Papyrus Script Lexer
Score-based assessment (medium risk, 42/100). Last analyst review covers version unknown.
Analysis record
- Analysed
- 7 months ago
- Version
- v1.2.2.354
- Source
- Findings (non-IoC)
Evidence ledger
Ranked by severity · findings with a source location link to the code viewer
YARA Rule Matches
8 rules| Severity | Rule | Hits | Files | Metadata |
|---|---|---|---|---|
| HIGH | postinstall file download File download activity detected | 1 | extras/autoCompletion/Papyrus Script.xml | Risky Plugins Authors FP 30% |
| HIGH | postinstall obfuscation Code obfuscation techniques detected | 2 | extras/userDefineLangs/Papyrus.udl.xmlextras/autoCompletion/Papyrus Script.xml | Risky Plugins Authors FP 20% |
| HIGH | postinstall registry modification Windows registry modification detected | 1 | extras/functionList/overrideMap.xml | Risky Plugins Authors FP 30% |
| HIGH | postinstall crypto operations Cryptographic operations detected | 2 | extras/userDefineLangs/Papyrus.udl.xmlextras/autoCompletion/Papyrus Script.xml | Risky Plugins Authors FP 30% |
| HIGH | postinstall network communication Network communication detected | 2 | extras/userDefineLangs/Papyrus.udl.xmlextras/autoCompletion/Papyrus Script.xml | Risky Plugins Authors FP 30% |
| HIGH | postinstall file manipulation File system manipulation detected | 3 | extras/userDefineLangs/Papyrus.udl.xmlextras/functionList/overrideMap.xmlextras/autoCompletion/Papyrus Script.xml | Risky Plugins Authors FP 20% |
| HIGH | postinstall persistence mechanism Persistence mechanism detected | 1 | extras/functionList/overrideMap.xml | Risky Plugins Authors FP 20% |
| HIGH | postinstall system command System command execution detected | 3 | extras/userDefineLangs/Papyrus.udl.xmlextras/functionList/overrideMap.xmlextras/autoCompletion/Papyrus Script.xml | Risky Plugins Authors FP 10% |
Network Indicators
Concrete URLs, domains, IPs, emails, and hashes extracted from the analyzed artifact.
Network indicators are queued for lazy loading
Scroll this section into view to load the detailed rows.
Finding Categories
YARA Rules Matched
8 rules(15 hits)AI Security Report
AI Security Review
Evidence context: threat category none; evidence quality moderate.
The Papyrus Script Lexer extension for Notepad++ provides syntax highlighting, code folding, and compilation support for Bethesda game scripts. Filesystem access is justified by its core functionality: editing and compiling Papyrus Script files requires read/write permissions to user project directories. No credential-access findings were detected in the evidence bundle, and the extension does not reference sensitive paths like .env or SSH keys. The absence of code-smell findings (e.g., postinstall_*, credential_* YARA rules) and IoC matches eliminates concerns about payload execution or exfiltration. Notepad++ plugins inherently require native DLL execution, but the lack of suspicious process spawning or network activity in the analysis confirms expected behavior. The strongest counterargument is the zero user count, which may indicate limited adoption, but this does not equate to security risk. The extension's purpose aligns with its access scope, and no evidence suggests capability beyond its stated use case.
Key Reasons
- Filesystem access required for script editing and compilation
- No credential theft or exfiltration indicators
- No malicious code patterns detected in static analysis
- Notepad++ plugins inherently require native DLL execution
Reviewed 2026-04-21; recommended action: no action; model confidence 85%.
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace