From the RiskyPlugins AI security review of the observed evidence.
Analysis record
- Analysed
- 3 months ago
- Version
- v26.6.15
- Artifact
- SHA256 517…145
- Source
- Findings (non-IoC)
Evidence ledger
Ranked by severity · findings with a source location link to the code viewer
Network Indicators
Concrete URLs, domains, IPs, emails, and hashes extracted from the analyzed artifact.
Network indicators are queued for lazy loading
Scroll this section into view to load the detailed rows.
Finding Categories
AI Security Report
AI Security Review
Evidence context: threat category unknown malware; evidence quality moderate.
This Notepad++ plugin presents unusual security signals that warrant investigation. The extension claims to provide tab-triggered snippets and hotspot navigation, which justifies basic filesystem access for reading configuration and user snippets. However, the presence of obfuscation in the native DLL is concerning.
The critical finding OBFUSCATION-supply_chain_binary in FingerText2.dll is the primary concern. Unlike JavaScript extensions where minification is standard, native DLLs do not typically require obfuscation for legitimate functionality. This pattern appears in the main binary file, not in bundled dependencies, making it harder to dismiss as noise.
The IoC findings show mixed signals. The URL findings pointing to https://github.com/ultimatejimmy/FingerText2/wiki and https://github.com/ultimatejimmy/FingerText2/issues indicate legitimate project hosting. The IP finding 26.5.26.1 matches the version number exactly, suggesting this is a false positive from the IoC extractor misreading version strings as IP addresses. However, the domain findings file.open and f.radio are suspicious—these are not standard infrastructure domains and do not appear in the legitimate GitHub URLs.
Credential access findings are absent from this extension, which is positive. The findings summary shows zero secret detections and zero malware signatures, indicating no direct evidence of credential theft or known malware families.
The strongest counterargument is that the GitHub project links demonstrate legitimate development and the version-number-as-IP finding is clearly a false positive. However, this does not explain why a snippet plugin would have supply chain obfuscation patterns in its DLL, nor does it explain the suspicious domain references. The zero user count further reduces confidence in the extension's legitimacy.
Given the obfuscation in a native DLL combined with suspicious domain references and no user adoption, this extension requires manual code review to determine if the obfuscation is defensive or malicious before recommending installation.
Key Reasons
- Critical obfuscation finding in native DLL (FingerText2.dll)
- Zero user count indicates untested extension
- Suspicious domain references (file.open, f.radio) not explained by functionality
- No malware signatures but obfuscation pattern is concerning for native binary
False Positive Considerations
- Version number 26.5.26.1 misidentified as IP address
- GitHub project URLs are legitimate infrastructure
- No malware signature matches detected
- No credential access findings present
Reviewed 2026-05-28; recommended action: runtime analysis; model confidence 65%.
Notepad++ version history
Risk trend by version
2 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.
Pick any point on the chart to explore that version's code below.
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace