VS Code Marketplace Verified

DeLorean JS Debug

by Henning Dieterichs · 517 users
58c2d0ca-c47f-59ed-94a1-4db54915b133 | v0.1.9
50/ 100
MEDIUM risk
Analyst verdict
Review before use

The AI review rates the findings as likely false positive, but the risk score (50/100) still counts them.

Analysis record

Analysed
8 months ago
Version
v0.1.9
Artifact
SHA256 306…229
Source
Findings (non-IoC)

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

40 detail rows

YARA Rule Matches

12 rules
SeverityRuleHitsFilesMetadata
HIGHNoUseSocketManually

Sockets are vulnerable in multiple ways: They enable a software to interact with the outside world. As this world is full of attackers it is necessary to check that they cannot receive sensitive information or inject dangerous input.The number of sockets is limited and can be exhausted. Which makes the application unresponsive to users who need additional sockets. In many cases there is no need to open a socket yourself. Use instead libraries and existing protocols For more information checkout the CWE-20 (https://cwe.mitre.org/data/definitions/20.html) advisory.

1
dist/index.js.map
FP 20%
HIGHpostinstall crypto operations

Cryptographic operations detected

3
src/api.d.tsdist/index.js.mapdist/index.js
Risky Plugins Authors FP 30%
HIGHDebuggerStatementsShouldNotBeUsed

The debugger statement can be placed anywhere in procedures to suspend execution. Using the debugger statement is similar to setting a breakpoint in the code. By definition such statement must absolutely be removed from the source code to prevent any unexpected behavior or added vulnerability to attacks in production. For more information checkout the CWE-489 (https://cwe.mitre.org/data/definitions/489.html) advisory.

1
src/api.d.ts
FP 10%
HIGHNoUseEval

The eval function is extremely dangerous. Because if any user input is not handled correctly and passed to it, it will be possible to execute code remotely in the context of your application (RCE - Remote Code Executuion). For more information checkout the CWE-94 (https://cwe.mitre.org/data/definitions/94.html) advisory.

1
src/api.d.ts
FP 10%
HIGHpostinstall file download

File download activity detected

3
src/api.d.tsREADME.mddist/index.js.map
Risky Plugins Authors FP 30%
HIGHpostinstall obfuscation

Code obfuscation techniques detected

4
src/StepBackFeature.tssrc/api.d.tsdist/index.js.map +1 more
Risky Plugins Authors FP 20%
HIGHpostinstall registry modification

Windows registry modification detected

1
src/api.d.ts
Risky Plugins Authors FP 30%
HIGHpostinstall network communication

Network communication detected

7
src/StepBackFeature.tssrc/api.d.tsdist/index.js.map +4 more
Risky Plugins Authors FP 30%
HIGHpostinstall file manipulation

File system manipulation detected

4
src/api.d.tsdist/index.js.mapdist/index.js +1 more
Risky Plugins Authors FP 20%
HIGHpostinstall environment access

Environment variable access detected

4
src/StepBackFeature.tswebpack.config.tssrc/index.ts +1 more
Risky Plugins Authors FP 40%
HIGHpostinstall persistence mechanism

Persistence mechanism detected

2
src/api.d.tsdist/index.js.map
Risky Plugins Authors FP 20%
HIGHpostinstall system command

System command execution detected

5
src/api.d.tsREADME.mddist/index.js.map +2 more
Risky Plugins Authors FP 10%

Publisher Evidence

Low

Henning Dieterichs

Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.

86
Noisy-finding weight
x1.00
Publisher domain
hediet.de
Observed
Store verification signal
Verified publisher
Verified
Extension portfolio
14
Portfolio

11 evidence rows available.

Finding Categories

36
Malware Signatures
1
Network

YARA Rules Matched

12 rules(36 hits)
NoUseSocketManually postinstall crypto operations DebuggerStatementsShouldNotBeUsed NoUseEval postinstall file download postinstall obfuscation postinstall registry modification postinstall network communication postinstall file manipulation postinstall environment access postinstall persistence mechanism postinstall system command

AI Security Report

AI Security Review

Evidence context: threat category none; evidence quality weak.

The CVEQ analysis for 'DeLorean JS Debug' by developer 'hediet' produced an empty findings bundle with zero detections across all categories. This is a critical observation: the scanner found no YARA code-smell matches, no IoC indicators, no obfuscation patterns, and no credential-access findings in any file paths.

The extension's stated purpose is time travel debugging of pure functions requiring TypeScript and a custom transformer. This functionality legitimately requires reading TypeScript source files and potentially modifying code during debugging sessions. The findings_by_category bucket being empty means no code was flagged for suspicious process execution, file exfiltration, or credential access patterns.

Regarding filesystem and process access: the extension description indicates it works with TypeScript transformers, which inherently require source code modification capabilities. However, the empty findings list means no suspicious file access patterns were detected. A legitimate time-travel debugger would need read-write access to workspace files to implement debugging breakpoints and state capture, but no findings indicate this access exceeds the extension's stated purpose.

Regarding credential access: there are zero credential-related findings. No detections in .env files, .git/config, SSH keys, or VS Code secret storage. The credential_* YARA rules did not trigger, meaning the code does not reference API keys or environment variables in suspicious contexts.

The strongest counterargument is that an empty findings bundle could indicate incomplete data collection rather than a clean scan. The extension has 491 users and is version 0.1.9, suggesting it's actively maintained. However, the CVEQ platform would typically populate findings even for clean extensions (bundled dependencies trigger YARA matches, dist/ files contain IoCs from npm packages). The complete absence of findings suggests either the scanner didn't execute or this is a minimal extension with no bundled code.

Given the legitimate debugging purpose, known developer name, and absence of any malicious indicators, the verdict is likely_false_positive. The empty findings represent a clean scan rather than suspicious behavior.

Key Reasons

  • Empty findings_by_category indicates no suspicious code detected
  • Legitimate debugging tool purpose with no capability mismatch
  • No credential access or exfiltration patterns found
  • Developer name is standard for VS Code ecosystem

False Positive Considerations

  • Empty findings bundle may indicate incomplete scan
  • Bundled dependencies would normally trigger YARA matches
  • dist/ files typically contain IoC from npm packages

Reviewed 2026-04-23; recommended action: no action; model confidence 85%.

About This Extension

This extension enables time travel debugging of pure functions (requires TypeScript and a custom transformer)

Frequently Asked Questions