The AI review rates the findings as likely false positive, but the risk score (64/100) still counts them.
No individual score drivers were recorded for this analysis.
Analysis record
- Analysed
- 3 days ago
- Version
- v0.8.12.1
- Artifact
- SHA256 A87…D12
- Source
- Findings (non-IoC)
Evidence ledger
Ranked by severity · findings with a source location link to the code viewer
Finding Categories
AI Security Report
AI Security Review
Evidence context: threat category none; evidence quality moderate.
NppExec is a long-standing Notepad++ plugin that lets users run commands and scripts without leaving the editor. Its stated purpose — executing external processes — legitimately requires the ability to spawn child processes and read workspace files to pass as arguments. The evidence shows no credential-access findings targeting .env, SSH keys, or cloud secrets; the only findings are a single critical obfuscation alert on the native DLL (OBFUSCATION-supply_chain_binary at NppExec.dll:0), 65 medium-severity IOC matches, and 157 low-severity code-smell hits. The IOC list consists largely of strings pulled from the binary: code fragments like console.info, location.search, sys.java, test.ps, and sel.ps, plus legitimate domains such as scintilla.org (the editing component Notepad++ uses), d0vgan.github.io (the developer's GitHub), www.gnu.org, en.wikipedia.org, and www.paypal.com (donation link). These are not suspicious command-and-control endpoints. The code-smell findings are YARA quality rules that fire on any non-trivial compiled or bundled code and are classified as noise in the platform guidance. The strongest counterargument is the critical obfuscation finding on the main DLL. However, native Notepad++ plugins are compiled C++ binaries, often packed or protected for size and anti-tampering; obfuscation detectors frequently flag legitimate packed binaries as supply-chain obfuscation. No malware signatures matched, no network beaconing was observed, and the plugin's process-spawning behavior aligns exactly with its documented feature set. The findings match three known false-positive drivers: obfuscation alerts on native binaries, IOC extractor garbage on code strings, and code-smell YARA rules.
Key Reasons
- Known legitimate Notepad++ plugin with established history
- No malware signatures matched
- IOC findings are code strings and legitimate domains
- Code-smell findings are known noise category
- Plugin purpose (command execution) justifies process spawn capability
False Positive Considerations
- OBFUSCATION-supply_chain_binary on native DLL
- IOC extractor garbage on code strings
- Code-smell YARA rules (known noise)
Reviewed 2026-09-29; recommended action: suppress false positive; model confidence 85%.
Notepad++ version history
Risk trend by version
2 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.
Pick any point on the chart to explore that version's code below.
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace