Notepad++ Plugins

NppMarkdownNext

838d8968-7f75-57fc-b897-626baf4c08fa | v1.0.0
65/ 100
MEDIUM risk
Analyst verdict
Needs follow up

From the RiskyPlugins AI security review of the observed evidence.

Analysis record

Analysed
4 days ago
Version
v1.0.0
Artifact
SHA256 A34…AEA
Source
Findings (non-IoC)

Is NppMarkdownNext safe?

NppMarkdownNext is described as a native C++ Markdown preview and reader. It declares no special permissions, and the listed endpoint img.shields.io is commonly used for a project badge; strings such as window.chrome, build.ps, and makerelease.ps do not by themselves show that the plugin sends document data online. Its stated job fits reading the open Markdown document for rendering.

The finding titled OBFUSCATION-supply_chain_binary covers both NppMarkdownNext.dll:0 and WebView2Loader.dll:0. If that finding represented concealed payload code, the plugin could carry behavior that static scanning could not explain. The available results name no credential files, secret storage, malware signature, network activity, or special permission.

The concern comes from the native DLLs, especially NppMarkdownNext.dll:0, rather than from a demonstrated theft or download action. Native release files and a WebView2 loader can trigger this kind of scanner result, yet the two critical detections need publisher or runtime validation before the plugin can be treated as routine.

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

16 detail rows

YARA Rule Matches

6 rules
SeverityRuleHitsFilesMetadata
LOWpostinstall persistence mechanism 1
WebView2Loader.dll
-
LOWpostinstall file download 1
NppMarkdownNext.dll
-
LOWpostinstall file manipulation 2
NppMarkdownNext.dllWebView2Loader.dll
-
LOWpostinstall obfuscation 1
NppMarkdownNext.dll
-
LOWpostinstall network communication 3
License.txtNppMarkdownNext.dllWebView2Loader.dll
-
LOWpostinstall system command 2
NppMarkdownNext.dllWebView2Loader.dll
-

Network Indicators

Concrete URLs, domains, IPs, emails, and hashes extracted from the analyzed artifact.

21 total
...

Network indicators are queued for lazy loading

Scroll this section into view to load the detailed rows.

Finding Categories

2
Obfuscation
21
IoC Indicators

YARA Rules Matched

6 rules(10 hits)
postinstall persistence mechanism postinstall file download postinstall file manipulation postinstall obfuscation postinstall network communication postinstall system command

AI Security Report

AI Security Review

Evidence context: threat category supply chain; evidence quality weak.

NppMarkdownNext is described as a native C++ Markdown live preview and reader, so document reads and rendering work fit the stated purpose associated with NppMarkdownNext.dll:0. The available results contain no filesystem, process-execution, or host-permission finding tied to NppMarkdownNext.dll:0, and the extension declares no permissions or host permissions. A live preview plugin still needs access to the document being displayed, so a read-only workspace classification fits the stated function. The evidence does not establish write access or full-system behavior.

The main concern is the finding titled OBFUSCATION-supply_chain_binary on NppMarkdownNext.dll:0. Notepad++ plugins are native DLLs, so opaque compiled code deserves more weight than the same label on bundled JavaScript. The same finding title also applies to WebView2Loader.dll:0, a file whose name matches a browser runtime loader used by WebView-based applications. The title alone does not show that either DLL hides payload code, changes Notepad++, or runs commands. It does show that static inspection could not provide a clear view of both native components.

Credential access is not supported by the listed results. No finding identifies .env, .ssh, cloud credential files, secret storage, or credential-provider access in NppMarkdownNext.dll:0 or WebView2Loader.dll:0. The results also list no secret finding and no network finding, so there is no documented path from workspace files to an external service. The endpoint strings build.ps, makerelease.ps, window.chrome, and img.shields.io are present in the listing, yet they do not establish runtime data transfer from the plugin. In particular, img.shields.io is commonly used for project badges, while the other strings can be build or browser-related names.

The strongest counterargument is that OBFUSCATION-supply_chain_binary can flag ordinary native release binaries, and WebView2Loader.dll:0 is consistent with a WebView2 integration. That explanation fits the extension's Markdown preview purpose and the absence of malware, tool-poisoning, credential, network, and permission findings. It does not resolve NppMarkdownNext.dll:0, because the same critical detection covers the plugin's own executable component and the publisher is listed as theneet0 with version 1.0.0. A signed-binary check, provenance for both DLLs, and runtime observation of file and process activity are needed before treating the detections as harmless build output. The available evidence supports follow-up rather than a malicious verdict.

Key Reasons

  • OBFUSCATION-supply_chain_binary covers the plugin DLL at NppMarkdownNext.dll:0.
  • OBFUSCATION-supply_chain_binary also covers WebView2Loader.dll:0, leaving the browser component opaque to static analysis.
  • No credential, malware, network, permission, or tool-poisoning finding is reported for the supplied native files.
  • The publisher is theneet0 and the version is 1.0.0, so provenance for the native release files is not established by the supplied results.

False Positive Considerations

  • Native compiled release files can trigger OBFUSCATION-supply_chain_binary without malicious intent.
  • WebView2Loader.dll:0 is consistent with the extension's stated WebView2 rendering design.
  • The endpoint strings img.shields.io, window.chrome, build.ps, and makerelease.ps do not prove runtime network access.
  • The absence of permission, network, secret, malware, and tool-poisoning findings limits the case for harmful behavior.

Reviewed 2026-09-29; recommended action: runtime analysis; model confidence 65%.

Frequently Asked Questions