JetBrains Marketplace Verified

UnitTestBot for Python

6b950b1c-297f-5f80-a541-043ee7a3d991 | v2023.11
71/ 100
HIGH risk
Analyst verdict
Review before use

The AI review rates the findings as likely false positive, but the risk score (71/100) still counts them.

Analysis record

Analysed
3 days ago
Version
v2023.11
Artifact
SHA256 775…BBE
Source
Findings (non-IoC)

Is UnitTestBot for Python safe?

UnitTestBot for Python generates unit tests for Python projects inside JetBrains IDEs. The listing comes from the JetBrains marketplace, counts around 500 installs, and declares no special permissions in its plugin manifest. Its extracted network endpoints include strings such as "0-.sy", "03r.cz" and "2pm.pk". Those fragments came out of minified Java and JavaScript bundles, where two-letter domain-shaped substrings occur constantly.

One high-severity scanner match landed on YARA--CAP_HookExKeylogger at utbot-intellij-python/lib/jna-platform-5.5.0.jar:11348. That jar carries JNA Platform, a standard library that maps Java calls onto native Windows functions, and it declares bindings for the keyboard hook APIs. A signature tuned for keylogger behavior will hit those bindings every time.

The remaining 227 code-smell results and 1615 address-shaped strings come from compressed third-party code inside the plugin distribution. Generating tests means reading your project's source files and writing new test files, so file access fits the job. The match sits inside a library built to expose Windows API functions, and nothing in these findings shows the plugin sending data anywhere or reading credentials.

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

122 detail rows
Showing 25 of 121 · highest severity first

YARA Rule Matches

1 rule
SeverityRuleHitsFilesMetadata
HIGHCAP HookExKeylogger 1
utbot-intellij-python/lib/jna-platform-5.5.0.jar
Brian C. Bell -- @biebsmalwareguy FP 5%

Publisher Evidence

Limited evidence

278357cd-e42c-45cb-a88a-b33ca4650a19

Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.

37
Noisy-finding weight
x1.00
Publisher domain
utbot.org
Observed
Store verification signal
Not exposed
Not exposed
Extension portfolio
2
Portfolio

12 evidence rows available.

Finding Categories

1
Malware Signatures

YARA Rules Matched

1 rule
CAP HookExKeylogger

AI Security Report

AI Security Review

Evidence context: threat category none; evidence quality moderate.

UnitTestBot for Python (JetBrains marketplace, version 2023.11, about 503 installs) generates unit tests for Python projects. That work requires reading project source and writing new test files into the workspace, so read/write workspace access matches the plugin's stated purpose. The manifest declares no permissions and no host permissions, and the finding set contains no manifest-analysis entries, so nothing here points to access beyond that scope.

Filesystem and process access: nothing in the evidence shows shell execution, postinstall payloads, or code downloaded and run at activation. A test generator spawns Python to run the tests it writes, and no finding contradicts that.

The single high-severity match is YARA--CAP_HookExKeylogger at utbot-intellij-python/lib/jna-platform-5.5.0.jar:11348. jna-platform 5.5.0 is the stock Java Native Access platform artifact, published on Maven Central by the java-native-access project and pulled in by thousands of Java desktop applications. It exposes Java bindings for Windows user32 functions including SetWindowsHookEx, UnhookWindowsHookEx and GetAsyncKeyState. The CAP_HookExKeylogger rule targets the API pattern a keylogger uses, and a library whose whole purpose is to expose those APIs will match it every time.

Credential access: none. There are zero secret findings, and no path pattern such as .env, .git/config, or SSH key material shows up anywhere in the set. The extension does not touch VS Code secret storage, cloud credential files, or browser stores, so there is no credential-theft signal to weigh.

The 1615 IoC entries show where the scanner noise comes from. They read as two-letter TLD shapes: "0-.sy", "0b.by", "0x.is", "2pm.pk". None carries a path, a port, or a resolvable host, and this pattern is what the extractor pulls out of minified JavaScript and compressed Java inside a distribution, where short identifier and hex substrings abound. The 227 code-smell findings are all severity low and land in bundled dependency code, the usual result of running generic rules over a jar-heavy plugin.

The strongest counterargument: a plugin shipping a keylogger signature could be doing the thing the rule describes. That argument fails on three points. The match sits inside a third-party artifact named on Maven Central, not in first-party code. Keylogging needs somewhere to send captured input, and the endpoint list holds no real host to receive it. Keylogging also needs input or credential access, and this finding set contains none of that.

One gap limits how far we can go. The listing's developer field holds a UUID (278357cd-e42c-45cb-a88a-b33ca4650a19) and the description is empty, so we cannot match the maintainer against a known account. That caps confidence below certainty, and it does not change how the individual findings read.

Key Reasons

  • The only high-severity match, YARA--CAP_HookExKeylogger, sits at utbot-intellij-python/lib/jna-platform-5.5.0.jar:11348, the stock JNA Platform artifact whose declared native bindings include Windows keyboard hook functions.
  • All 1615 IoC entries are two-letter TLD-shaped fragments from minified bundles ("0-.sy", "0b.by", "2pm.pk") with no host, path, or port attached.
  • Zero secret, network, obfuscation, tool-poisoning, or manifest-analysis findings, so no credential access and no exfiltration path exists in the set.
  • The 227 code-smell hits are all low severity and land in bundled dependency code inside the distributed jars.
  • Reading source files and writing generated tests is the extension's stated function, so workspace file access sits within scope.

False Positive Considerations

  • YARA CAP keylogger rule matching native Windows API bindings declared inside a stock Maven Central artifact (jna-platform 5.5.0)
  • IoC extractor harvesting two-letter domain-shaped substrings from minified JavaScript and packaged Java
  • 227 low-severity code-smell hits generated by generic rules over bundled dependencies
  • Empty description and UUID-shaped developer field (278357cd-e42c-45cb-a88a-b33ca4650a19) limit publisher verification but produce no threat signal

Reviewed 2026-09-30; recommended action: suppress false positive; model confidence 85%.

About This Extension

UnitTestBot is the tool for automated unit test generation and precise code analysis. Discover UnitTestBot key features in our latest release: generating ready-to-use...

Frequently Asked Questions