VS Code Marketplace

PRODM280W1 TESTone On Platform

5d9b6879-7089-586d-a563-b3c2041a79f8 | v3.3.8
52/ 100
MEDIUM risk
Analyst verdict
Review before use

The AI review rates the findings as likely false positive, but the risk score (52/100) still counts them.

Analysis record

Analysed
Yesterday
Version
v3.3.8
Artifact
SHA256 161…B1C
Source
Findings (non-IoC)

Is PRODM280W1 TESTone On Platform safe?

This extension pitches itself as a full embedded toolchain for STM32, ESP32, AVR, Zephyr and similar microcontroller families, the ground PlatformIO IDE covers. Its manifest declares no permissions and no host permissions, so any access to your project comes from what the extension code does once it runs. The endpoint strings pulled out of the package land on PlatformIO's own documentation, including https://bit.ly/vscode-platformio-home-docs and http://docs.platformio.org/page/ide/vscode.html.

Almost everything the scanner flagged came from bundled third party libraries, with the extension's own logic rarely producing these strings. A finding labelled XIOC-DOMAIN-binarystream.read caught a JavaScript property name, XIOC-IP-1:2:3:4:: caught a string that cannot work as an address, and XIOC-DOMAIN-mkdirp-manual.js.map caught the filename of a source map. The two email addresses, [email protected] and [email protected], belong to maintainers of npm packages shipped inside the bundle, and any project pulling in those same libraries would contain them too.

That explains the volume. Hundreds of bundled libraries each contribute strings that the extractor reads as endpoints, so hundreds of harmless hits stack up fast. Nothing here opens .env files, SSH keys or cloud credentials, and no malware signature turned up anywhere in the package.

One detail deserves a human look. The publisher name PRODM280DVTWEEK1 and an install count of zero do not match PlatformIO's official listing, so this copy has the shape of a test or private upload of the same code. A repackaged payload would normally add an install script or a download call, and the file set here carries PlatformIO 3.3.8 unchanged.

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

43 detail rows

YARA Rule Matches

10 rules
SeverityRuleHitsFilesMetadata
LOWcredential env files 2
dist/extension.js.mapdist/extension.js
-
LOWpostinstall persistence mechanism 3
dist/extension.js.mappackage.jsondist/extension.js
-
LOWpostinstall file download 4
syntaxes/assembly.tmLanguagescripts/publish.pydist/extension.js.map +1 more
-
LOWNoUseWeakRandom 2
dist/extension.js.mapdist/extension.js
-
LOWDebuggerStatementsShouldNotBeUsed 2
package.jsonextension.vsixmanifest
-
LOWpostinstall file manipulation 6
scripts/publish.pysyntaxes/assembly-configuration.jsondist/extension.js.map +3 more
-
LOWpostinstall system command 10
readme.mdassets/welcome/platformio-ini-example.mdscripts/publish.py +7 more
-
LOWpostinstall registry modification 5
scripts/publish.pydist/extension.js.mappackage.json +2 more
-
LOWpostinstall obfuscation 3
assets/welcome/platformio-ini-example.mddist/extension.js.mapdist/extension.js
-
LOWpostinstall network communication 3
changelog.mddist/extension.js.mapdist/extension.js
-

Network Indicators

Concrete URLs, domains, IPs, emails, and hashes extracted from the analyzed artifact.

431 total
...

Network indicators are queued for lazy loading

Scroll this section into view to load the detailed rows.

Publisher Evidence

Limited evidence

PRODM280DVTWEEK1

Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.

30
Noisy-finding weight
x1.00
Publisher domain
No domain
Missing
Store verification signal
Not exposed
Not exposed
Extension portfolio
5
Portfolio

10 evidence rows available.

Finding Categories

431
IoC Indicators

YARA Rules Matched

10 rules(40 hits)
credential env files postinstall persistence mechanism postinstall file download NoUseWeakRandom DebuggerStatementsShouldNotBeUsed postinstall file manipulation postinstall system command postinstall registry modification postinstall obfuscation postinstall network communication

AI Security Report

AI Security Review

Evidence context: threat category none; evidence quality moderate.

What this extension does

The listing describes an embedded toolchain for CMSIS, ESP-IDF, FreeRTOS, STM32Cube, Zephyr RTOS, Arduino and a long list of microcontroller families. That matches PlatformIO IDE's feature set, and the package ships version 3.3.8 with PlatformIO's own documentation links inside it, including http://docs.platformio.org/page/core.html and http://docs.platformio.org/page/ide/vscode.html. The manifest declares no permissions and no host permissions, so the access question comes down to what the extension code does at runtime.

Filesystem and process access

A build tool for embedded targets invokes platformio and the compilers it manages, reads workspace sources and config, and writes build output. Process spawning and broad file reads belong to that job. The code-smell pass returned 40 low-severity hits, every one in bundled JavaScript and none above low severity. The dependency category returned three findings, consistent with the npm libraries shipped in the package. Nothing in the file set reaches outside the workspace and toolchain directories a build system needs.

Credential findings

Zero. The secret category came back empty, and no finding references .env files, .ssh keys or cloud credential paths. The two mailbox strings the extractor pulled out, [email protected] and [email protected], sit in bundled dependency metadata as npm maintainer addresses. Pulling a package author's email out of a bundled license file tells you nothing about the developer's stored secrets.

The IoC list

The 431 IoC entries decompose into documented extraction noise. XIOC-IP-1:2:3:4:: is a string no network stack can route. XIOC-DOMAIN-binarystream.read caught a JavaScript property access chain. XIOC-DOMAIN-mkdirp-manual.js.map caught the filename of a source map. The rest covers PlatformIO's documentation, a shortlink PlatformIO itself ships (https://bit.ly/vscode-platformio-home-docs), aka.ms/tsconfig.json from Microsoft's TypeScript templates, and a Wikipedia link to the squared Euclidean distance formula from a bundled math library. The endpoint list repeats the pattern: adodb.stream names a Windows COM class, while convert.rgb.apple and codecoptions.gb have the shape of property chains rather than hosts.

Strongest counterargument

The publisher name PRODM280DVTWEEK1 and an install count of zero do not match PlatformIO's official marketplace account, and a re-upload under an unfamiliar name is the classic shape of a supply chain substitution. The package contents argue against that reading. A poisoned repackaging leaves traces: an install script, a fetch call during activation, an extra dependency, obfuscated code. This bundle shows no malware signature matches, no obfuscation findings, no network findings and no manifest changes, and the embedded version strings and documentation URLs line up with the upstream 3.3.8 release.

Key Reasons

  • No malware signature, obfuscation, network or secret findings appear in the package; the only hits come from bundled dependency metadata and upstream documentation links.
  • The 431 IoC entries are known extractor noise: XIOC-DOMAIN-binarystream.read reads a property chain, XIOC-IP-1:2:3:4:: is unroutable, XIOC-DOMAIN-mkdirp-manual.js.map reads a source map filename.
  • PlatformIO documentation URLs and the bit.ly/vscode-platformio-home-docs shortlink ship with the upstream project itself.
  • Process spawning and workspace reads fit an embedded build toolchain, and the 40 code-smell hits sit at low severity inside bundled JavaScript.
  • The publisher name and zero install count point to a test or private re-upload, while the bundled PlatformIO 3.3.8 contents stay unchanged from upstream.

False Positive Considerations

  • IoC extraction reading property access chains (binarystream.read, adodb.stream, codecoptions.gb) as network domains
  • Bundled npm dependency metadata supplying maintainer email addresses and documentation URLs
  • Low-severity code-smell hits firing on minified dist JavaScript
  • An invalid IPv6 fragment, 1:2:3:4::, counted as a routable IP address

Reviewed 2026-10-01; recommended action: suppress false positive; model confidence 82%.

About This Extension

Your Gateway to Embedded Software Development Excellence: CMSIS, ESP-IDF, FreeRTOS, libOpenCM3, mbed OS, SPL, STM32Cube, Zephyr RTOS, Arduino, ARM, AVR, Espressif (ESP8266/ESP32), FPGA, MCS-51 (8051), MSP430, Nordic (nRF51/nRF52), PIC32, RISC-V, Raspberry Pi (RP2040), STMicroelectronics (STM8/STM32)

Frequently Asked Questions