VS Code Marketplace Verified

Device Simulator Express

by Microsoft · 15.0K users · 4.5 rating
7dbc145a-1044-5361-8178-6e7ab904f086 | v2022.0.0
63/ 100
MEDIUM risk
Risk verdict
Review before use

Score-based assessment (medium risk, 63/100). No analyst review available.

Analysis record

Analysed
2 weeks ago
Version
v2022.0.0
Artifact
SHA256 917…BB6
Source
Findings (non-IoC)

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

285 detail rows
Showing 25 of 96 · highest severity first

YARA Rule Matches

15 rules
SeverityRuleHitsFilesMetadata
LOWNoUseEval 1
out/simulator.js
-
LOWpostinstall file download 11
out/python_constants.pylocales/en/package.i18n.jsondocs/install.md +8 more
-
LOWSQLInjection 1
out/simulator.js
-
LOWNoUseWeakRandom 1
out/simulator.js
-
LOWcredential env files 2
out/simulator.jsout/extension.js
-
LOWpostinstall persistence mechanism 3
out/simulator.jsout/base_circuitpython/fonts/ter-u12n.bdfout/micropython/utime.py
-
LOWDebuggerStatementsShouldNotBeUsed 24
out/clue/adafruit_slideshow.pyout/latest_release_note.jsout/common/debugger_communication_client.py +21 more
-
LOWLocalStorageShouldNotBeUsed 1
out/simulator.js
-
LOWpostinstall file manipulation 22
out/view/components/clue/ClueImage.jsout/simulator.jsout/view/components/microbit/Microbit.js +19 more
-
LOWpostinstall system command 25
ThirdPartyNotices.txtout/constants.jslocales/en/out/constants.i18n.json +22 more
-
LOWpostinstall environment access 4
webpack.config.jsout/base_circuitpython/displayio/test/test_group.pyout/base_circuitpython/__init__.py +1 more
-
LOWpostinstall registry modification 3
out/simulator.jsout/base_circuitpython/fonts/ter-u12n.bdfThirdPartyNotices.txt
-
LOWpostinstall obfuscation 21
out/view/components/toolbar/GenericSliderComponent.jsassets/readmeFiles/otherSensors.gifout/clue/adafruit_slideshow.py +18 more
-
LOWpostinstall network communication 67
assets/readmeFiles/clue/check_preview_mode.gifout/constants.jsout/common/debugger_communication_client.py +64 more
-
LOWpostinstall crypto operations 3
ThirdPartyNotices.txt.pylintrcout/simulator.js
-

Network Indicators

Concrete URLs, domains, IPs, emails, and hashes extracted from the analyzed artifact.

19,048 total
...

Network indicators are queued for lazy loading

Scroll this section into view to load the detailed rows.

Publisher Evidence

High

Microsoft

Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.

100
Noisy-finding weight
x0.50
Publisher domain
microsoft.com
Trusted match
Store verification signal
Verified publisher
Verified
Extension portfolio
653
Portfolio

11 evidence rows available.

Finding Categories

69
Network
19,048
IoC Indicators

YARA Rules Matched

15 rules(189 hits)
NoUseEval postinstall file download SQLInjection NoUseWeakRandom credential env files postinstall persistence mechanism DebuggerStatementsShouldNotBeUsed LocalStorageShouldNotBeUsed postinstall file manipulation postinstall system command postinstall environment access postinstall registry modification postinstall obfuscation postinstall network communication postinstall crypto operations

Security Analysis Summary

Security Analysis Overview

Device Simulator Express is a Visual Studio Code Marketplace extension published by Microsoft. Version 2022.0.0 has been analyzed by the Risky Plugins security platform, receiving a risk score of 63.05/100 (MEDIUM risk) based on 19333 security findings.

Risk Assessment

This extension presents moderate security risk. Several findings were detected that may warrant attention. Users should carefully review the permissions and findings before installation.

Findings Breakdown

  • Medium: 19117 finding(s)
  • Low: 216 finding(s)

What Was Analyzed

The security assessment covers multiple analysis categories:

  • Malware Detection: YARA rule matching against 2,400+ malware signatures
  • Secret Detection: Scanning for exposed API keys, tokens, and credentials
  • Static Analysis: Code-level security analysis for common vulnerability patterns
  • Network Analysis: Detection of suspicious network communications and endpoints
  • Obfuscation Detection: Identification of code obfuscation techniques

Developer Information

Device Simulator Express is published by Microsoft on the Visual Studio Code Marketplace marketplace. The extension has approximately 15K users.

Recommendation

This extension is not recommended for installation without thorough manual review. Consider alternatives with lower risk scores, or contact the developer to address the identified security concerns.

About This Extension

Device Simulator Express, a Microsoft Garage project

Frequently Asked Questions