Jtools-Mybatis-Log
Based on the RiskyPlugins AI security review of the observed evidence.
Analysis record
- Analysed
- Today
- Version
- v1.1.3
- Artifact
- SHA256 F06…87C
- Source
- Findings (non-IoC)
Evidence ledger
Ranked by severity · findings with a source location link to the code viewer
Publisher Evidence
Limited evidence8349aa96-e390-43d3-9aaf-5572ea8a8593
Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.
12 evidence rows available.
Finding Categories
AI Security Report
AI Security Review
Evidence context: threat category none; evidence quality moderate.
The Jtools-Mybatis-Log extension is a JetBrains IDE plugin for MyBatis SQL logging with 998 users. The filesystem access pattern is justified by the extension's stated purpose: a MyBatis logging tool legitimately reads SQL log files, configuration files, and Java source code to display query information in the IDE.
Filesystem/Process Access Analysis: No manifest-analysis findings indicate the extension's declared permissions. The 5 code-smell findings (severity=low) are expected for any non-trivial JavaScript codebase and do not indicate malicious behavior. These match the documented false-positive pattern where code-smell rules fire on standard Node.js patterns. There are zero malware-signature findings and zero malware findings, which would be required to establish malicious postinstall payload execution or unauthorized process spawning.
Credential Access Analysis: The findings_summary shows zero secret findings. No credential-access findings target actual secrets like .env files, .ssh directories, cloud credentials, or VS Code secret storage. The extension does not request or access sensitive developer credentials beyond what a logging tool requires for its legitimate function.
IOC Finding Analysis:
All 33 IOC findings are XIOC-DOMAIN type with property access chains misread as domains. Examples include "v.gb", "j.ni", "0.us", "i.pt", "2.so", and "8.si" - these are classic false positives where the XIOC extractor misinterprets JavaScript property access patterns (e.g., v.gb as v.gb property access, not a domain). The file_path for all IOCs is "extracted_from_files", indicating extraction from minified/bundled JavaScript rather than specific source files. Two findings contain Unicode characters ("ߩ.st", "q7ɖ.lv") which further suggests parsing artifacts from minified code, not actual domain strings.
Strongest Counterargument: The 33 medium-severity IOC findings could suggest suspicious network activity. However, these are definitively XIOC false positives following the documented pattern where property access chains in minified JavaScript are misread as domain names. The absence of any actual network findings, malware signatures, or credential access findings confirms these IOCs are noise. A malicious extension would show at least one of: postinstall payload execution, credential theft patterns, or obfuscation - none of which appear in the evidence.
Conclusion: This extension exhibits the classic false-positive pattern: high IOC count from XIOC noise, code-smell findings from bundled/minified code, and zero actual malicious indicators. The extension serves a legitimate development purpose (MyBatis SQL logging) and shows no evidence of malicious intent.
Key Reasons
- All 33 IOC findings are XIOC false positives - property access chains masquerading as domains
- Zero malware signatures or actual malicious indicators
- No credential access findings targeting secrets
- Code-smell findings are expected noise for bundled code
- Extension purpose (MyBatis logging) is legitimate development tool
False Positive Considerations
- XIOC-DOMAIN findings are property access chains misread as domains (e.g., v.gb, j.ni, 0.us)
- All IOCs extracted from minified/bundled files with generic extracted_from_files path
- Code-smell findings (5 total) are expected for any non-trivial JavaScript
- Zero malware, credential access, or obfuscation findings
Reviewed 2026-04-28; recommended action: suppress false positive; model confidence 85%.
JetBrains version history
Risk trend by version
4 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.
Pick any point on the chart to explore that version's code below.
About This Extension
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace
JTools
8349aa96-e390-43d3-9aaf-5572ea8a8593
JTools HTTP Client
8349aa96-e390-43d3-9aaf-5572ea8a8593
JTools SSH Publisher
8349aa96-e390-43d3-9aaf-5572ea8a8593
JTools-Background
8349aa96-e390-43d3-9aaf-5572ea8a8593
DotVVM
keeper7
CodeScan
CodeScan