From the RiskyPlugins AI security review of the observed evidence.
Analysis record
- Analysed
- 4 days ago
- Version
- v1.0.0
- Artifact
- SHA256 A34…AEA
- Source
- Findings (non-IoC)
Is NppMarkdownNext safe?
NppMarkdownNext is described as a native C++ Markdown preview and reader. It declares no special permissions, and the listed endpoint img.shields.io is commonly used for a project badge; strings such as window.chrome, build.ps, and makerelease.ps do not by themselves show that the plugin sends document data online. Its stated job fits reading the open Markdown document for rendering.
The finding titled OBFUSCATION-supply_chain_binary covers both NppMarkdownNext.dll:0 and WebView2Loader.dll:0. If that finding represented concealed payload code, the plugin could carry behavior that static scanning could not explain. The available results name no credential files, secret storage, malware signature, network activity, or special permission.
The concern comes from the native DLLs, especially NppMarkdownNext.dll:0, rather than from a demonstrated theft or download action. Native release files and a WebView2 loader can trigger this kind of scanner result, yet the two critical detections need publisher or runtime validation before the plugin can be treated as routine.
Evidence ledger
Ranked by severity · findings with a source location link to the code viewer
YARA Rule Matches
6 rules| Severity | Rule | Hits | Files | Metadata |
|---|---|---|---|---|
| LOW | postinstall persistence mechanism | 1 | WebView2Loader.dll | - |
| LOW | postinstall file download | 1 | NppMarkdownNext.dll | - |
| LOW | postinstall file manipulation | 2 | NppMarkdownNext.dllWebView2Loader.dll | - |
| LOW | postinstall obfuscation | 1 | NppMarkdownNext.dll | - |
| LOW | postinstall network communication | 3 | License.txtNppMarkdownNext.dllWebView2Loader.dll | - |
| LOW | postinstall system command | 2 | NppMarkdownNext.dllWebView2Loader.dll | - |
Network Indicators
Concrete URLs, domains, IPs, emails, and hashes extracted from the analyzed artifact.
Network indicators are queued for lazy loading
Scroll this section into view to load the detailed rows.
Finding Categories
YARA Rules Matched
6 rules(10 hits)AI Security Report
AI Security Review
Evidence context: threat category supply chain; evidence quality weak.
NppMarkdownNext is described as a native C++ Markdown live preview and reader, so document reads and rendering work fit the stated purpose associated with NppMarkdownNext.dll:0. The available results contain no filesystem, process-execution, or host-permission finding tied to NppMarkdownNext.dll:0, and the extension declares no permissions or host permissions. A live preview plugin still needs access to the document being displayed, so a read-only workspace classification fits the stated function. The evidence does not establish write access or full-system behavior.
The main concern is the finding titled OBFUSCATION-supply_chain_binary on NppMarkdownNext.dll:0. Notepad++ plugins are native DLLs, so opaque compiled code deserves more weight than the same label on bundled JavaScript. The same finding title also applies to WebView2Loader.dll:0, a file whose name matches a browser runtime loader used by WebView-based applications. The title alone does not show that either DLL hides payload code, changes Notepad++, or runs commands. It does show that static inspection could not provide a clear view of both native components.
Credential access is not supported by the listed results. No finding identifies .env, .ssh, cloud credential files, secret storage, or credential-provider access in NppMarkdownNext.dll:0 or WebView2Loader.dll:0. The results also list no secret finding and no network finding, so there is no documented path from workspace files to an external service. The endpoint strings build.ps, makerelease.ps, window.chrome, and img.shields.io are present in the listing, yet they do not establish runtime data transfer from the plugin. In particular, img.shields.io is commonly used for project badges, while the other strings can be build or browser-related names.
The strongest counterargument is that OBFUSCATION-supply_chain_binary can flag ordinary native release binaries, and WebView2Loader.dll:0 is consistent with a WebView2 integration. That explanation fits the extension's Markdown preview purpose and the absence of malware, tool-poisoning, credential, network, and permission findings. It does not resolve NppMarkdownNext.dll:0, because the same critical detection covers the plugin's own executable component and the publisher is listed as theneet0 with version 1.0.0. A signed-binary check, provenance for both DLLs, and runtime observation of file and process activity are needed before treating the detections as harmless build output. The available evidence supports follow-up rather than a malicious verdict.
Key Reasons
OBFUSCATION-supply_chain_binarycovers the plugin DLL atNppMarkdownNext.dll:0.OBFUSCATION-supply_chain_binaryalso coversWebView2Loader.dll:0, leaving the browser component opaque to static analysis.- No credential, malware, network, permission, or tool-poisoning finding is reported for the supplied native files.
- The publisher is
theneet0and the version is1.0.0, so provenance for the native release files is not established by the supplied results.
False Positive Considerations
- Native compiled release files can trigger
OBFUSCATION-supply_chain_binarywithout malicious intent. WebView2Loader.dll:0is consistent with the extension's stated WebView2 rendering design.- The endpoint strings
img.shields.io,window.chrome,build.ps, andmakerelease.psdo not prove runtime network access. - The absence of permission, network, secret, malware, and tool-poisoning findings limits the case for harmful behavior.
Reviewed 2026-09-29; recommended action: runtime analysis; model confidence 65%.
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace