JTools HTTP Client
The AI review rates the findings as likely false positive, but the risk score (47/100) still counts them.
Analysis record
- Analysed
- 5 days ago
- Version
- v0.0.5
- Artifact
- SHA256 664…D51
- Source
- Findings (non-IoC)
Is JTools HTTP Client safe?
JTools HTTP Client is a plugin for JetBrains IDEs that sends HTTP requests from inside your editor. It declares no special permissions and no host permissions, so it isn't asking for filesystem or process access in its manifest. The network addresses listed in its scan data, names like 0x.jp and cl.cr, are what the scanner found when it went looking for hosts in the plugin's bundled code.
Those addresses don't hold up as real servers. One of them, anchor.properties, is a Java property lookup rather than a website, and several others, including ν.jo and nϙe.uz, contain characters that can't appear in a hostname. Several findings are tagged XIOC-DOMAIN-n.lu, which is the scanner's label for a short string it matched on a dot. If any of these were a genuine command endpoint, that would mean the plugin was phoning home to a server you never asked it to contact. The evidence doesn't show that happening.
Nothing in the scan found the plugin reading .env files, SSH keys or IDE-stored credentials, and no malware or install-time script signatures matched. The low-severity hits under the code-smell rules are the ones that fire on ordinary JavaScript using fetch or process.env, which an HTTP client will do by definition.
The scanner tripped on how it slices tokens out of bundled code, not on the plugin making contact with anything. The one thing worth knowing is that the publisher lists no name and the plugin has a small user base, so installing it means trusting a project without much of a track record. That is a reason to keep an eye on it.
Evidence ledger
Ranked by severity · findings with a source location link to the code viewer
YARA Rule Matches
7 rules| Severity | Rule | Hits | Files | Metadata |
|---|---|---|---|---|
| LOW | postinstall crypto operations | 6 | jtools-https/lib/nashorn-core-15.6.jarjtools-https/lib/kotlin-stdlib-2.2.10.jarjtools-https/lib/asm-commons-7.3.1.jar +3 more | - |
| LOW | postinstall network communication | 8 | jtools-https/lib/fontbox-2.0.31.jarjtools-https/lib/sqlite-jdbc-3.46.0.0.jarjtools-https/lib/nashorn-core-15.6.jar +5 more | - |
| LOW | postinstall file manipulation | 2 | jtools-https/lib/nashorn-core-15.6.jarjtools-https/lib/jtools-https-0.0.5.jar | - |
| LOW | postinstall system command | 6 | jtools-https/lib/kotlin-stdlib-2.2.10.jarjtools-https/lib/pdfbox-2.0.31.jarjtools-https/lib/jtools-https-0.0.5.jar +3 more | - |
| LOW | postinstall obfuscation | 7 | jtools-https/lib/nashorn-core-15.6.jarjtools-https/lib/jackson-core-2.17.2.jarjtools-https/lib/kotlin-stdlib-2.2.10.jar +4 more | - |
| LOW | postinstall registry modification | 1 | jtools-https/lib/jtools-https-0.0.5.jar | - |
| LOW | postinstall file download | 2 | jtools-https/lib/jackson-databind-2.17.2.jarjtools-https/lib/jtools-https-0.0.5.jar | - |
Network Indicators
Concrete URLs, domains, IPs, emails, and hashes extracted from the analyzed artifact.
Network indicators are queued for lazy loading
Scroll this section into view to load the detailed rows.
Publisher Evidence
Limited evidence8349aa96-e390-43d3-9aaf-5572ea8a8593
Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.
12 evidence rows available.
Finding Categories
YARA Rules Matched
7 rules(32 hits)AI Security Report
AI Security Review
Evidence context: threat category none; evidence quality moderate.
JTools HTTP Client is a JetBrains IDE plugin, version 0.0.5, installed by around 110 people, that sends HTTP requests from inside the editor. Network traffic is the product, so the relevant question is whether anything in the scan shows it doing more than sending requests on your behalf.
The biggest group of hits are network indicators pulled out of bundled files under the title pattern XIOC-DOMAIN-*. Examples include XIOC-DOMAIN-n.lu, XIOC-DOMAIN-g.lb, XIOC-DOMAIN-0x.jp, XIOC-DOMAIN-zu.ke, XIOC-DOMAIN-ĵ.al and XIOC-DOMAIN-nϙe.uz. As a set they don't behave like a server list. Two of the entries, anchor.properties and functions.properties, are Java property lookups rather than hostnames, and the ones carrying non-Latin characters can't be resolved as written. Short two-label strings such as n.bw, z.nr, ea.cr and fo.gq read as tokens the extractor cut out of minified or bundled code on the dot, not as destinations anyone contacts. All 239 share the same shape and the same medium severity.
Credential access is where a plugin like this usually gets caught, and there is nothing there. No secret findings, no reads of .env, .git/config or SSH key material, no calls into IDE credential storage. The permissions and host permissions lists are both empty, so nothing in the manifest asks for filesystem or process capability. Malware signatures, tool-poisoning checks and obfuscation detectors all report zero. An HTTP client running inside the editor process and spawning request threads is the job description, and no finding here pairs file reads with outbound sends.
The 32 low-severity code-smell hits are the rules that fire on any JavaScript touching fetch, exec, crypto or process.env. The manifest-analysis category is empty, so there is no evidence of the plugin editing IDE configuration or touching other plugins.
The strongest argument against calling this clean is the publisher: the developer name is a bare UUID, the plugin has no description, one release and a small user base. New and unattributed plugins in a smaller marketplace do warrant a look. That argument stops at the address list, though. If those domains were real command infrastructure, the picture would change; instead they fail as hostnames, and the two most legible entries are property names. A thin track record with no supporting code finding is cause to watch the project. The scan found no malicious code. Nothing here reads source and ships it out, runs at install time, or touches credentials.
Key Reasons
- All 239 network indicators are medium-severity XIOC domain extractions from bundled files; several contain characters that cannot exist in a hostname (XIOC-DOMAIN-ν.jo, XIOC-DOMAIN-nϙe.uz, XIOC-DOMAIN-ĵ.al) and two are property names (anchor.properties, functions.properties).
- Zero findings in the secret, malware-signature, obfuscation, tool-poisoning, dependency and manifest-analysis categories.
- No permission or host permission strings are declared, and an HTTP client plugin issuing network requests matches its stated purpose.
- The 32 code-smell hits are the low-severity generic rules that match any JavaScript using fetch, exec, crypto or process.env.
False Positive Considerations
- XIOC extractor tokenising bundled code into fake two-label domains such as n.lu, g.lb and 0x.jp
- Java property-access chains (anchor.properties, functions.properties) misread as network domains
- Code-smell rules matching generic fetch/exec/process.env patterns in extension code
- Non-ASCII fragments from bundled files misread as internationalised hostnames
Reviewed 2026-09-29; recommended action: suppress false positive; model confidence 80%.
About This Extension
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace
JTools
8349aa96-e390-43d3-9aaf-5572ea8a8593
JTools SSH Publisher
8349aa96-e390-43d3-9aaf-5572ea8a8593
JTools-Background
8349aa96-e390-43d3-9aaf-5572ea8a8593
Jtools-Mybatis-Log
8349aa96-e390-43d3-9aaf-5572ea8a8593
DotVVM
keeper7
CodeScan
CodeScan