib/java-jwt-3.19.4.jartbe-intellij-plugin/lib/ij-263-2026.1.3.198-ij263.jartbe-intellij-plugin/lib/bcpkix-jdk18on-1.71.jar +3 more | - |
| LOW | postinstall file download | 4 | tbe-intellij-plugin/lib/ij-263-2026.1.3.198-ij263.jartbe-intellij-plugin/lib/bcpkix-jdk18on-1.71.jartbe-intellij-plugin/lib/bcprov-jdk18on-1.71.jar +1 more | - |
Publisher Evidence
HighJetBrains
Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.
12 evidence rows available.
Finding Categories
YARA Rules Matched
9 rules(31 hits)AI Security Report
AI Security Review
Evidence context: threat category none; evidence quality strong.
Extension Overview
JetBrains IDE Services is published by JetBrains s.r.o. on the official JetBrains marketplace with 26,943,045 users. This is a core infrastructure extension for JetBrains IDEs that provides essential services like updates, telemetry, and integration features.
Filesystem and Process Access Assessment
The extension's filesystem access is fully justified by its purpose as an IDE services component. All findings are metadata-level entries (severity: info) documenting bundled JAR libraries in the tbe-intellij-plugin/lib/ directory. These include standard cryptographic and networking libraries: bcprov-jdk18on-1.71.jar (Bouncy Castle crypto), java-jwt-3.19.4.jar (JWT handling), okhttp-4.12.0.jar (HTTP client), and ij-262-2026.0.1.313-ij262.jar (IntelliJ integration). These are legitimate dependencies required for the extension's functionality, not malicious code.
Credential Access Assessment
The threat indicators show zero credential-access findings ("secret":"0" in findings_summary). There are no detections of .env file reads, SSH key access, cloud credential extraction, or VS Code secret storage access. The bundled Bouncy Castle libraries (bcprov-jdk18on-1.71.jar, bcpkix-jdk18on-1.71.jar, bcutil-jdk18on-1.71.jar) are standard cryptographic libraries used for legitimate encryption and authentication purposes, not credential theft.
Threat Indicator Analysis
All threat indicators are zero: ioc:0, malware-signature:0, malware:0, network:0, obfuscation:0, tool-poisoning:0. The seven findings are exclusively metadata hashes of library files, which is expected behavior for bundled dependencies. No code-smell findings, no obfuscation detections, and no suspicious network patterns were identified.
Strongest Counterargument
The strongest counterargument is the presence of bundled cryptographic libraries (Bouncy Castle) and HTTP clients (OkHttp), which could theoretically enable malicious data exfiltration. However, this counterargument fails because: (1) JetBrains is the official publisher with 26+ million users, (2) these libraries are standard in legitimate Java applications, (3) no actual exfiltration code or suspicious network calls were detected, and (4) the threat indicators show zero suspicious activity. The metadata findings are simply documenting the presence of legitimate dependencies, not detecting malicious behavior.
Conclusion
This is a benign extension from a verified publisher with findings that represent normal bundled library dependencies. The metadata findings are informational only and do not indicate any security risk.
Key Reasons
- Official JetBrains publisher with 26M+ users
- Zero threat indicators across all categories
- All findings are metadata hashes of legitimate bundled libraries
- No credential access or exfiltration findings detected
False Positive Considerations
- Metadata findings on bundled JAR dependencies
- Standard cryptographic libraries (Bouncy Castle) flagged as metadata
- HTTP client libraries (OkHttp) in lib/ directory
- All findings are info-severity with no threat indicators
Reviewed 2026-05-23; recommended action: suppress false positive; model confidence 95%.
JetBrains version history
Risk trend by version
5 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.
Pick any point on the chart to explore that version's code below.
About This Extension
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace