Modern Markdown viewer
From the RiskyPlugins AI security review of the observed evidence.
Analysis record
- Analysed
- 4 days ago
- Version
- v1.0.0
- Artifact
- SHA256 B54…15D
- Source
- Findings (non-IoC)
Is Modern Markdown viewer safe?
This listing describes Modern Markdown viewer, a Notepad++ plugin for Markdown display, scrolling, zoom, Mermaid, front matter, and coloring. It declares no special permissions, while the native file NMD.dll:0 still runs with the host plugin's access. The listed endpoints include atomics.store and 0-i.top, which would give the plugin an external destination if its code connects to them.
The main finding is OBFUSCATION-supply_chain_binary at NMD.dll:0. If that finding reflects hidden behavior in the DLL, the plugin could conceal file access or network activity from a simple manifest check. No recorded finding names .env, .ssh, cloud credentials, secret storage, or a malware signature.
Some endpoint entries, including comment.block.java and comment.line.double-slash.shell, look like code or configuration text that an IoC scanner misread as domains. That explains part of the noise. The native DLL finding and the unrelated-looking domains still need runtime checks before installation can be treated as safe.
Evidence ledger
Ranked by severity · findings with a source location link to the code viewer
YARA Rule Matches
2 rules| Severity | Rule | Hits | Files | Metadata |
|---|---|---|---|---|
| LOW | NoUseWeakRandom | 1 | NMD.dll | - |
| LOW | DebuggerStatementsShouldNotBeUsed | 1 | NMD.dll | - |
Network Indicators
Concrete URLs, domains, IPs, emails, and hashes extracted from the analyzed artifact.
Network indicators are queued for lazy loading
Scroll this section into view to load the detailed rows.
Finding Categories
YARA Rules Matched
2 rulesAI Security Report
AI Security Review
Evidence context: threat category supply chain; evidence quality moderate.
The extension is described as a “Modern Markdown viewer” with sync scrolling, zoom, Mermaid support, front matter, and coloring. Reading workspace files is consistent with that purpose, since rendering Markdown requires access to the document being viewed. The native plugin file NMD.dll:0 also runs inside Notepad++, so its process and filesystem capability is broader than the empty declared permission list suggests. No process-execution finding or filesystem-specific finding is recorded by title, so the available material does not show a command being launched or unrelated files being collected.
Credential access is not the main issue in the recorded results. No finding names .env, .ssh, cloud credential files, secret storage, or credential providers. The code-smell results are not described as secret theft, and the available category data records no secret finding. The absence of a credential finding does not prove that NMD.dll:0 never reads sensitive files, because a native DLL can perform file operations without a manifest permission, but the supplied evidence does not identify a real secret target.
The strongest signal is OBFUSCATION-supply_chain_binary at NMD.dll:0, marked critical. A native binary deserves more scrutiny than minified JavaScript because its behavior cannot be assessed from a manifest alone, and the finding title specifically links the obfuscation result to the supply chain. The endpoint list adds context that needs checking: 0-i.top, 2-s.top-s.bottom-d.top, ag.center, an.is, atomics.store, and bc.services are unrelated to Markdown rendering on their face. The same list also contains code-like strings such as comment.block.java and comment.line.double-slash.shell, which fit an IoC extractor misreading syntax or configuration data as network indicators. Those strings weaken the endpoint signal, while the native binary finding remains unresolved.
The strongest counterargument is that NMD.dll:0 is simply a compiled Notepad++ plugin, and the critical result is an obfuscation heuristic rather than a malware signature. The endpoint list contains several code-like entries, and the recorded results include no malware signature, credential theft finding, or explicit network behavior. That counterargument reduces confidence in a malicious conclusion, yet it does not clear the supply-chain concern because NMD.dll:0 is native code with no publisher or source validation in the supplied material. Runtime inspection should check child processes, file reads outside the opened Markdown document, outbound connections to the listed domains, and any writes to Notepad++ configuration or other plugins.
Key Reasons
OBFUSCATION-supply_chain_binarymarks the nativeNMD.dll:0file as critical.NMD.dll:0is native code running inside Notepad++, with no source or publisher validation supplied.- Endpoints such as
atomics.store,0-i.top, andbc.serviceshave no stated link to Markdown rendering. - No recorded finding identifies
.env,.ssh, cloud credentials, secret storage, or a malware signature.
False Positive Considerations
- The endpoint list includes code-like strings such as
comment.block.javaandcomment.line.double-slash.shell, consistent with IoC extraction noise. OBFUSCATION-supply_chain_binaryhas an empty description, so the exact binary behavior is not documented.- The extension declares no permissions or host permissions, limiting manifest-based context for
NMD.dll:0.
Reviewed 2026-09-29; recommended action: runtime analysis; model confidence 78%.
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace