JetBrains Marketplace Verified

UnitTestBot

by 278357cd-e42c-45cb-a88a-b33ca4650a19 · 11.8K users · 4.6 rating
4e3f719d-4ec8-58b7-9846-90366a3ee529 | v2023.10
71/ 100
HIGH risk
Analyst verdict
Review before use

The AI review rates the findings as likely false positive, but the risk score (71/100) still counts them.

Analysis record

Analysed
3 days ago
Version
v2023.10
Artifact
SHA256 345…332
Source
Findings (non-IoC)

Is UnitTestBot safe?

UnitTestBot generates unit tests for Java and Kotlin code inside JetBrains IDEs, and about twelve thousand developers have installed it from the JetBrains Marketplace. JetBrains plugins declare their capabilities in plugin.xml instead of Chrome-style permission strings, and this one requests none of the special entries we track. The endpoint list our extractor produced includes entries such as 0x.is, 1a.ci and 0-.sy, which look alarming until you count the characters. Every one runs two or three letters long. The scanner scrapes those fragments out of binary JAR contents, and no genuine server address in the plugin points anywhere.

One malware signature fired. A rule called YARA--CAP_HookExKeylogger matched inside lib/jna-platform-5.5.0.jar, the Java Native Access library that ships with huge numbers of desktop Java applications. That library maps Windows API calls such as SetWindowsHookEx into Java, and any keyboard-hook rule will light up on those bindings. Nothing in UnitTestBot uses them to capture keystrokes.

The rest of the hits break down into a few hundred code-quality matches and roughly two thousand of those two-letter endpoint fragments, all landing on bundled third-party JAR files. The scanner tripped on a well-known dependency and on its own text parser, not on any behavior of UnitTestBot's own code. Generating tests requires reading your source tree and writing test files alongside it, which this plugin does and nothing more.

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

146 detail rows
Showing 25 of 145 · highest severity first

YARA Rule Matches

1 rule
SeverityRuleHitsFilesMetadata
HIGHCAP HookExKeylogger 1
utbot-intellij/lib/jna-platform-5.5.0.jar
Brian C. Bell -- @biebsmalwareguy FP 5%

Publisher Evidence

Limited evidence

278357cd-e42c-45cb-a88a-b33ca4650a19

Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.

43
Noisy-finding weight
x1.00
Publisher domain
utbot.org
Observed
Store verification signal
Not exposed
Not exposed
Extension portfolio
2
Portfolio

12 evidence rows available.

Finding Categories

1
Malware Signatures

YARA Rules Matched

1 rule
CAP HookExKeylogger

AI Security Report

AI Security Review

Evidence context: threat category none; evidence quality moderate.

UnitTestBot ships for JetBrains IDEs at version 2023.10 and 11,833 developers have installed it. A unit test generator reads a source tree and writes generated test files beside it, so workspace read and write access follows directly from the product. Every source path in the findings points at utbot-intellij, the plugin's own directory.

The one high-severity match is a YARA rule, YARA--CAP_HookExKeylogger, landing at utbot-intellij/lib/jna-platform-5.5.0.jar:11348. That JAR is JNA Platform, the standard Java library that exposes native operating system APIs to JVM code. Its Windows bindings declare SetWindowsHookEx, KBDLLHOOKSTRUCT and the other structures a keyboard-hook rule keys on, so a rule written to catch keyloggers matches the library on sight. JNA Platform ships inside thousands of desktop Java applications, and it sits in the lib/ dependency directory rather than in UnitTestBot's own classes.

No credential findings exist to weigh. Nothing here touches .env files, .ssh keys, .git/config or cloud credential stores, and the secret scanner returned nothing at all. The plugin's manifest declares no host permissions and no special permission strings, which matters on JetBrains because capabilities live in plugin.xml rather than in a Chrome-style permission list.

The bulk of the volume comes from an IoC extractor pointed at bundled binary JARs. Its endpoint output includes 0x.is, 1a.ci, 0b.by and 0-.sy. Those run two or three characters long and read as fragments of constant pools or string tables inside compiled class files rather than as hostnames. A second cluster consists of low-severity code-quality matches covering ordinary Java patterns such as random number use, environment lookups and string manipulation. Neither cluster maps onto a specific behavior in the plugin.

The strongest counterargument is that a keyboard-hook signature fired at all, and that the plugin writes into your repository by design. Both have answers. The hook rule matched a bundled dependency under lib/jna-platform-5.5.0.jar, not code UnitTestBot's authors wrote, and a keylogger hiding in JNA's API bindings would surface in every application that bundles the library. Writing test files is the feature customers install. The absence of manifest-analysis, obfuscation, secret and network findings, alongside a store listing with a real user base, leaves no evidence of intent to harm.

Key Reasons

  • The only high-severity hit is YARA--CAP_HookExKeylogger matching Windows API hook bindings inside the bundled library lib/jna-platform-5.5.0.jar, not UnitTestBot source code
  • The so-called network endpoints are two- and three-character fragments such as 0x.is, 1a.ci and 0-.sy scraped from binary JAR contents by the IoC extractor
  • No secret, credential, obfuscation, network or manifest-analysis findings exist anywhere in the set
  • The plugin declares no host permissions and no special permission strings, and stores capabilities in plugin.xml for a JetBrains listing with 11,833 users
  • Remaining volume consists of low-severity code-quality matches on ordinary Java patterns like randomness and string handling

False Positive Considerations

  • IoC extractor misread hex and constant-pool fragments from binary JARs as network endpoints
  • Reclassified malware family rule CAP_HookExKeylogger matches JNA's legitimate native Windows API bindings
  • Low-severity code-smell rules match generic Java patterns such as randomness and environment lookups
  • Bundled third-party JARs under lib/ multiply finding counts without reflecting plugin behavior

Reviewed 2026-09-30; recommended action: suppress false positive; model confidence 85%.

About This Extension

UnitTestBot is the tool for automated unit test generation and precise code analysis. Discover UnitTestBot key features in our latest release: generating ready-to-use...

Frequently Asked Questions