Baidu Comate
From the RiskyPlugins AI security review of the observed evidence.
Analysis record
- Analysed
- 3 days ago
- Version
- v4.14.3
- Artifact
- SHA256 130…66F
- Source
- Findings (non-IoC)
Is Baidu Comate safe?
Baidu Comate is an AI code assistant for JetBrains IDEs used by over 530,000 developers. The extension declares no special permissions in the marketplace, though the bundled plugin code contains network libraries (axios, socket.io, fetch) that allow it to communicate with Baidu's servers, which is necessary for an AI assistant to function.
The bundle triggered a YARA--CAP_HookExKeylogger detection in jna-platform-5.6.0.jar. This is a false positive. JNA is a standard library for calling native code from Java, used in thousands of legitimate applications. The scan also found network calls in minified plugin files (lines 22152, 25387, 25371 in demo-feature/dist/index.js, for example), but these are normal for bundled npm dependencies and expected for an assistant that sends code context to a remote AI model. Obfuscation findings (OBFUSCATION-unicode_heavy, OBFUSCATION-function_indirect in server.js) match the signatures of minified JavaScript produced by webpack, not intentional obfuscation.
The 3128 IoC hits are mostly noise: minified code produces millions of false matches for property chains and hex sequences. The presence of network libraries in a cloud-connected development tool is not a red flag by itself. However, the combination of obfuscation findings, bundled complexity, and the keylogger signature warrants closer inspection of the actual runtime behavior before installation, even though the findings themselves appear consistent with a legitimate IDE plugin.
Evidence ledger
Ranked by severity · findings with a source location link to the code viewer
YARA Rule Matches
25 rules| Severity | Rule | Hits | Files | Metadata |
|---|---|---|---|---|
| HIGH | CAP HookExKeylogger | 1 | comate-intellij-plugin/lib/jna-platform-5.6.0.jar | Brian C. Bell -- @biebsmalwareguy FP 5% |
| LOW | UsingCommandLineArguments | 14 | comate-intellij-plugin/comate-agent/bin/comate-kernel/plugins/jarvis/dist/index.jscomate-intellij-plugin/comate-agent/bin/comate-kernel/completion-agent/server.cjscomate-intellij-plugin/comate-agent/bin/comate-kernel/server.js +11 more | - |
| LOW | DebuggerStatementsShouldNotBeUsed | 15 | comate-intellij-plugin/comate-agent/bin/comate-kernel/plugins/weiyun/dist/index.jscomate-intellij-plugin/comate-agent/bin/comate-kernel/plugins/demo-feature/dist/index.jscomate-intellij-plugin/comate-agent/bin/comate-kernel/assets/skills/create-subagent/SKILL.md +12 more | - |
| LOW | LocalStorageShouldNotBeUsed | 1 | comate-intellij-plugin/comate-agent/bin/comate-kernel/server.js | - |
| LOW | credential ssh keys | 3 | comate-intellij-plugin/comate-agent/bin/comate-kernel/assets/skills/icode/references/feature/ssh-setup.mdcomate-intellij-plugin/comate-agent/bin/comate-kernel/assets/skills/build-swe-data-auto/tests/test_image_builder.pycomate-intellij-plugin/comate-agent/bin/comate-kernel/assets/skills/icode/SKILL.md | - |
| LOW | postinstall file download | 111 | comate-intellij-plugin/lib/go.jarcomate-intellij-plugin/comate-agent/bin/comate-kernel/assets/skills/build-swe-data-auto/SKILL.mdcomate-intellij-plugin/lib/jna-platform-5.6.0.jar +108 more | - |
| LOW | credential git credentials | 8 | comate-intellij-plugin/comate-agent/bin/comate-kernel/assets/skills/build-swe-data-auto/scripts/image_builder.pycomate-intellij-plugin/comate-agent/bin/comate-kernel/assets/skills/build-swe-data-auto/scripts/__pycache__/image_builder.cpython-39.pyccomate-intellij-plugin/comate-agent/bin/comate-kernel/assets/skills/code-security/scripts/utils.py +5 more | - |
| LOW | SQLInjection | 10 | comate-intellij-plugin/comate-agent/bin/comate-kernel/assets/skills/code-security/references/vul_repair-java_sql_injection.mdcomate-intellij-plugin/comate-agent/bin/comate-kernel/assets/skills/code-security/references/vul_repair-go_sql_injection.mdcomate-intellij-plugin/comate-agent/bin/comate-kernel/assets/skills/code-fixer/references/Js/JS_CODE_FIX_COMPLETE.md +7 more | - |
| LOW | NoUseWeakRandom | 13 | comate-intellij-plugin/comate-agent/bin/comate-kernel/plugins/devaux/dist/index.jscomate-intellij-plugin/comate-agent/bin/comate-kernel/plugins/git/dist/index.jscomate-intellij-plugin/comate-agent/bin/comate-kernel/plugins/jarvis/dist/index.js +10 more | - |
| LOW | NoUseEval | 7 | comate-intellij-plugin/comate-agent/bin/comate-kernel/plugins/testmate/dist/index.jscomate-intellij-plugin/comate-agent/bin/comate-kernel/plugins/iapi/dist/index.jscomate-intellij-plugin/comate-agent/bin/comate-kernel/server.js +4 more | - |
| LOW | HavingAPermissiveCrossOriginResourceSharingPolicy | 2 | comate-intellij-plugin/comate-agent/bin/comate-kernel/server.jscomate-intellij-plugin/comate-agent/bin/comate-kernel/plugins/f2c/dist/index.js | - |
| LOW | postinstall process injection | 1 | comate-intellij-plugin/lib/jna-platform-5.6.0.jar | - |
| LOW | Bolonyokte | 1 | comate-intellij-plugin/comate-agent/bin/comate-kernel/server.js | - |
| LOW | postinstall network communication | 102 | comate-intellij-plugin/comate-agent/bin/comate-kernel/assets/skills/build-swe-data-auto/tests/test_stub_probe.pycomate-intellij-plugin/comate-agent/bin/comate-kernel/assets/skills/popo/scripts/pull.pycomate-intellij-plugin/comate-agent/bin/comate-kernel/completion-agent/server.cjs +99 more | - |
| LOW | OriginsNotVerified | 6 | comate-intellij-plugin/comate-agent/bin/comate-kernel/server.jscomate-intellij-plugin/comate-agent/bin/comate-kernel/completion-agent/server.cjscomate-intellij-plugin/comate-agent/bin/comate-kernel/plugins/testmate/dist/index.js +3 more | - |
| LOW | UsingShellInterpreterWhenExecutingOSCommands | 15 | comate-intellij-plugin/comate-agent/bin/comate-kernel/server.jscomate-intellij-plugin/comate-agent/bin/comate-kernel/plugins/paddle/dist/index.jscomate-intellij-plugin/comate-agent/bin/comate-kernel/plugins/weiyun/dist/index.js +12 more | - |
| LOW | postinstall crypto operations | 24 | comate-intellij-plugin/comate-agent/bin/comate-kernel/plugins/demo-feature/dist/index.jscomate-intellij-plugin/comate-agent/bin/comate-kernel/assets/skills/icode/references/feature/submit-cr.mdcomate-intellij-plugin/comate-agent/bin/comate-kernel/plugins/security/dist/index.js +21 more | - |
| LOW | postinstall system command | 335 | comate-intellij-plugin/comate-agent/bin/comate-kernel/fallbackServer.jscomate-intellij-plugin/comate-agent/bin/comate-kernel/assets/skills/icode/scripts/merge-cr.shcomate-intellij-plugin/comate-agent/bin/comate-kernel/server.js +332 more | - |
| LOW | NoRenderContentFromRequest | 1 | comate-intellij-plugin/comate-agent/bin/comate-kernel/assets/skills/code-security/scripts/kernel_socket.py | - |
| LOW | postinstall environment access | 26 | comate-intellij-plugin/comate-agent/bin/comate-kernel/plugins/testmate/dist/index.jscomate-intellij-plugin/comate-agent/bin/comate-kernel/plugins/front-end-skills/dist/index.jscomate-intellij-plugin/comate-agent/bin/comate-kernel/plugins/appdev/dist/index.js +23 more | - |
| LOW | CreatingCookiesWithoutTheSecureFlag | 1 | comate-intellij-plugin/comate-agent/bin/comate-kernel/server.js | - |
| LOW | postinstall obfuscation | 120 | comate-intellij-plugin/comate-agent/bin/comate-kernel/assets/skills/build-swe-data-auto/tests/test_container_evaluator.pycomate-intellij-plugin/comate-agent/bin/comate-kernel/assets/skills/code-fixer/references/Python/PYTHON_CODE_FIX_COMPLETE.mdcomate-intellij-plugin/comate-agent/bin/comate-kernel/fallbackServer.js +117 more | - |
| LOW | postinstall registry modification | 45 | comate-intellij-plugin/comate-agent/bin/comate-kernel/plugins/harmonyos/dist/index.jscomate-intellij-plugin/comate-agent/bin/comate-kernel/plugins/jarvis/dist/index.jscomate-intellij-plugin/lib/python-ce.jar +42 more | - |
| LOW | NoUseSocketManually | 4 | comate-intellij-plugin/comate-agent/bin/comate-kernel/plugins/demo-feature/dist/index.jscomate-intellij-plugin/comate-agent/bin/comate-kernel/plugins/f2c/dist/index.jscomate-intellij-plugin/comate-agent/bin/comate-kernel/completion-agent/server.cjs +1 more | - |
| LOW | StaticallyServingHiddenFilesIsSecuritySensitive | 1 | comate-intellij-plugin/comate-agent/bin/comate-kernel/server.js | - |
Network Indicators
Concrete URLs, domains, IPs, emails, and hashes extracted from the analyzed artifact.
Network indicators are queued for lazy loading
Scroll this section into view to load the detailed rows.
Publisher Evidence
Lowbaidu
Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.
11 evidence rows available.
Finding Categories
YARA Rules Matched
25 rules(867 hits)AI Security Report
AI Security Review
Evidence context: threat category unknown malware; evidence quality moderate.
Baidu Comate is a JetBrains IDE extension with over 530k users. The extension declares no special permissions in the marketplace manifest, but the bundled code reveals extensive network access and file I/O typical of an AI assistant plugin that communicates with remote services.
The most concerning finding is the YARA--CAP_HookExKeylogger signature in /comate-intellij-plugin/lib/jna-platform-5.6.0.jar:11585. This is a false positive. The signature triggers on jna-platform, a standard Java Native Access library used for cross-platform native function calls. JNA is widely used in legitimate Java applications and carries no intrinsic keylogging capability. The JetBrains marketplace would not permit a keylogger to distribute publicly at this scale.
Network activity appears in minified plugin code: axios and fetch calls in comate-agent/bin/comate-kernel/plugins/demo-feature/dist/index.js, socket.io in the f2c plugin, and git integration in git plugin. These are found at lines 22152, 25387, 25383, 25371, 25367, 25358, 25333 and others. The presence of network calls in a plugin designed to provide AI-powered code suggestions is expected. The bundled JavaScript is minified (webpack/esbuild output), which creates noise: each of the dozens of npm packages included in dist/ files triggers its own network findings.
Obfuscation flags on comate-agent/bin/comate-kernel/server.js (OBFUSCATION-unicode_heavy, OBFUSCATION-function_indirect) are consistent with minified source code, not deliberate obfuscation intended to hide malicious logic. Minification is standard practice in Node.js/browser builds.
The IoC count (3128 total) is high but misleading. The vast majority are false positives from IoC extraction on minified code: property chains misread as domains, hex substrings from compressed syntax misidentified as IPv6 fragments. The network_endpoints list includes filenames like 2026-07-06-ducc-skill-approval-no-button.md and markdown paths, which are not actual external endpoints but noise from the extraction process.
The strongest counterargument is that the plugin runs on JetBrains infrastructure with 530k users and version 4.14.3 indicates a mature, actively maintained project. However, the obfuscation findings combined with the keylogger signature and bundled network code create enough uncertainty to warrant runtime behavior analysis before full confidence can be established. The finding nature does not indicate confirmed malicious intent, but the bundled complexity makes it difficult to rule out unintended data access.
Key Reasons
- YARA--CAP_HookExKeylogger signature detected in jna-platform-5.6.0.jar, a legitimate JNA library often misidentified by broad YARA rules
- Network activity (axios, fetch, socket.io) found in minified dist/ plugin bundles (demo-feature, git, f2c, dev-tools), consistent with bundled dependencies
- OBFUSCATION-unicode_heavy and OBFUSCATION-function_indirect in server.js; likely minified output, not intentional obfuscation
- Large IoC count (3128) but mostly false positives from minified code and bundled npm packages
- 530k users and JetBrains marketplace presence suggest some legitimate distribution, but findings require verification
False Positive Considerations
- YARA rule CAP_HookExKeylogger fires on jna-platform library, a standard Java FFI dependency—not malware
- Network findings in dist/ files from webpack/esbuild bundled code, not source-level malicious activity
- Obfuscation findings match minified JavaScript output pattern (server.js, bundled plugins), not deliberate obfuscation
- IoC volume inflated by CDN and package manager domains in bundled dependencies
Reviewed 2026-09-29; recommended action: runtime analysis; model confidence 62%.
JetBrains version history
Risk trend by version
3 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.
Pick any point on the chart to explore that version's code below.
About This Extension
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace