Tarantool-EmmyLua
Marketplace listing not found
Our last marketplace check could not find this listing in JetBrains Marketplace. It may have been removed or delisted. Existing installs may still run, but verify the publisher and package source before installing or updating.
From the RiskyPlugins AI security review of the observed evidence.
Analysis record
- Analysed
- 3 weeks ago
- Version
- v1.6-IDEA222
- Artifact
- SHA256 11B…17A
- Source
- Findings (non-IoC)
Evidence ledger
Ranked by severity · findings with a source location link to the code viewer
YARA Rule Matches
14 rules| Severity | Rule | Hits | Files | Metadata |
|---|---|---|---|---|
| HIGH | CAP HookExKeylogger | 1 | TarantoolEmmyLua/lib/jna-platform-5.5.0.jar | Brian C. Bell -- @biebsmalwareguy FP 5% |
| LOW | postinstall file download | 10 | TarantoolEmmyLua/std/Tarantool/global.luaTarantoolEmmyLua/lib/org.eclipse.egit.github.core-2.1.5.jarTarantoolEmmyLua/std/Tarantool/http.lua +7 more | - |
| LOW | postinstall process injection | 1 | TarantoolEmmyLua/lib/jna-platform-5.5.0.jar | - |
| LOW | NoUseEval | 1 | TarantoolEmmyLua/std/Tarantool/net_box.lua | - |
| LOW | postinstall system command | 26 | TarantoolEmmyLua/std/Tarantool/console.luaTarantoolEmmyLua/std/Tarantool/popen.luaTarantoolEmmyLua/std/Tarantool/os.lua +23 more | - |
| LOW | postinstall crypto operations | 9 | TarantoolEmmyLua/std/Tarantool/swim.luaTarantoolEmmyLua/lib/kotlin-stdlib-common-1.6.0.jarTarantoolEmmyLua/debugger/emmy/linux/emmy_core.so +6 more | - |
| LOW | postinstall file manipulation | 18 | TarantoolEmmyLua/std/Tarantool/box.luaTarantoolEmmyLua/lib/TarantoolEmmyLua-1.6-IDEA222.jarTarantoolEmmyLua/std/Tarantool/io.lua +15 more | - |
| LOW | postinstall network communication | 17 | TarantoolEmmyLua/debugger/mobdebug/mobdebug.luaTarantoolEmmyLua/std/Tarantool/http.luaTarantoolEmmyLua/lib/jna-platform-5.5.0.jar +14 more | - |
| LOW | JavaDropper | 3 | TarantoolEmmyLua/lib/jna-5.5.0.jarTarantoolEmmyLua/lib/kotlin-stdlib-1.6.0.jarTarantoolEmmyLua/lib/TarantoolEmmyLua-1.6-IDEA222.jar | - |
| LOW | postinstall registry modification | 4 | TarantoolEmmyLua/debugger/emmy/linux/emmy_core.soTarantoolEmmyLua/std/Tarantool/debug.luaTarantoolEmmyLua/lib/jna-platform-5.5.0.jar +1 more | - |
| LOW | postinstall obfuscation | 15 | TarantoolEmmyLua/std/Tarantool/box.luaTarantoolEmmyLua/std/Tarantool/console.luaTarantoolEmmyLua/std/Tarantool/digest.lua +12 more | - |
| LOW | DebuggerStatementsShouldNotBeUsed | 9 | TarantoolEmmyLua/debugger/windows/x86/EasyHook.dllTarantoolEmmyLua/lib/TarantoolEmmyLua-1.6-IDEA222.jarTarantoolEmmyLua/debugger/windows/x64/EasyHook.dll +6 more | - |
| LOW | credential env files | 1 | TarantoolEmmyLua/std/Tarantool/os.lua | - |
| LOW | postinstall persistence mechanism | 2 | TarantoolEmmyLua/lib/jna-platform-5.5.0.jarTarantoolEmmyLua/debugger/emmy/linux/emmy_core.so | - |
Network Indicators
Concrete URLs, domains, IPs, emails, and hashes extracted from the analyzed artifact.
Network indicators are queued for lazy loading
Scroll this section into view to load the detailed rows.
Publisher Evidence
Limited evidenceDanis Nizamutdinov
Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.
13 evidence rows available.
Finding Categories
YARA Rules Matched
14 rules(117 hits)AI Security Report
AI Security Review
Risky Plugins reviewed this extension with an AI-assisted security workflow on 2026-05-23. The review verdict is benign but powerful with 92% confidence.
Recommended action: no action. Evidence context: threat category none; evidence quality strong.
The extension’s purpose is to add EmmyLua debugging support for Tarantool projects. All identified findings are simple metadata entries such as HASH-8ae66a884bdb5b1a in TarantoolEmmyLua/std/Tarantool/box.lua and HASH-ace2a10dc8e2d5fd in TarantoolEmmyLua/lib/annotations-13.0.jar. No process‑spawning, network, or post‑install signatures were detected, so the filesystem and process access is fully justified by the need to read library files and expose debugging symbols.
The evidence contains zero credential‑related findings; there are no references to .env, .ssh, cloud credential files, or VS Code secret storage. The only files listed are source modules (*.lua) and bundled JAR libraries, confirming that the extension does not attempt to harvest secrets.
A possible counterargument could be that the presence of many JAR files (luaj-jse-3.0.1.jar, annotations-13.0.jar) suggests hidden malicious code. However, each JAR is accounted for by a metadata hash entry, and no malware‑signature, obfuscation, or code‑smell patterns were reported. The lack of any actionable IoC or suspicious API usage means the extension’s behavior aligns with normal language‑server tooling.
Conclusion: The extension’s file reads are necessary for providing language intelligence, no credential access is performed, and there is no evidence of malicious intent. It can be classified as a legitimate development aid with broad but appropriate capabilities.
Key Reasons
- Only metadata hash findings (e.g., HASH‑8ae66a884bdb5b1a in box.lua)
- No process‑execution or network‑communication signatures
- No credential‑access or secret‑reading findings
- All files are source modules or bundled libraries required for debugging
False Positive Considerations
- metadata‑only findings
- bundled JAR libraries
- absence of code‑smell detections
- no IoC or network activity
About This Extension
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace