Notepad++ Plugins

Modern Markdown viewer

61967e05-8af7-598d-b04f-cd4fd1077eb1 | v1.0.0
63/ 100
MEDIUM risk
Analyst verdict
Needs follow up

From the RiskyPlugins AI security review of the observed evidence.

Analysis record

Analysed
4 days ago
Version
v1.0.0
Artifact
SHA256 B54…15D
Source
Findings (non-IoC)

Is Modern Markdown viewer safe?

This listing describes Modern Markdown viewer, a Notepad++ plugin for Markdown display, scrolling, zoom, Mermaid, front matter, and coloring. It declares no special permissions, while the native file NMD.dll:0 still runs with the host plugin's access. The listed endpoints include atomics.store and 0-i.top, which would give the plugin an external destination if its code connects to them.

The main finding is OBFUSCATION-supply_chain_binary at NMD.dll:0. If that finding reflects hidden behavior in the DLL, the plugin could conceal file access or network activity from a simple manifest check. No recorded finding names .env, .ssh, cloud credentials, secret storage, or a malware signature.

Some endpoint entries, including comment.block.java and comment.line.double-slash.shell, look like code or configuration text that an IoC scanner misread as domains. That explains part of the noise. The native DLL finding and the unrelated-looking domains still need runtime checks before installation can be treated as safe.

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

4 detail rows

YARA Rule Matches

2 rules
SeverityRuleHitsFilesMetadata
LOWNoUseWeakRandom 1
NMD.dll
-
LOWDebuggerStatementsShouldNotBeUsed 1
NMD.dll
-

Network Indicators

Concrete URLs, domains, IPs, emails, and hashes extracted from the analyzed artifact.

505 total
...

Network indicators are queued for lazy loading

Scroll this section into view to load the detailed rows.

Finding Categories

1
Obfuscation
505
IoC Indicators

YARA Rules Matched

2 rules
NoUseWeakRandom DebuggerStatementsShouldNotBeUsed

AI Security Report

AI Security Review

Evidence context: threat category supply chain; evidence quality moderate.

The extension is described as a “Modern Markdown viewer” with sync scrolling, zoom, Mermaid support, front matter, and coloring. Reading workspace files is consistent with that purpose, since rendering Markdown requires access to the document being viewed. The native plugin file NMD.dll:0 also runs inside Notepad++, so its process and filesystem capability is broader than the empty declared permission list suggests. No process-execution finding or filesystem-specific finding is recorded by title, so the available material does not show a command being launched or unrelated files being collected.

Credential access is not the main issue in the recorded results. No finding names .env, .ssh, cloud credential files, secret storage, or credential providers. The code-smell results are not described as secret theft, and the available category data records no secret finding. The absence of a credential finding does not prove that NMD.dll:0 never reads sensitive files, because a native DLL can perform file operations without a manifest permission, but the supplied evidence does not identify a real secret target.

The strongest signal is OBFUSCATION-supply_chain_binary at NMD.dll:0, marked critical. A native binary deserves more scrutiny than minified JavaScript because its behavior cannot be assessed from a manifest alone, and the finding title specifically links the obfuscation result to the supply chain. The endpoint list adds context that needs checking: 0-i.top, 2-s.top-s.bottom-d.top, ag.center, an.is, atomics.store, and bc.services are unrelated to Markdown rendering on their face. The same list also contains code-like strings such as comment.block.java and comment.line.double-slash.shell, which fit an IoC extractor misreading syntax or configuration data as network indicators. Those strings weaken the endpoint signal, while the native binary finding remains unresolved.

The strongest counterargument is that NMD.dll:0 is simply a compiled Notepad++ plugin, and the critical result is an obfuscation heuristic rather than a malware signature. The endpoint list contains several code-like entries, and the recorded results include no malware signature, credential theft finding, or explicit network behavior. That counterargument reduces confidence in a malicious conclusion, yet it does not clear the supply-chain concern because NMD.dll:0 is native code with no publisher or source validation in the supplied material. Runtime inspection should check child processes, file reads outside the opened Markdown document, outbound connections to the listed domains, and any writes to Notepad++ configuration or other plugins.

Key Reasons

  • OBFUSCATION-supply_chain_binary marks the native NMD.dll:0 file as critical.
  • NMD.dll:0 is native code running inside Notepad++, with no source or publisher validation supplied.
  • Endpoints such as atomics.store, 0-i.top, and bc.services have no stated link to Markdown rendering.
  • No recorded finding identifies .env, .ssh, cloud credentials, secret storage, or a malware signature.

False Positive Considerations

  • The endpoint list includes code-like strings such as comment.block.java and comment.line.double-slash.shell, consistent with IoC extraction noise.
  • OBFUSCATION-supply_chain_binary has an empty description, so the exact binary behavior is not documented.
  • The extension declares no permissions or host permissions, limiting manifest-based context for NMD.dll:0.

Reviewed 2026-09-29; recommended action: runtime analysis; model confidence 78%.

Frequently Asked Questions