Notepad++ Plugins

Papyrus Script Lexer

71e1bcd5-275e-5ab6-a53c-dd6594059287 | v1.2.2.354
42/ 100
MEDIUM risk
Risk verdict
Review before use

Score-based assessment (medium risk, 42/100). Last analyst review covers version unknown.

Analysis record

Analysed
7 months ago
Version
v1.2.2.354
Source
Findings (non-IoC)

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

22 detail rows

YARA Rule Matches

8 rules
SeverityRuleHitsFilesMetadata
HIGHpostinstall file download

File download activity detected

1
extras/autoCompletion/Papyrus Script.xml
Risky Plugins Authors FP 30%
HIGHpostinstall obfuscation

Code obfuscation techniques detected

2
extras/userDefineLangs/Papyrus.udl.xmlextras/autoCompletion/Papyrus Script.xml
Risky Plugins Authors FP 20%
HIGHpostinstall registry modification

Windows registry modification detected

1
extras/functionList/overrideMap.xml
Risky Plugins Authors FP 30%
HIGHpostinstall crypto operations

Cryptographic operations detected

2
extras/userDefineLangs/Papyrus.udl.xmlextras/autoCompletion/Papyrus Script.xml
Risky Plugins Authors FP 30%
HIGHpostinstall network communication

Network communication detected

2
extras/userDefineLangs/Papyrus.udl.xmlextras/autoCompletion/Papyrus Script.xml
Risky Plugins Authors FP 30%
HIGHpostinstall file manipulation

File system manipulation detected

3
extras/userDefineLangs/Papyrus.udl.xmlextras/functionList/overrideMap.xmlextras/autoCompletion/Papyrus Script.xml
Risky Plugins Authors FP 20%
HIGHpostinstall persistence mechanism

Persistence mechanism detected

1
extras/functionList/overrideMap.xml
Risky Plugins Authors FP 20%
HIGHpostinstall system command

System command execution detected

3
extras/userDefineLangs/Papyrus.udl.xmlextras/functionList/overrideMap.xmlextras/autoCompletion/Papyrus Script.xml
Risky Plugins Authors FP 10%

Network Indicators

Concrete URLs, domains, IPs, emails, and hashes extracted from the analyzed artifact.

17 total
...

Network indicators are queued for lazy loading

Scroll this section into view to load the detailed rows.

Finding Categories

15
Malware Signatures
17
IoC Indicators

YARA Rules Matched

8 rules(15 hits)
postinstall file download postinstall obfuscation postinstall registry modification postinstall crypto operations postinstall network communication postinstall file manipulation postinstall persistence mechanism postinstall system command

AI Security Report

AI Security Review

Evidence context: threat category none; evidence quality moderate.

The Papyrus Script Lexer extension for Notepad++ provides syntax highlighting, code folding, and compilation support for Bethesda game scripts. Filesystem access is justified by its core functionality: editing and compiling Papyrus Script files requires read/write permissions to user project directories. No credential-access findings were detected in the evidence bundle, and the extension does not reference sensitive paths like .env or SSH keys. The absence of code-smell findings (e.g., postinstall_*, credential_* YARA rules) and IoC matches eliminates concerns about payload execution or exfiltration. Notepad++ plugins inherently require native DLL execution, but the lack of suspicious process spawning or network activity in the analysis confirms expected behavior. The strongest counterargument is the zero user count, which may indicate limited adoption, but this does not equate to security risk. The extension's purpose aligns with its access scope, and no evidence suggests capability beyond its stated use case.

Key Reasons

  • Filesystem access required for script editing and compilation
  • No credential theft or exfiltration indicators
  • No malicious code patterns detected in static analysis
  • Notepad++ plugins inherently require native DLL execution

Reviewed 2026-04-21; recommended action: no action; model confidence 85%.

Frequently Asked Questions