VS Code Marketplace Verified

Rexx Language Support

by Broadcom · 11.3K users · 5.0 rating
70055ef2-60d0-5870-92ff-b6a544502b24 | v0.0.24
54/ 100
MEDIUM risk
Analyst verdict
Review before use

The AI review rates the findings as likely false positive, but the risk score (54/100) still counts them.

Analysis record

Analysed
2 weeks ago
Version
v0.0.24
Artifact
SHA256 E41…ACA
Source
Findings (non-IoC)

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

34 detail rows

YARA Rule Matches

9 rules
SeverityRuleHitsFilesMetadata
LOWpostinstall crypto operations 2
dist/desktop/extension.jsdist/web/extension.js
-
LOWpostinstall file manipulation 5
LICENSE.txtlanguage-configuration.jsonsyntaxes/rexx.tmLanguage +2 more
-
LOWpostinstall registry modification 1
syntaxes/rexx.tmLanguage
-
LOWpostinstall obfuscation 2
dist/desktop/extension.jsdist/web/extension.js
-
LOWpostinstall network communication 5
LICENSE.txtREADME.mdsyntaxes/rexx.tmLanguage +2 more
-
LOWpostinstall system command 5
README.mdsyntaxes/rexx.tmLanguagedist/desktop/extension.js +2 more
-
LOWpostinstall file download 3
syntaxes/rexx.tmLanguagedist/desktop/extension.jsdist/web/extension.js
-
LOWNoUseWeakRandom 2
dist/desktop/extension.jsdist/web/extension.js
-
LOWcredential env files 2
dist/desktop/extension.jsdist/web/extension.js
-

Publisher Evidence

Low

Broadcom

Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.

88
Noisy-finding weight
x1.00
Publisher domain
broadcom.com
Observed
Store verification signal
Verified publisher
Verified
Extension portfolio
27
Portfolio

12 evidence rows available.

Finding Categories

6
Network

YARA Rules Matched

9 rules(27 hits)
postinstall crypto operations postinstall file manipulation postinstall registry modification postinstall obfuscation postinstall network communication postinstall system command postinstall file download NoUseWeakRandom credential env files

AI Security Report

AI Security Review

Evidence context: threat category none; evidence quality moderate.

Rexx Language Support Security Analysis

This extension provides language support for Rexx, a scripting language. The analysis reveals standard patterns expected for language support extensions with no evidence of malicious behavior.

Filesystem and Process Access

The extension's network activity appears in extension/dist/desktop/extension.js and extension/dist/web/extension.js files. These are bundled output directories containing minified JavaScript. The NET-FETCH findings (lines 2, 4, 14) and NET-SOCKET_IO findings (lines 4, 9) in these files represent standard network operations for language extensions. Fetch calls commonly retrieve language server binaries, documentation, or update manifests. Socket.io is the standard protocol for communicating with language servers in VS Code extensions.

This network activity is justified by the extension's stated purpose of providing "rich language support" for Rexx code. Language support extensions must download language server components and maintain persistent connections for features like code completion, error checking, and documentation lookup.

Credential Access

No credential-related findings were detected. The secret: 0 count in the threat indicators confirms the extension does not access .env files, SSH keys, cloud credentials, or VS Code's secret storage. The only dependency identified is @vscode/[email protected] in extension/package.json, which is the official VS Code telemetry package used for anonymous usage statistics.

Malware and Obfuscation

Zero malware signatures matched the extension code. No obfuscation patterns were detected, including no invisible Unicode characters in locale files or suspicious minification techniques. The code structure is consistent with legitimate VS Code extensions.

Strongest Counterargument

The six medium-severity network findings might suggest suspicious data transmission. However, these findings originate from bundled dist/ files using standard protocols (fetch, socket.io) that language extensions require. The absence of any actual IOCs (IP addresses or suspicious domains), combined with the lack of credential access or obfuscation, indicates these are false positives from automated detection rules that flag any network activity.

Conclusion

This extension demonstrates the normal behavior profile of a language support tool. The network activity serves legitimate language server communication purposes, no credentials are accessed, and no malware signatures were found. The findings represent expected patterns for VS Code language extensions rather than security concerns.

Key Reasons

  • No malware signatures or obfuscation detected
  • Network activity uses standard protocols for language servers
  • No credential access findings
  • Extension has 10,547 users indicating adoption
  • Findings are in bundled dist/ directories

False Positive Considerations

  • Network findings in dist/ bundled output files
  • Socket.io usage is standard for language server communication
  • Fetch calls are normal for language extensions
  • No actual IOCs or suspicious domains detected

Reviewed 2026-06-02; recommended action: no action; model confidence 85%.

About This Extension

Code4z rich language support extension for Rexx code.

Frequently Asked Questions