Is "Nexus AI" on VS Code Marketplace Safe to Install?

Mohammed Hafiz · vscode · v4.3.1

AI code assistant powered by call-graph + vector search. Ask, debug, review, and generate tests — all locally.

Risk Assessment

Analyzed
84.95
out of 100
HIGH

324 security findings detected across all analyzers

VS Code extension analyzed via package manifest and static code analysis

Severity Breakdown

0
Critical
0
High
275
Medium
49
Low
0
Info

Finding Categories

12
Network
255
IoC Indicators

YARA Rules Matched

10 rules(47 hits)
postinstall network communication credential env files postinstall obfuscation postinstall file manipulation postinstall file download postinstall system command postinstall persistence mechanism postinstall registry modification NoUseWeakRandom postinstall crypto operations

About This Extension

AI code assistant powered by call-graph + vector search. Ask, debug, review, and generate tests — all locally.

Detailed Findings

61 total

YARA Rule Matches

10 rules

Indicators of Compromise

Network indicators, suspicious strings, and potential IoCs extracted during analysis

URLs
46
IP Addresses
11
Domains
199
Strings
255

All Indicators · 255

URL
detected URL: https://github.com/Hafiz408/Nexus/raw/HEAD/images/demo.gif

XIOC detected URL: https://github.com/Hafiz408/Nexus/raw/HEAD/images/demo.gif

extracted_from_files

IP
detected IP: ::9

XIOC detected IP: ::9

extracted_from_files

IP
detected IP: ::a

XIOC detected IP: ::a

extracted_from_files

IP
detected IP: c::

XIOC detected IP: c::

extracted_from_files

Domain
detected Domain: hafiz408.nexus

XIOC detected Domain: hafiz408.nexus

extracted_from_files

Domain
detected Domain: build.py

XIOC detected Domain: build.py

extracted_from_files

Domain
detected Domain: client.ping

XIOC detected Domain: client.ping

extracted_from_files

Domain
detected Domain: readme.md

XIOC detected Domain: readme.md

extracted_from_files

Domain
detected Domain: schemas.openxmlformats.org

XIOC detected Domain: schemas.openxmlformats.org

extracted_from_files

IP
detected IP: ea::

XIOC detected IP: ea::

extracted_from_files

IP
detected IP: ::af

XIOC detected IP: ::af

extracted_from_files

Domain
detected Domain: e9.ph

XIOC detected Domain: e9.ph

extracted_from_files

Domain
detected Domain: n.gt

XIOC detected Domain: n.gt

extracted_from_files

Domain
detected Domain: w.cab

XIOC detected Domain: w.cab

extracted_from_files

Domain
detected Domain: ns.adobe.com

XIOC detected Domain: ns.adobe.com

extracted_from_files

Domain
detected Domain: js.map

XIOC detected Domain: js.map

extracted_from_files

Domain
detected Domain: extension-output-publisher.name

XIOC detected Domain: extension-output-publisher.name

extracted_from_files

Domain
detected Domain: asyncio.to

XIOC detected Domain: asyncio.to

extracted_from_files

Domain
detected Domain: y.vi

XIOC detected Domain: y.vi

extracted_from_files

Domain
detected Domain: ҋ.sv

XIOC detected Domain: ҋ.sv

extracted_from_files

Domain
detected Domain: k.bi

XIOC detected Domain: k.bi

extracted_from_files

Domain
detected Domain: q.ph

XIOC detected Domain: q.ph

extracted_from_files

Domain
detected Domain: 6.ye

XIOC detected Domain: 6.ye

extracted_from_files

Domain
detected Domain: c.mk

XIOC detected Domain: c.mk

extracted_from_files

Domain
detected Domain: n.my

XIOC detected Domain: n.my

extracted_from_files

Domain
detected Domain: v.do

XIOC detected Domain: v.do

extracted_from_files

Domain
detected Domain: i.cz

XIOC detected Domain: i.cz

extracted_from_files

Domain
detected Domain: h.bs

XIOC detected Domain: h.bs

extracted_from_files

Domain
detected Domain: t.tm

XIOC detected Domain: t.tm

extracted_from_files

Domain
detected Domain: q.tj

XIOC detected Domain: q.tj

extracted_from_files

Domain
detected Domain: k.ht

XIOC detected Domain: k.ht

extracted_from_files

Domain
detected Domain: 6.hk

XIOC detected Domain: 6.hk

extracted_from_files

Domain
detected Domain: 7.es

XIOC detected Domain: 7.es

extracted_from_files

Domain
detected Domain: b.tj

XIOC detected Domain: b.tj

extracted_from_files

Domain
detected Domain: u.us

XIOC detected Domain: u.us

extracted_from_files

Domain
detected Domain: t.mu

XIOC detected Domain: t.mu

extracted_from_files

Domain
detected Domain: 6.lt

XIOC detected Domain: 6.lt

extracted_from_files

Domain
detected Domain: z.sd

XIOC detected Domain: z.sd

extracted_from_files

Domain
detected Domain: a.dz

XIOC detected Domain: a.dz

extracted_from_files

Domain
detected Domain: 4.pl

XIOC detected Domain: 4.pl

extracted_from_files

Domain
detected Domain: 8.dz

XIOC detected Domain: 8.dz

extracted_from_files

Domain
detected Domain: ھ.my

XIOC detected Domain: ھ.my

extracted_from_files

Domain
detected Domain: x.pn

XIOC detected Domain: x.pn

extracted_from_files

Domain
detected Domain: u.ir

XIOC detected Domain: u.ir

extracted_from_files

Domain
detected Domain: 큨.ag

XIOC detected Domain: 큨.ag

extracted_from_files

Domain
detected Domain: q.ws

XIOC detected Domain: q.ws

extracted_from_files

Domain
detected Domain: a.ca

XIOC detected Domain: a.ca

extracted_from_files

Domain
detected Domain: s.sx

XIOC detected Domain: s.sx

extracted_from_files

Domain
detected Domain: m.om

XIOC detected Domain: m.om

extracted_from_files

Domain
detected Domain: 2.ar.ax

XIOC detected Domain: 2.ar.ax

extracted_from_files

Domain
detected Domain: 5.kh

XIOC detected Domain: 5.kh

extracted_from_files

Domain
detected Domain: dka.lb

XIOC detected Domain: dka.lb

extracted_from_files

Domain
detected Domain: 3ha.ls

XIOC detected Domain: 3ha.ls

extracted_from_files

Domain
detected Domain: kp.re

XIOC detected Domain: kp.re

extracted_from_files

Domain
detected Domain: z.uz

XIOC detected Domain: z.uz

extracted_from_files

Domain
detected Domain: rciv.bbt

XIOC detected Domain: rciv.bbt

extracted_from_files

Domain
detected Domain: m.ge

XIOC detected Domain: m.ge

extracted_from_files

Domain
detected Domain: ak.lt

XIOC detected Domain: ak.lt

extracted_from_files

Domain
detected Domain: x.nl

XIOC detected Domain: x.nl

extracted_from_files

Domain
detected Domain: z5.cy

XIOC detected Domain: z5.cy

extracted_from_files

Domain
detected Domain: x.uy

XIOC detected Domain: x.uy

extracted_from_files

Domain
detected Domain: į.dz

XIOC detected Domain: į.dz

extracted_from_files

Domain
detected Domain: r.ai

XIOC detected Domain: r.ai

extracted_from_files

Domain
detected Domain: o.er

XIOC detected Domain: o.er

extracted_from_files

Domain
detected Domain: 7f.ps

XIOC detected Domain: 7f.ps

extracted_from_files

Domain
detected Domain: c.bn

XIOC detected Domain: c.bn

extracted_from_files

Domain
detected Domain: d.fi

XIOC detected Domain: d.fi

extracted_from_files

Domain
detected Domain: w.lc

XIOC detected Domain: w.lc

extracted_from_files

IP
detected IP: 0::

XIOC detected IP: 0::

extracted_from_files

Domain
detected Domain: b.cc

XIOC detected Domain: b.cc

extracted_from_files

Domain
detected Domain: q.cf

XIOC detected Domain: q.cf

extracted_from_files

Domain
detected Domain: խ.qa

XIOC detected Domain: խ.qa

extracted_from_files

Domain
detected Domain: h.sa

XIOC detected Domain: h.sa

extracted_from_files

Domain
detected Domain: i.gh

XIOC detected Domain: i.gh

extracted_from_files

Domain
detected Domain: qx.aq

XIOC detected Domain: qx.aq

extracted_from_files

Domain
detected Domain: 9.nr

XIOC detected Domain: 9.nr

extracted_from_files

Domain
detected Domain: r6eq.et

XIOC detected Domain: r6eq.et

extracted_from_files

Domain
detected Domain: d.ky

XIOC detected Domain: d.ky

extracted_from_files

Domain
detected Domain: mm.la

XIOC detected Domain: mm.la

extracted_from_files

Domain
detected Domain: 0g.bv

XIOC detected Domain: 0g.bv

extracted_from_files

Domain
detected Domain: qi.gp

XIOC detected Domain: qi.gp

extracted_from_files

Domain
detected Domain: this.context.secrets.store

XIOC detected Domain: this.context.secrets.store

extracted_from_files

Domain
detected Domain: date.now

XIOC detected Domain: date.now

extracted_from_files

Domain
detected Domain: hasownprop.call

XIOC detected Domain: hasownprop.call

extracted_from_files

Domain
detected Domain: q.ca

XIOC detected Domain: q.ca

extracted_from_files

Domain
detected Domain: q.pm

XIOC detected Domain: q.pm

extracted_from_files

Domain
detected Domain: b.uy

XIOC detected Domain: b.uy

extracted_from_files

Domain
detected Domain: d.bb

XIOC detected Domain: d.bb

extracted_from_files

Domain
detected Domain: lock.pid

XIOC detected Domain: lock.pid

extracted_from_files

Domain
detected Domain: progress.report

XIOC detected Domain: progress.report

extracted_from_files

Domain
detected Domain: msg.pr

XIOC detected Domain: msg.pr

extracted_from_files

Domain
detected Domain: msg.target

XIOC detected Domain: msg.target

extracted_from_files

Domain
detected Domain: reader.read

XIOC detected Domain: reader.read

extracted_from_files

Domain
detected Domain: err.name

XIOC detected Domain: err.name

extracted_from_files

Domain
detected Domain: filecitations.map

XIOC detected Domain: filecitations.map

extracted_from_files

Domain
detected Domain: electronjs.org

XIOC detected Domain: electronjs.org

extracted_from_files

Domain
detected Domain: www.andismith.com

XIOC detected Domain: www.andismith.com

extracted_from_files

Domain
detected Domain: reactjs.org

XIOC detected Domain: reactjs.org

extracted_from_files

Domain
detected Domain: providers.map

XIOC detected Domain: providers.map

extracted_from_files

Domain
detected Domain: files.map

XIOC detected Domain: files.map

extracted_from_files

Domain
detected Domain: channel.show

XIOC detected Domain: channel.show

extracted_from_files

Domain
detected Domain: proc.pid

XIOC detected Domain: proc.pid

extracted_from_files

Domain
detected Domain: type.name

XIOC detected Domain: type.name

extracted_from_files

Domain
detected Domain: innertype.name

XIOC detected Domain: innertype.name

extracted_from_files

Domain
detected Domain: value.constructor.name

XIOC detected Domain: value.constructor.name

extracted_from_files

Domain
detected Domain: constructor.name

XIOC detected Domain: constructor.name

extracted_from_files

Domain
detected Domain: function.prototype.apply.call

XIOC detected Domain: function.prototype.apply.call

extracted_from_files

Domain
detected Domain: args.map

XIOC detected Domain: args.map

extracted_from_files

Domain
detected Domain: html.spec.whatwg.org

XIOC detected Domain: html.spec.whatwg.org

extracted_from_files

Domain
detected Domain: console.group

XIOC detected Domain: console.group

extracted_from_files

Domain
detected Domain: console.info

XIOC detected Domain: console.info

extracted_from_files

Domain
detected Domain: render.name

XIOC detected Domain: render.name

extracted_from_files

Domain
detected Domain: func.call

XIOC detected Domain: func.call

extracted_from_files

Domain
detected Domain: iterator.next

XIOC detected Domain: iterator.next

extracted_from_files

Domain
detected Domain: iteratorfn.call

XIOC detected Domain: iteratorfn.call

extracted_from_files

Domain
detected Domain: hasownproperty.call

XIOC detected Domain: hasownproperty.call

extracted_from_files

Domain
detected Domain: b.id

XIOC detected Domain: b.id

extracted_from_files

Domain
detected Domain: a.id

XIOC detected Domain: a.id

extracted_from_files

Domain
detected Domain: noderequire.call

XIOC detected Domain: noderequire.call

extracted_from_files

IP
detected IP: ::7

XIOC detected IP: ::7

extracted_from_files

Domain
detected Domain: fn.name

XIOC detected Domain: fn.name

extracted_from_files

Domain
detected Domain: fake.call

XIOC detected Domain: fake.call

extracted_from_files

Domain
detected Domain: props.name

XIOC detected Domain: props.name

extracted_from_files

Domain
detected Domain: node.name

XIOC detected Domain: node.name

extracted_from_files

Domain
detected Domain: set2.call

XIOC detected Domain: set2.call

extracted_from_files

Domain
detected Domain: get2.call

XIOC detected Domain: get2.call

extracted_from_files

Domain
detected Domain: localdate.now

XIOC detected Domain: localdate.now

extracted_from_files

Domain
detected Domain: localperformance.now

XIOC detected Domain: localperformance.now

extracted_from_files

Domain
detected Domain: performance.now

XIOC detected Domain: performance.now

extracted_from_files

Domain
detected Domain: array.prototype.slice.call

XIOC detected Domain: array.prototype.slice.call

extracted_from_files

Domain
detected Domain: nativeevent.target

XIOC detected Domain: nativeevent.target

extracted_from_files

Domain
detected Domain: unknownprops.map

XIOC detected Domain: unknownprops.map

extracted_from_files

Domain
detected Domain: invalidprops.map

XIOC detected Domain: invalidprops.map

extracted_from_files

Domain
detected Domain: props.is

XIOC detected Domain: props.is

extracted_from_files

Domain
detected Domain: props.style

XIOC detected Domain: props.style

extracted_from_files

Domain
detected Domain: node.style

XIOC detected Domain: node.style

extracted_from_files

Domain
detected Domain: enterevent.target

XIOC detected Domain: enterevent.target

extracted_from_files

Domain
detected Domain: leave.target

XIOC detected Domain: leave.target

extracted_from_files

Domain
detected Domain: nativeevent.data

XIOC detected Domain: nativeevent.data

extracted_from_files

Domain
detected Domain: event.data

XIOC detected Domain: event.data

extracted_from_files

Domain
detected Domain: detail.data

XIOC detected Domain: detail.data

extracted_from_files

Domain
detected Domain: this.target

XIOC detected Domain: this.target

extracted_from_files

Domain
detected Domain: queuedtarget.target

XIOC detected Domain: queuedtarget.target

extracted_from_files

Domain
detected Domain: instance.style

XIOC detected Domain: instance.style

extracted_from_files

Domain
detected Domain: nextnode.data

XIOC detected Domain: nextnode.data

extracted_from_files

Domain
detected Domain: nextrawprops.name

XIOC detected Domain: nextrawprops.name

extracted_from_files

Domain
detected Domain: object.prototype.tostring.call

XIOC detected Domain: object.prototype.tostring.call

extracted_from_files

Domain
detected Domain: event.target

XIOC detected Domain: event.target

extracted_from_files

Domain
detected Domain: info.top

XIOC detected Domain: info.top

extracted_from_files

Domain
detected Domain: object.is

XIOC detected Domain: object.is

extracted_from_files

Domain
detected Domain: dependency.next

XIOC detected Domain: dependency.next

extracted_from_files

Domain
detected Domain: pending.next

XIOC detected Domain: pending.next

extracted_from_files

Domain
detected Domain: update.next

XIOC detected Domain: update.next

extracted_from_files

Domain
detected Domain: newchildren.next

XIOC detected Domain: newchildren.next

extracted_from_files

Domain
detected Domain: suspendedcontext.id

XIOC detected Domain: suspendedcontext.id

extracted_from_files

Domain
detected Domain: node.data

XIOC detected Domain: node.data

extracted_from_files

Domain
detected Domain: instance.data

XIOC detected Domain: instance.data

extracted_from_files

Domain
detected Domain: payload.call

XIOC detected Domain: payload.call

extracted_from_files

Domain
detected Domain: lastbaseupdate.next

XIOC detected Domain: lastbaseupdate.next

extracted_from_files

Domain
detected Domain: newlast.next

XIOC detected Domain: newlast.next

extracted_from_files

Domain
detected Domain: interleaved.next

XIOC detected Domain: interleaved.next

extracted_from_files

Domain
detected Domain: lastpendingupdate.next

XIOC detected Domain: lastpendingupdate.next

extracted_from_files

Domain
detected Domain: lastinterleavedupdate.next

XIOC detected Domain: lastinterleavedupdate.next

extracted_from_files

Domain
detected Domain: lastcontextdependency.next

XIOC detected Domain: lastcontextdependency.next

extracted_from_files

Domain
detected Domain: basequeue.next

XIOC detected Domain: basequeue.next

extracted_from_files

Domain
detected Domain: workinprogresshook.next

XIOC detected Domain: workinprogresshook.next

extracted_from_files

Domain
detected Domain: hook.next

XIOC detected Domain: hook.next

extracted_from_files

Domain
detected Domain: currenthook.next

XIOC detected Domain: currenthook.next

extracted_from_files

Domain
detected Domain: callback.call

XIOC detected Domain: callback.call

extracted_from_files

Domain
detected Domain: newlastbaseupdate.next

XIOC detected Domain: newlastbaseupdate.next

extracted_from_files

Domain
detected Domain: currentlastbaseupdate.next

XIOC detected Domain: currentlastbaseupdate.next

extracted_from_files

Domain
detected Domain: component.name

XIOC detected Domain: component.name

extracted_from_files

Domain
detected Domain: component.compare

XIOC detected Domain: component.compare

extracted_from_files

Domain
detected Domain: lasteffect.next

XIOC detected Domain: lasteffect.next

extracted_from_files

Domain
detected Domain: effect.next

XIOC detected Domain: effect.next

extracted_from_files

Domain
detected Domain: lastrenderphaseupdate.next

XIOC detected Domain: lastrenderphaseupdate.next

extracted_from_files

Domain
detected Domain: newbasequeuelast.next

XIOC detected Domain: newbasequeuelast.next

extracted_from_files

Domain
detected Domain: pendingqueue.next

XIOC detected Domain: pendingqueue.next

extracted_from_files

Domain
detected Domain: originalcallback.call

XIOC detected Domain: originalcallback.call

extracted_from_files

Domain
detected Domain: currenthook2.next

XIOC detected Domain: currenthook2.next

extracted_from_files

Domain
detected Domain: pendingprops.id

XIOC detected Domain: pendingprops.id

extracted_from_files

Domain
detected Domain: families.map

XIOC detected Domain: families.map

extracted_from_files

Domain
detected Domain: finishedwork.memoizedprops.id

XIOC detected Domain: finishedwork.memoizedprops.id

extracted_from_files

Domain
detected Domain: memoize.id

XIOC detected Domain: memoize.id

extracted_from_files

Domain
detected Domain: childreniterator.next

XIOC detected Domain: childreniterator.next

extracted_from_files

Domain
detected Domain: msg.chat

XIOC detected Domain: msg.chat

extracted_from_files

Domain
detected Domain: textarea.select

XIOC detected Domain: textarea.select

extracted_from_files

Domain
detected Domain: findings.map

XIOC detected Domain: findings.map

extracted_from_files

Domain
detected Domain: impactradius.map

XIOC detected Domain: impactradius.map

extracted_from_files

Domain
detected Domain: suspects.map

XIOC detected Domain: suspects.map

extracted_from_files

Domain
detected Domain: parts.map

XIOC detected Domain: parts.map

extracted_from_files

Domain
detected Domain: window.top

XIOC detected Domain: window.top

extracted_from_files

Domain
detected Domain: logs.map

XIOC detected Domain: logs.map

extracted_from_files

Domain
detected Domain: options.map

XIOC detected Domain: options.map

extracted_from_files

Domain
detected Domain: showncitations.map

XIOC detected Domain: showncitations.map

extracted_from_files

Domain
detected Domain: msg.id

XIOC detected Domain: msg.id

extracted_from_files

Domain
detected Domain: messages.map

XIOC detected Domain: messages.map

extracted_from_files

Domain
detected Domain: configstatus.chat

XIOC detected Domain: configstatus.chat

extracted_from_files

Domain
detected Domain: e.target

XIOC detected Domain: e.target

extracted_from_files

URL
detected URL: http://schemas.openxmlformats.org/package/2006/content-types

XIOC detected URL: http://schemas.openxmlformats.org/package/2006/content-types

extracted_from_files

Domain
detected Domain: changelog.md

XIOC detected Domain: changelog.md

extracted_from_files

Domain
detected Domain: microsoft.visualstudio.services.links.support

XIOC detected Domain: microsoft.visualstudio.services.links.support

extracted_from_files

Domain
detected Domain: schemas.microsoft.com

XIOC detected Domain: schemas.microsoft.com

extracted_from_files

Domain
detected Domain: dev.md

XIOC detected Domain: dev.md

extracted_from_files

Domain
detected Domain: entry.id

XIOC detected Domain: entry.id

extracted_from_files

URL
detected URL: https://reactjs.org/link/special-props)

XIOC detected URL: https://reactjs.org/link/special-props)

extracted_from_files

URL
detected URL: https://github.com/facebook/react/issues/3236).

XIOC detected URL: https://github.com/facebook/react/issues/3236).

extracted_from_files

URL
detected URL: http://127.0.0.1:$

XIOC detected URL: http://127.0.0.1:$

extracted_from_files

URL
detected URL: http://127.0.0.1:8000

XIOC detected URL: http://127.0.0.1:8000

extracted_from_files

URL
detected URL: https://github.com/Hafiz408/Nexus/releases/download/v$

XIOC detected URL: https://github.com/Hafiz408/Nexus/releases/download/v$

extracted_from_files

URL
detected URL: https://github.com/Hafiz408/Nexus/releases

XIOC detected URL: https://github.com/Hafiz408/Nexus/releases

extracted_from_files

URL
detected URL: http://www.andismith.com/blog/2012/02/modernizr-prefixed/),

XIOC detected URL: http://www.andismith.com/blog/2012/02/modernizr-prefixed/),

extracted_from_files

URL
detected URL: https://reactjs.org/link/controlled-components

XIOC detected URL: https://reactjs.org/link/controlled-components

extracted_from_files

URL
detected URL: https://github.com/facebook/react/issues

XIOC detected URL: https://github.com/facebook/react/issues

extracted_from_files

URL
detected URL: https://reactjs.org/link/warning-keys

XIOC detected URL: https://reactjs.org/link/warning-keys

extracted_from_files

URL
detected URL: https://reactjs.org/link/invalid-hook-call

XIOC detected URL: https://reactjs.org/link/invalid-hook-call

extracted_from_files

URL
detected URL: https://reactjs.org/link/strict-mode-string-ref',

XIOC detected URL: https://reactjs.org/link/strict-mode-string-ref',

extracted_from_files

URL
detected URL: https://html.spec.whatwg.org/multipage/syntax.html#html-integration-point

XIOC detected URL: https://html.spec.whatwg.org/multipage/syntax.html#html-integration-point

extracted_from_files

URL
detected URL: https://electronjs.org/docs/api/webview-tag

XIOC detected URL: https://electronjs.org/docs/api/webview-tag

extracted_from_files

URL
detected URL: https://reactjs.org/link/react-devtools

XIOC detected URL: https://reactjs.org/link/react-devtools

extracted_from_files

URL
detected URL: https://reactjs.org/link/crossorigin-error

XIOC detected URL: https://reactjs.org/link/crossorigin-error

extracted_from_files

URL
detected URL: https://reactjs.org/link/attribute-behavior

XIOC detected URL: https://reactjs.org/link/attribute-behavior

extracted_from_files

URL
detected URL: https://reactjs.org/link/invalid-aria-props

XIOC detected URL: https://reactjs.org/link/invalid-aria-props

extracted_from_files

URL
detected URL: https://reactjs.org/link/dangerously-set-inner-html

XIOC detected URL: https://reactjs.org/link/dangerously-set-inner-html

extracted_from_files

URL
detected URL: https://reactjs.org/link/rules-of-hooks

XIOC detected URL: https://reactjs.org/link/rules-of-hooks

extracted_from_files

URL
detected URL: https://reactjs.org/link/refs-must-have-owner

XIOC detected URL: https://reactjs.org/link/refs-must-have-owner

extracted_from_files

URL
detected URL: https://reactjs.org/link/strict-mode-string-ref

XIOC detected URL: https://reactjs.org/link/strict-mode-string-ref

extracted_from_files

URL
detected URL: https://reactjs.org/link/legacy-context

XIOC detected URL: https://reactjs.org/link/legacy-context

extracted_from_files

URL
detected URL: https://reactjs.org/link/derived-state

XIOC detected URL: https://reactjs.org/link/derived-state

extracted_from_files

URL
detected URL: https://reactjs.org/link/unsafe-component-lifecycles

XIOC detected URL: https://reactjs.org/link/unsafe-component-lifecycles

extracted_from_files

URL
detected URL: https://reactjs.org/link/wrap-tests-with-act

XIOC detected URL: https://reactjs.org/link/wrap-tests-with-act

extracted_from_files

URL
detected URL: https://reactjs.org/link/setstate-in-render

XIOC detected URL: https://reactjs.org/link/setstate-in-render

extracted_from_files

URL
detected URL: https://reactjs.org/link/hooks-data-fetching

XIOC detected URL: https://reactjs.org/link/hooks-data-fetching

extracted_from_files

URL
detected URL: https://reactjs.org/link/error-boundaries

XIOC detected URL: https://reactjs.org/link/error-boundaries

extracted_from_files

URL
detected URL: https://github.com/Hafiz408/Nexus

XIOC detected URL: https://github.com/Hafiz408/Nexus

extracted_from_files

URL
detected URL: https://reactjs.org/link/react-devtools-faq

XIOC detected URL: https://reactjs.org/link/react-devtools-faq

extracted_from_files

URL
detected URL: https://reactjs.org/link/react-polyfills

XIOC detected URL: https://reactjs.org/link/react-polyfills

extracted_from_files

URL
detected URL: https://reactjs.org/link/switch-to-createroot

XIOC detected URL: https://reactjs.org/link/switch-to-createroot

extracted_from_files

URL
detected URL: https://reactjs.org/link/strict-mode-find-node

XIOC detected URL: https://reactjs.org/link/strict-mode-find-node

extracted_from_files

URL
detected URL: https://github.com/Hafiz408/Nexus/blob/HEAD/DEV.md)

XIOC detected URL: https://github.com/Hafiz408/Nexus/blob/HEAD/DEV.md)

extracted_from_files

URL
detected URL: https://github.com/Hafiz408/Nexus)

XIOC detected URL: https://github.com/Hafiz408/Nexus)

extracted_from_files

URL
detected URL: https://ollama.com)

XIOC detected URL: https://ollama.com)

extracted_from_files

URL
detected URL: https://open-vsx.org/extension/Hafiz408/nexus-ai)

XIOC detected URL: https://open-vsx.org/extension/Hafiz408/nexus-ai)

extracted_from_files

URL
detected URL: https://marketplace.visualstudio.com/items?itemName=Hafiz408.nexus-ai)

XIOC detected URL: https://marketplace.visualstudio.com/items?itemName=Hafiz408.nexus-ai)

extracted_from_files

URL
detected URL: https://raw.githubusercontent.com/Hafiz408/Nexus/main/extension/images/demo.gif

XIOC detected URL: https://raw.githubusercontent.com/Hafiz408/Nexus/main/extension/images/demo.gif

extracted_from_files

URL
detected URL: https://github.com/Hafiz408/Nexus/blob/main/backend/app/retrieval/README.md)

XIOC detected URL: https://github.com/Hafiz408/Nexus/blob/main/backend/app/retrieval/README.md)

extracted_from_files

URL
detected URL: https://github.com/Hafiz408/Nexus#readme

XIOC detected URL: https://github.com/Hafiz408/Nexus#readme

extracted_from_files

URL
detected URL: https://github.com/Hafiz408/Nexus/issues

XIOC detected URL: https://github.com/Hafiz408/Nexus/issues

extracted_from_files

URL
detected URL: https://github.com/Hafiz408/Nexus.git

XIOC detected URL: https://github.com/Hafiz408/Nexus.git

extracted_from_files

IP
detected IP: 4::

XIOC detected IP: 4::

extracted_from_files

IP
detected IP: ::bef

XIOC detected IP: ::bef

extracted_from_files

Domain
detected Domain: parenttype.name

XIOC detected Domain: parenttype.name

extracted_from_files

Domain
detected Domain: fn.call

XIOC detected Domain: fn.call

extracted_from_files

Domain
detected Domain: o.ye

XIOC detected Domain: o.ye

extracted_from_files

IP
detected IP: ::0

XIOC detected IP: ::0

extracted_from_files

Security Analysis Summary

Security Analysis Overview

Nexus AI is a Visual Studio Code Marketplace extension published by Mohammed Hafiz. Version 4.3.1 has been analyzed by the Risky Plugins security platform, receiving a risk score of 84.95/100 (HIGH risk) based on 324 security findings.

Risk Assessment

This extension presents critical security risk. Severe issues were detected, potentially including malware indicators, exposed secrets, or dangerous behaviors. Installation is strongly discouraged until these issues are addressed.

Findings Breakdown

  • Medium: 275 finding(s)
  • Low: 49 finding(s)

What Was Analyzed

The security assessment covers multiple analysis categories:

  • Malware Detection: YARA rule matching against 2,400+ malware signatures
  • Secret Detection: Scanning for exposed API keys, tokens, and credentials
  • Static Analysis: Code-level security analysis for common vulnerability patterns
  • Network Analysis: Detection of suspicious network communications and endpoints
  • Obfuscation Detection: Identification of code obfuscation techniques

Developer Information

Nexus AI is published by Mohammed Hafiz on the Visual Studio Code Marketplace marketplace. The extension has approximately 3 users.

Recommendation

This extension is not recommended for installation without thorough manual review. Consider alternatives with lower risk scores, or contact the developer to address the identified security concerns.

Frequently Asked Questions