GPU Dev Accelerator Ultimate
From the RiskyPlugins AI security review of the observed evidence.
Analysis record
- Analysed
- 6 days ago
- Version
- v2026.5.0
- Artifact
- SHA256 AE7…A34
- Source
- Findings (non-IoC)
Evidence ledger
Ranked by severity · findings with a source location link to the code viewer
YARA Rule Matches
4 rules| Severity | Rule | Hits | Files | Metadata |
|---|---|---|---|---|
| LOW | postinstall obfuscation | 1 | gpu-dev-accelerator-ultimate/lib/Java-WebSocket-1.5.4.jar | - |
| LOW | postinstall network communication | 1 | gpu-dev-accelerator-ultimate/lib/Java-WebSocket-1.5.4.jar | - |
| LOW | postinstall system command | 2 | gpu-dev-accelerator-ultimate/lib/instrumented-gpu-dev-accelerator-ultimate-2026.5.0.jargpu-dev-accelerator-ultimate/lib/slf4j-api-2.0.6.jar | - |
| LOW | DebuggerStatementsShouldNotBeUsed | 1 | gpu-dev-accelerator-ultimate/lib/instrumented-gpu-dev-accelerator-ultimate-2026.5.0.jar | - |
Network Indicators
Concrete URLs, domains, IPs, emails, and hashes extracted from the analyzed artifact.
Network indicators are queued for lazy loading
Scroll this section into view to load the detailed rows.
Publisher Evidence
Lowjakub-jirak
Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.
12 evidence rows available.
Finding Categories
YARA Rules Matched
4 rules(5 hits)AI Security Report
AI Security Review
Evidence context: threat category none; evidence quality weak.
This analysis evaluates the 'GPU Dev Accelerator Ultimate' plugin for the JetBrains IDE. The evidence bundle provided contains no specific security findings (IoCs, YARA hits, or code-smell violations), preventing a dynamic code assessment.
Based on the naming convention and the JetBrains platform context, this is likely a developer tool designed to utilize local GPU hardware for accelerating IDE operations or background build processes. Such tools legitimately require deep system integration (filesystem access, process execution) to function correctly, which fits the 'benign_but_powerful' profile.
Without access to the specific version or code bundle, a 'confirmed_malicious' verdict cannot be supported. The primary risk factor is the low user count (743), which suggests it is not a widely vetted industry standard tool. However, absent any indicators of data exfiltration, credential theft, or suspicious postinstall payloads in the provided evidence, it is treated as a standard, albeit niche, utility. The developer is identified as 'Jakub Jirák' via the store metadata, which provides a level of accountability compared to pseudonymous publishing.
Key Reasons
- No security findings or IoCs detected in the provided bundle
- Extension behavior consistent with development acceleration utilities
- Named publisher attribution (Jakub Jirák) on the JetBrains Marketplace
False Positive Considerations
- Standard IDE utility permissions may appear as excessive capability in automated scans
- Process execution for acceleration can be flagged as suspicious without context
Reviewed 2026-04-14; recommended action: no action; model confidence 55%.
JetBrains version history
Risk trend by version
2 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.
Pick any point on the chart to explore that version's code below.
About This Extension
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace
README Diagrams - Mermaid and Structurizr Preview
jakub-jirak
Technical Debt Accountant
jakub-jirak
ADR Companion
jakub-jirak
Intel DPC++ Support
jakub-jirak
Run Config Drift Detector
jakub-jirak
Kei - API Contract Testing
jakub-jirak