Notepad++ Plugins

FingerText2

6549007a-72af-551f-9156-a9bcd18d0634 | v26.6.15
57/ 100
MEDIUM risk
-1 since v26.5.26.1
Analyst verdict
Needs follow up

From the RiskyPlugins AI security review of the observed evidence.

Analysis record

Analysed
3 months ago
Version
v26.6.15
Artifact
SHA256 517…145
Source
Findings (non-IoC)

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

2 detail rows

Network Indicators

Concrete URLs, domains, IPs, emails, and hashes extracted from the analyzed artifact.

4 total
...

Network indicators are queued for lazy loading

Scroll this section into view to load the detailed rows.

Finding Categories

1
Obfuscation
4
IoC Indicators

AI Security Report

AI Security Review

Evidence context: threat category unknown malware; evidence quality moderate.

This Notepad++ plugin presents unusual security signals that warrant investigation. The extension claims to provide tab-triggered snippets and hotspot navigation, which justifies basic filesystem access for reading configuration and user snippets. However, the presence of obfuscation in the native DLL is concerning.

The critical finding OBFUSCATION-supply_chain_binary in FingerText2.dll is the primary concern. Unlike JavaScript extensions where minification is standard, native DLLs do not typically require obfuscation for legitimate functionality. This pattern appears in the main binary file, not in bundled dependencies, making it harder to dismiss as noise.

The IoC findings show mixed signals. The URL findings pointing to https://github.com/ultimatejimmy/FingerText2/wiki and https://github.com/ultimatejimmy/FingerText2/issues indicate legitimate project hosting. The IP finding 26.5.26.1 matches the version number exactly, suggesting this is a false positive from the IoC extractor misreading version strings as IP addresses. However, the domain findings file.open and f.radio are suspicious—these are not standard infrastructure domains and do not appear in the legitimate GitHub URLs.

Credential access findings are absent from this extension, which is positive. The findings summary shows zero secret detections and zero malware signatures, indicating no direct evidence of credential theft or known malware families.

The strongest counterargument is that the GitHub project links demonstrate legitimate development and the version-number-as-IP finding is clearly a false positive. However, this does not explain why a snippet plugin would have supply chain obfuscation patterns in its DLL, nor does it explain the suspicious domain references. The zero user count further reduces confidence in the extension's legitimacy.

Given the obfuscation in a native DLL combined with suspicious domain references and no user adoption, this extension requires manual code review to determine if the obfuscation is defensive or malicious before recommending installation.

Key Reasons

  • Critical obfuscation finding in native DLL (FingerText2.dll)
  • Zero user count indicates untested extension
  • Suspicious domain references (file.open, f.radio) not explained by functionality
  • No malware signatures but obfuscation pattern is concerning for native binary

False Positive Considerations

  • Version number 26.5.26.1 misidentified as IP address
  • GitHub project URLs are legitimate infrastructure
  • No malware signature matches detected
  • No credential access findings present

Reviewed 2026-05-28; recommended action: runtime analysis; model confidence 65%.

Notepad++ version history

Risk trend by version

2 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.

Selected
57
Change since first
-1
Change from previous
-1
Versions:
First analyzed version
26.5.26.1
May 28, 2026
Risk range
57 to 57
Across analyzed versions
Latest analyzed version
26.6.15
Jun 19, 2026
Selected version
medium
Version
v26.6.15
3 months ago
Risk score
57
Findings
6
Change vs previous
-1

Pick any point on the chart to explore that version's code below.

Frequently Asked Questions