UnitTestBot for Python
The AI review rates the findings as likely false positive, but the risk score (71/100) still counts them.
Analysis record
- Analysed
- 3 days ago
- Version
- v2023.11
- Artifact
- SHA256 775…BBE
- Source
- Findings (non-IoC)
Is UnitTestBot for Python safe?
UnitTestBot for Python generates unit tests for Python projects inside JetBrains IDEs. The listing comes from the JetBrains marketplace, counts around 500 installs, and declares no special permissions in its plugin manifest. Its extracted network endpoints include strings such as "0-.sy", "03r.cz" and "2pm.pk". Those fragments came out of minified Java and JavaScript bundles, where two-letter domain-shaped substrings occur constantly.
One high-severity scanner match landed on YARA--CAP_HookExKeylogger at utbot-intellij-python/lib/jna-platform-5.5.0.jar:11348. That jar carries JNA Platform, a standard library that maps Java calls onto native Windows functions, and it declares bindings for the keyboard hook APIs. A signature tuned for keylogger behavior will hit those bindings every time.
The remaining 227 code-smell results and 1615 address-shaped strings come from compressed third-party code inside the plugin distribution. Generating tests means reading your project's source files and writing new test files, so file access fits the job. The match sits inside a library built to expose Windows API functions, and nothing in these findings shows the plugin sending data anywhere or reading credentials.
Evidence ledger
Ranked by severity · findings with a source location link to the code viewer
YARA Rule Matches
1 rule| Severity | Rule | Hits | Files | Metadata |
|---|---|---|---|---|
| HIGH | CAP HookExKeylogger | 1 | utbot-intellij-python/lib/jna-platform-5.5.0.jar | Brian C. Bell -- @biebsmalwareguy FP 5% |
Publisher Evidence
Limited evidence278357cd-e42c-45cb-a88a-b33ca4650a19
Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.
12 evidence rows available.
Finding Categories
YARA Rules Matched
1 ruleAI Security Report
AI Security Review
Evidence context: threat category none; evidence quality moderate.
UnitTestBot for Python (JetBrains marketplace, version 2023.11, about 503 installs) generates unit tests for Python projects. That work requires reading project source and writing new test files into the workspace, so read/write workspace access matches the plugin's stated purpose. The manifest declares no permissions and no host permissions, and the finding set contains no manifest-analysis entries, so nothing here points to access beyond that scope.
Filesystem and process access: nothing in the evidence shows shell execution, postinstall payloads, or code downloaded and run at activation. A test generator spawns Python to run the tests it writes, and no finding contradicts that.
The single high-severity match is YARA--CAP_HookExKeylogger at utbot-intellij-python/lib/jna-platform-5.5.0.jar:11348. jna-platform 5.5.0 is the stock Java Native Access platform artifact, published on Maven Central by the java-native-access project and pulled in by thousands of Java desktop applications. It exposes Java bindings for Windows user32 functions including SetWindowsHookEx, UnhookWindowsHookEx and GetAsyncKeyState. The CAP_HookExKeylogger rule targets the API pattern a keylogger uses, and a library whose whole purpose is to expose those APIs will match it every time.
Credential access: none. There are zero secret findings, and no path pattern such as .env, .git/config, or SSH key material shows up anywhere in the set. The extension does not touch VS Code secret storage, cloud credential files, or browser stores, so there is no credential-theft signal to weigh.
The 1615 IoC entries show where the scanner noise comes from. They read as two-letter TLD shapes: "0-.sy", "0b.by", "0x.is", "2pm.pk". None carries a path, a port, or a resolvable host, and this pattern is what the extractor pulls out of minified JavaScript and compressed Java inside a distribution, where short identifier and hex substrings abound. The 227 code-smell findings are all severity low and land in bundled dependency code, the usual result of running generic rules over a jar-heavy plugin.
The strongest counterargument: a plugin shipping a keylogger signature could be doing the thing the rule describes. That argument fails on three points. The match sits inside a third-party artifact named on Maven Central, not in first-party code. Keylogging needs somewhere to send captured input, and the endpoint list holds no real host to receive it. Keylogging also needs input or credential access, and this finding set contains none of that.
One gap limits how far we can go. The listing's developer field holds a UUID (278357cd-e42c-45cb-a88a-b33ca4650a19) and the description is empty, so we cannot match the maintainer against a known account. That caps confidence below certainty, and it does not change how the individual findings read.
Key Reasons
- The only high-severity match, YARA--CAP_HookExKeylogger, sits at utbot-intellij-python/lib/jna-platform-5.5.0.jar:11348, the stock JNA Platform artifact whose declared native bindings include Windows keyboard hook functions.
- All 1615 IoC entries are two-letter TLD-shaped fragments from minified bundles ("0-.sy", "0b.by", "2pm.pk") with no host, path, or port attached.
- Zero secret, network, obfuscation, tool-poisoning, or manifest-analysis findings, so no credential access and no exfiltration path exists in the set.
- The 227 code-smell hits are all low severity and land in bundled dependency code inside the distributed jars.
- Reading source files and writing generated tests is the extension's stated function, so workspace file access sits within scope.
False Positive Considerations
- YARA CAP keylogger rule matching native Windows API bindings declared inside a stock Maven Central artifact (jna-platform 5.5.0)
- IoC extractor harvesting two-letter domain-shaped substrings from minified JavaScript and packaged Java
- 227 low-severity code-smell hits generated by generic rules over bundled dependencies
- Empty description and UUID-shaped developer field (278357cd-e42c-45cb-a88a-b33ca4650a19) limit publisher verification but produce no threat signal
Reviewed 2026-09-30; recommended action: suppress false positive; model confidence 85%.
About This Extension
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace