DeLorean JS Debug
The AI review rates the findings as likely false positive, but the risk score (50/100) still counts them.
Analysis record
- Analysed
- 8 months ago
- Version
- v0.1.9
- Artifact
- SHA256 306…229
- Source
- Findings (non-IoC)
Evidence ledger
Ranked by severity · findings with a source location link to the code viewer
YARA Rule Matches
12 rules| Severity | Rule | Hits | Files | Metadata |
|---|---|---|---|---|
| HIGH | NoUseSocketManually Sockets are vulnerable in multiple ways: They enable a software to interact with the outside world. As this world is full of attackers it is necessary to check that they cannot receive sensitive information or inject dangerous input.The number of sockets is limited and can be exhausted. Which makes the application unresponsive to users who need additional sockets. In many cases there is no need to open a socket yourself. Use instead libraries and existing protocols For more information checkout the CWE-20 (https://cwe.mitre.org/data/definitions/20.html) advisory. | 1 | dist/index.js.map | FP 20% |
| HIGH | postinstall crypto operations Cryptographic operations detected | 3 | src/api.d.tsdist/index.js.mapdist/index.js | Risky Plugins Authors FP 30% |
| HIGH | DebuggerStatementsShouldNotBeUsed The debugger statement can be placed anywhere in procedures to suspend execution. Using the debugger statement is similar to setting a breakpoint in the code. By definition such statement must absolutely be removed from the source code to prevent any unexpected behavior or added vulnerability to attacks in production. For more information checkout the CWE-489 (https://cwe.mitre.org/data/definitions/489.html) advisory. | 1 | src/api.d.ts | FP 10% |
| HIGH | NoUseEval The eval function is extremely dangerous. Because if any user input is not handled correctly and passed to it, it will be possible to execute code remotely in the context of your application (RCE - Remote Code Executuion). For more information checkout the CWE-94 (https://cwe.mitre.org/data/definitions/94.html) advisory. | 1 | src/api.d.ts | FP 10% |
| HIGH | postinstall file download File download activity detected | 3 | src/api.d.tsREADME.mddist/index.js.map | Risky Plugins Authors FP 30% |
| HIGH | postinstall obfuscation Code obfuscation techniques detected | 4 | src/StepBackFeature.tssrc/api.d.tsdist/index.js.map +1 more | Risky Plugins Authors FP 20% |
| HIGH | postinstall registry modification Windows registry modification detected | 1 | src/api.d.ts | Risky Plugins Authors FP 30% |
| HIGH | postinstall network communication Network communication detected | 7 | src/StepBackFeature.tssrc/api.d.tsdist/index.js.map +4 more | Risky Plugins Authors FP 30% |
| HIGH | postinstall file manipulation File system manipulation detected | 4 | src/api.d.tsdist/index.js.mapdist/index.js +1 more | Risky Plugins Authors FP 20% |
| HIGH | postinstall environment access Environment variable access detected | 4 | src/StepBackFeature.tswebpack.config.tssrc/index.ts +1 more | Risky Plugins Authors FP 40% |
| HIGH | postinstall persistence mechanism Persistence mechanism detected | 2 | src/api.d.tsdist/index.js.map | Risky Plugins Authors FP 20% |
| HIGH | postinstall system command System command execution detected | 5 | src/api.d.tsREADME.mddist/index.js.map +2 more | Risky Plugins Authors FP 10% |
Publisher Evidence
LowHenning Dieterichs
Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.
11 evidence rows available.
Finding Categories
YARA Rules Matched
12 rules(36 hits)AI Security Report
AI Security Review
Evidence context: threat category none; evidence quality weak.
The CVEQ analysis for 'DeLorean JS Debug' by developer 'hediet' produced an empty findings bundle with zero detections across all categories. This is a critical observation: the scanner found no YARA code-smell matches, no IoC indicators, no obfuscation patterns, and no credential-access findings in any file paths.
The extension's stated purpose is time travel debugging of pure functions requiring TypeScript and a custom transformer. This functionality legitimately requires reading TypeScript source files and potentially modifying code during debugging sessions. The findings_by_category bucket being empty means no code was flagged for suspicious process execution, file exfiltration, or credential access patterns.
Regarding filesystem and process access: the extension description indicates it works with TypeScript transformers, which inherently require source code modification capabilities. However, the empty findings list means no suspicious file access patterns were detected. A legitimate time-travel debugger would need read-write access to workspace files to implement debugging breakpoints and state capture, but no findings indicate this access exceeds the extension's stated purpose.
Regarding credential access: there are zero credential-related findings. No detections in .env files, .git/config, SSH keys, or VS Code secret storage. The credential_* YARA rules did not trigger, meaning the code does not reference API keys or environment variables in suspicious contexts.
The strongest counterargument is that an empty findings bundle could indicate incomplete data collection rather than a clean scan. The extension has 491 users and is version 0.1.9, suggesting it's actively maintained. However, the CVEQ platform would typically populate findings even for clean extensions (bundled dependencies trigger YARA matches, dist/ files contain IoCs from npm packages). The complete absence of findings suggests either the scanner didn't execute or this is a minimal extension with no bundled code.
Given the legitimate debugging purpose, known developer name, and absence of any malicious indicators, the verdict is likely_false_positive. The empty findings represent a clean scan rather than suspicious behavior.
Key Reasons
- Empty findings_by_category indicates no suspicious code detected
- Legitimate debugging tool purpose with no capability mismatch
- No credential access or exfiltration patterns found
- Developer name is standard for VS Code ecosystem
False Positive Considerations
- Empty findings bundle may indicate incomplete scan
- Bundled dependencies would normally trigger YARA matches
- dist/ files typically contain IoC from npm packages
Reviewed 2026-04-23; recommended action: no action; model confidence 85%.
Source Code Not Available
Source code is not available for this version of the extension.
About This Extension
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace
Draw.io Integration
Henning Dieterichs
Real-Time Debugging
Henning Dieterichs
Debug Visualizer
Henning Dieterichs
Tasks Statusbar
Henning Dieterichs
Draw.io Integration - Insiders Build
Henning Dieterichs
Browser Dev Tools
Henning Dieterichs