Notepad++ Plugins

NppExec

81133ba8-4f3b-5946-8be0-1a79a8b68b3d | v0.8.12.1
57/ 100
MEDIUM risk
+22 since v0.8.10
Analyst verdict
Needs follow up

From the RiskyPlugins AI security review of the observed evidence.

Analysis record

Analysed
3 days ago
Version
v0.8.12.1
Artifact
SHA256 D8F…5DA
Source
Findings (non-IoC)

Is NppExec safe?

NppExec is a Notepad++ plugin whose description says it can “execute commands or saved scripts without leaving Notepad++.” That gives it direct command-running power on the host. It declares no special permissions, and the listing provides no network endpoints, so there is no recorded outbound service for this plugin.

The scanner flagged OBFUSCATION-supply_chain_binary at NppExec.dll:0. If that flag matches concealed or packed native code, the DLL would be harder to inspect and verify. The same file is also the part that carries NppExec’s command-running function, so its origin matters.

The command-runner purpose fits the plugin description, and the supplied findings name no credential files or exfiltration path. A clean malware result would help, yet the native DLL flag still needs a closer look through runtime tracing and publisher or hash checks.

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

93 detail rows
Showing 25 of 93 · highest severity first

Finding Categories

1
Obfuscation

AI Security Report

AI Security Review

Evidence context: threat category supply chain; evidence quality moderate.

NppExec is described as an extension that can “execute commands or saved scripts without leaving Notepad++.” That purpose directly explains process execution and gives the plugin broad host control. The relevant executable is NppExec.dll:0, a native Notepad++ plugin, so command execution is part of the stated function rather than an unexplained capability. The same capability can run arbitrary commands under the user account, which makes the plugin more sensitive than a text-only Notepad++ add-on.

The only named security finding is OBFUSCATION-supply_chain_binary at NppExec.dll:0. The title marks the native component as a supply-chain review concern, yet the supplied record gives no behavior, command, download URL, persistence action, or payload detail for that file. Native code receives more weight in this context because the plugin can execute saved scripts, while JavaScript bundling noise does not explain this finding. The finding supports verification of the DLL's origin and build contents. It does not establish harmful intent on its own.

Credential access is not shown. The available record has no finding naming .env, .ssh, cloud credential files, secret storage, or another secret path. NppExec.dll:0 is the only file path attached to a security finding, and OBFUSCATION-supply_chain_binary does not describe credential collection. The absence of network endpoints also leaves no recorded route for sending command output or files outside the host. That absence limits the case for spyware or data exfiltration.

The strongest counterargument is that NppExec has a long-standing command runner use case, and NppExec.dll:0 may have been flagged because native plugin code is hard for static scanners to inspect. The extension description supports that benign explanation for process execution. It does not resolve the specific OBFUSCATION-supply_chain_binary result, because the supplied record contains no publisher verification, hash comparison, source-build detail, or runtime trace for NppExec.dll:0. A runtime test with network observation and command tracing is therefore justified before treating the DLL as safe or malicious.

Key Reasons

  • OBFUSCATION-supply_chain_binary flags NppExec.dll:0, the native component that executes commands.
  • NppExec's stated purpose explains process execution, so that capability is expected for this plugin.
  • No finding identifies credential files, secret storage, network endpoints, or data exfiltration.
  • The record lacks publisher verification, hash comparison, source-build detail, or runtime behavior for NppExec.dll:0.

False Positive Considerations

  • Native plugin code can trigger OBFUSCATION-supply_chain_binary during static inspection.
  • NppExec's stated command and saved-script execution purpose explains broad process access.
  • The supplied record contains no network endpoints or credential-access findings.
  • The finding at NppExec.dll:0 has no supporting behavior or payload detail.

Reviewed 2026-09-29; recommended action: runtime analysis; model confidence 78%.

Notepad++ version history

Risk trend by version

2 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.

Selected
57
Change since first
+22
Change from previous
+22
Versions:
First analyzed version
0.8.10
Apr 5, 2026
Risk range
36 to 57
Across analyzed versions
Latest analyzed version
0.8.12.1
Sep 28, 2026
Selected version
medium
Version
v0.8.12.1
3 days ago
Risk score
57
Findings
93
Change vs previous
+22

Pick any point on the chart to explore that version's code below.

Frequently Asked Questions