JetBrains Marketplace Verified

Baidu Comate

by baidu · 530.0K users · 3.8 rating
80bd61ff-c3da-56df-bb6d-c83e05b19332 | v4.14.3
80/ 100
HIGH risk
No change since v4.14.1
Analyst verdict
Needs follow up

From the RiskyPlugins AI security review of the observed evidence.

Analysis record

Analysed
3 days ago
Version
v4.14.3
Artifact
SHA256 130…66F
Source
Findings (non-IoC)

Is Baidu Comate safe?

Baidu Comate is an AI code assistant for JetBrains IDEs used by over 530,000 developers. The extension declares no special permissions in the marketplace, though the bundled plugin code contains network libraries (axios, socket.io, fetch) that allow it to communicate with Baidu's servers, which is necessary for an AI assistant to function.

The bundle triggered a YARA--CAP_HookExKeylogger detection in jna-platform-5.6.0.jar. This is a false positive. JNA is a standard library for calling native code from Java, used in thousands of legitimate applications. The scan also found network calls in minified plugin files (lines 22152, 25387, 25371 in demo-feature/dist/index.js, for example), but these are normal for bundled npm dependencies and expected for an assistant that sends code context to a remote AI model. Obfuscation findings (OBFUSCATION-unicode_heavy, OBFUSCATION-function_indirect in server.js) match the signatures of minified JavaScript produced by webpack, not intentional obfuscation.

The 3128 IoC hits are mostly noise: minified code produces millions of false matches for property chains and hex sequences. The presence of network libraries in a cloud-connected development tool is not a red flag by itself. However, the combination of obfuscation findings, bundled complexity, and the keylogger signature warrants closer inspection of the actual runtime behavior before installation, even though the findings themselves appear consistent with a legitimate IDE plugin.

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

1000 detail rows
Showing 25 of 133 · highest severity first

YARA Rule Matches

26 rules
SeverityRuleHitsFilesMetadata
HIGHCAP HookExKeylogger 1
comate-intellij-plugin/lib/jna-platform-5.6.0.jar
Brian C. Bell -- @biebsmalwareguy FP 5%
LOWpostinstall file download 111
comate-intellij-plugin/lib/go.jarcomate-intellij-plugin/comate-agent/bin/comate-kernel/assets/skills/code-review/references/rules/Js/JS_STYLE_RULES.mdcomate-intellij-plugin/comate-agent/bin/comate-kernel/server.js +108 more
-
LOWcredential git credentials 8
comate-intellij-plugin/comate-agent/bin/comate-kernel/assets/skills/code-security/scripts/credential_url.pycomate-intellij-plugin/comate-agent/bin/comate-kernel/plugins/f2c/dist/index.jscomate-intellij-plugin/comate-agent/bin/comate-kernel/server.js +5 more
-
LOWSQLInjection 10
comate-intellij-plugin/comate-agent/bin/comate-kernel/assets/skills/code-security/references/vul_repair-python_sql_injection.mdcomate-intellij-plugin/comate-agent/bin/comate-kernel/assets/skills/code-security/references/vul_repair-go_sql_injection.mdcomate-intellij-plugin/comate-agent/bin/comate-kernel/plugins/demo-feature/dist/providers/renderJsx.js +7 more
-
LOWNoUseWeakRandom 13
comate-intellij-plugin/comate-agent/bin/comate-kernel/fallbackServer.jscomate-intellij-plugin/comate-agent/bin/comate-kernel/server.jscomate-intellij-plugin/comate-agent/bin/comate-kernel/plugins/dev-tools/dist/index.js +10 more
-
LOWNoUseEval 7
comate-intellij-plugin/comate-agent/bin/comate-kernel/plugins/testmate/dist/index.jscomate-intellij-plugin/comate-agent/bin/comate-kernel/plugins/iapi/dist/index.jscomate-intellij-plugin/comate-agent/bin/comate-kernel/plugins/devaux/dist/index.js +4 more
-
LOWHavingAPermissiveCrossOriginResourceSharingPolicy 2
comate-intellij-plugin/comate-agent/bin/comate-kernel/plugins/f2c/dist/index.jscomate-intellij-plugin/comate-agent/bin/comate-kernel/server.js
-
LOWpostinstall process injection 1
comate-intellij-plugin/lib/jna-platform-5.6.0.jar
-
LOWBolonyokte 1
comate-intellij-plugin/comate-agent/bin/comate-kernel/server.js
-
LOWcredential env files 64
comate-intellij-plugin/comate-agent/bin/comate-kernel/assets/automations/automation-dataAnalyze/AUTOMATION.mdcomate-intellij-plugin/comate-agent/bin/comate-kernel/plugins/tor/dist/index.jscomate-intellij-plugin/comate-agent/bin/comate-kernel/assets/skills/build-swe-data-auto/scripts/consistency.py +61 more
-
LOWpostinstall persistence mechanism 35
comate-intellij-plugin/comate-agent/bin/comate-kernel/assets/automations/automation-3commitBugAnalyze/AUTOMATION.mdcomate-intellij-plugin/comate-agent/bin/comate-kernel/plugins/demo-feature/dist/index.jscomate-intellij-plugin/comate-agent/bin/comate-kernel/assets/automations/automation-dataAnalyze/AUTOMATION.md +32 more
-
LOWRedirectToUnknownPath 2
comate-intellij-plugin/comate-agent/bin/comate-kernel/plugins/f2c/dist/index.jscomate-intellij-plugin/comate-agent/bin/comate-kernel/server.js
-
LOWCreatingCookiesWithoutTheHttpOnlyFlag 1
comate-intellij-plugin/comate-agent/bin/comate-kernel/server.js
-
LOWWarpStrings 1
comate-intellij-plugin/comate-agent/bin/comate-kernel/assets/skills/baidu-cloud-bos/package-lock.json
-
LOWPM Zip with js 1
comate-intellij-plugin/lib/comate-intellij-plugin-4.14.3-saas.jar
-
LOWServerCertificatesNotVerified 6
comate-intellij-plugin/comate-agent/bin/comate-kernel/plugins/devaux/dist/index.jscomate-intellij-plugin/comate-agent/bin/comate-kernel/plugins/f2c/dist/index.jscomate-intellij-plugin/comate-agent/bin/comate-kernel/server.js +3 more
-
LOWpostinstall network communication 102
comate-intellij-plugin/comate-agent/bin/comate-kernel/assets/skills/build-swe-data-auto/scripts/gateway_adapter.pycomate-intellij-plugin/comate-agent/bin/comate-kernel/assets/skills/build-swe-data-auto/scripts/mutation.pycomate-intellij-plugin/comate-agent/bin/comate-kernel/plugins/casebuilder/dist/index.js +99 more
-
LOWOriginsNotVerified 6
comate-intellij-plugin/comate-agent/bin/comate-kernel/plugins/devaux/dist/index.jscomate-intellij-plugin/comate-agent/bin/comate-kernel/plugins/f2c/dist/index.jscomate-intellij-plugin/comate-agent/bin/comate-kernel/plugins/testmate/dist/index.js +3 more
-
LOWUsingShellInterpreterWhenExecutingOSCommands 15
comate-intellij-plugin/comate-agent/bin/comate-kernel/plugins/git/dist/index.jscomate-intellij-plugin/comate-agent/bin/comate-kernel/plugins/jarvis/dist/index.jscomate-intellij-plugin/comate-agent/bin/comate-kernel/plugins/weiyun/dist/index.js +12 more
-
LOWpostinstall crypto operations 12
comate-intellij-plugin/comate-agent/bin/comate-kernel/plugins/demo-feature/dist/index.jscomate-intellij-plugin/comate-agent/bin/comate-kernel/assets/skills/icode/references/feature/submit-cr.mdcomate-intellij-plugin/comate-agent/bin/comate-kernel/plugins/security/dist/index.js +9 more
-
LOWpostinstall system command 335
comate-intellij-plugin/comate-agent/bin/comate-kernel/assets/skills/code-security/scripts/kernel_socket.pycomate-intellij-plugin/comate-agent/bin/comate-kernel/assets/skills/icode/references/api/get_diff_content.mdcomate-intellij-plugin/lib/sqljet-1.1.15.jar +332 more
-
LOWNoRenderContentFromRequest 1
comate-intellij-plugin/comate-agent/bin/comate-kernel/assets/skills/code-security/scripts/kernel_socket.py
-
LOWpostinstall environment access 1
comate-intellij-plugin/comate-agent/bin/comate-kernel/plugins/smartapp/dist/index.js
-
LOWCreatingCookiesWithoutTheSecureFlag 1
comate-intellij-plugin/comate-agent/bin/comate-kernel/server.js
-
LOWpostinstall obfuscation 120
comate-intellij-plugin/comate-agent/bin/comate-kernel/assets/skills/create-memory/scripts/extract_sessions.pycomate-intellij-plugin/comate-agent/bin/comate-kernel/assets/skills/create-skill/agents/comparator.mdcomate-intellij-plugin/comate-agent/bin/comate-kernel/assets/skills/code-security/references/vul_repair-go_ssrf.md +117 more
-
LOWpostinstall registry modification 10
comate-intellij-plugin/comate-agent/bin/comate-kernel/plugins/smartapp/dist/index.jscomate-intellij-plugin/lib/guava-32.1.3-jre.jarcomate-intellij-plugin/comate-agent/bin/comate-kernel/plugins/paddle/dist/index.js +7 more
-

Network Indicators

Concrete URLs, domains, IPs, emails, and hashes extracted from the analyzed artifact.

3,126 total
...

Network indicators are queued for lazy loading

Scroll this section into view to load the detailed rows.

Publisher Evidence

Low

baidu

Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.

97
Noisy-finding weight
x1.00
Publisher domain
baidu.com
Observed
Store verification signal
Verified publisher
Verified
Extension portfolio
33
Portfolio

11 evidence rows available.

Finding Categories

1
Malware Signatures
2
Obfuscation
131
Network
3,126
IoC Indicators

YARA Rules Matched

26 rules(867 hits)
CAP HookExKeylogger postinstall file download credential git credentials SQLInjection NoUseWeakRandom NoUseEval HavingAPermissiveCrossOriginResourceSharingPolicy postinstall process injection Bolonyokte credential env files postinstall persistence mechanism RedirectToUnknownPath CreatingCookiesWithoutTheHttpOnlyFlag WarpStrings PM Zip with js ServerCertificatesNotVerified +10 more

AI Security Report

AI Security Review

Evidence context: threat category unknown malware; evidence quality moderate.

Baidu Comate is a JetBrains IDE extension with over 530k users. The extension declares no special permissions in the marketplace manifest, but the bundled code reveals extensive network access and file I/O typical of an AI assistant plugin that communicates with remote services.

The most concerning finding is the YARA--CAP_HookExKeylogger signature in /comate-intellij-plugin/lib/jna-platform-5.6.0.jar:11585. This is a false positive. The signature triggers on jna-platform, a standard Java Native Access library used for cross-platform native function calls. JNA is widely used in legitimate Java applications and carries no intrinsic keylogging capability. The JetBrains marketplace would not permit a keylogger to distribute publicly at this scale.

Network activity appears in minified plugin code: axios and fetch calls in comate-agent/bin/comate-kernel/plugins/demo-feature/dist/index.js, socket.io in the f2c plugin, and git integration in git plugin. These are found at lines 22152, 25387, 25383, 25371, 25367, 25358, 25333 and others. The presence of network calls in a plugin designed to provide AI-powered code suggestions is expected. The bundled JavaScript is minified (webpack/esbuild output), which creates noise: each of the dozens of npm packages included in dist/ files triggers its own network findings.

Obfuscation flags on comate-agent/bin/comate-kernel/server.js (OBFUSCATION-unicode_heavy, OBFUSCATION-function_indirect) are consistent with minified source code, not deliberate obfuscation intended to hide malicious logic. Minification is standard practice in Node.js/browser builds.

The IoC count (3128 total) is high but misleading. The vast majority are false positives from IoC extraction on minified code: property chains misread as domains, hex substrings from compressed syntax misidentified as IPv6 fragments. The network_endpoints list includes filenames like 2026-07-06-ducc-skill-approval-no-button.md and markdown paths, which are not actual external endpoints but noise from the extraction process.

The strongest counterargument is that the plugin runs on JetBrains infrastructure with 530k users and version 4.14.3 indicates a mature, actively maintained project. However, the obfuscation findings combined with the keylogger signature and bundled network code create enough uncertainty to warrant runtime behavior analysis before full confidence can be established. The finding nature does not indicate confirmed malicious intent, but the bundled complexity makes it difficult to rule out unintended data access.

Key Reasons

  • YARA--CAP_HookExKeylogger signature detected in jna-platform-5.6.0.jar, a legitimate JNA library often misidentified by broad YARA rules
  • Network activity (axios, fetch, socket.io) found in minified dist/ plugin bundles (demo-feature, git, f2c, dev-tools), consistent with bundled dependencies
  • OBFUSCATION-unicode_heavy and OBFUSCATION-function_indirect in server.js; likely minified output, not intentional obfuscation
  • Large IoC count (3128) but mostly false positives from minified code and bundled npm packages
  • 530k users and JetBrains marketplace presence suggest some legitimate distribution, but findings require verification

False Positive Considerations

  • YARA rule CAP_HookExKeylogger fires on jna-platform library, a standard Java FFI dependency—not malware
  • Network findings in dist/ files from webpack/esbuild bundled code, not source-level malicious activity
  • Obfuscation findings match minified JavaScript output pattern (server.js, bundled plugins), not deliberate obfuscation
  • IoC volume inflated by CDN and package manager domains in bundled dependencies

Reviewed 2026-09-29; recommended action: runtime analysis; model confidence 62%.

JetBrains version history

Risk trend by version

3 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.

Selected
80
Change since first
No change
Change from previous
No change
Versions:
First analyzed version
4.14.0
Sep 10, 2026
Risk range
80 to 80
Across analyzed versions
Latest analyzed version
4.14.3
Sep 28, 2026
Selected version
high
Version
v4.14.3
3 days ago
Risk score
80
Findings
4605
Change vs previous
No change

Pick any point on the chart to explore that version's code below.

About This Extension

Baidu Comate: Code with agility, stay ahead - your intelligent coding companion that truly understands you Baidu Comate is an innovative AI-powered coding assistant...

Frequently Asked Questions