Notepad++ Plugins

NppExec

6bbc0bb4-fae2-5acc-8d10-9f9a5f54b757 | v0.8.12.1
64/ 100
MEDIUM risk
+19 since v0.8.10
Analyst verdict
Review before use

The AI review rates the findings as likely false positive, but the risk score (64/100) still counts them.

No individual score drivers were recorded for this analysis.

Analysis record

Analysed
3 days ago
Version
v0.8.12.1
Artifact
SHA256 A87…D12
Source
Findings (non-IoC)

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

92 detail rows
Showing 25 of 92 · highest severity first

Finding Categories

AI Security Report

AI Security Review

Evidence context: threat category none; evidence quality moderate.

NppExec is a long-standing Notepad++ plugin that lets users run commands and scripts without leaving the editor. Its stated purpose — executing external processes — legitimately requires the ability to spawn child processes and read workspace files to pass as arguments. The evidence shows no credential-access findings targeting .env, SSH keys, or cloud secrets; the only findings are a single critical obfuscation alert on the native DLL (OBFUSCATION-supply_chain_binary at NppExec.dll:0), 65 medium-severity IOC matches, and 157 low-severity code-smell hits. The IOC list consists largely of strings pulled from the binary: code fragments like console.info, location.search, sys.java, test.ps, and sel.ps, plus legitimate domains such as scintilla.org (the editing component Notepad++ uses), d0vgan.github.io (the developer's GitHub), www.gnu.org, en.wikipedia.org, and www.paypal.com (donation link). These are not suspicious command-and-control endpoints. The code-smell findings are YARA quality rules that fire on any non-trivial compiled or bundled code and are classified as noise in the platform guidance. The strongest counterargument is the critical obfuscation finding on the main DLL. However, native Notepad++ plugins are compiled C++ binaries, often packed or protected for size and anti-tampering; obfuscation detectors frequently flag legitimate packed binaries as supply-chain obfuscation. No malware signatures matched, no network beaconing was observed, and the plugin's process-spawning behavior aligns exactly with its documented feature set. The findings match three known false-positive drivers: obfuscation alerts on native binaries, IOC extractor garbage on code strings, and code-smell YARA rules.

Key Reasons

  • Known legitimate Notepad++ plugin with established history
  • No malware signatures matched
  • IOC findings are code strings and legitimate domains
  • Code-smell findings are known noise category
  • Plugin purpose (command execution) justifies process spawn capability

False Positive Considerations

  • OBFUSCATION-supply_chain_binary on native DLL
  • IOC extractor garbage on code strings
  • Code-smell YARA rules (known noise)

Reviewed 2026-09-29; recommended action: suppress false positive; model confidence 85%.

Notepad++ version history

Risk trend by version

2 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.

Selected
64
Change since first
+19
Change from previous
+19
Versions:
First analyzed version
0.8.10
Apr 5, 2026
Risk range
45 to 64
Across analyzed versions
Latest analyzed version
0.8.12.1
Sep 28, 2026
Selected version
medium
Version
v0.8.12.1
3 days ago
Risk score
64
Findings
315
Change vs previous
+19

Pick any point on the chart to explore that version's code below.

Frequently Asked Questions