JetBrains Marketplace Verified

Assertive

by assertive · 220 users · 4.1 rating
8524c059-dbab-5aa7-b780-fda2415d6efa | v2025.05.1-SNAPSHOT
71/ 100
HIGH risk
Analyst verdict
Review before use

The AI review rates the findings as likely false positive, but the risk score (71/100) still counts them.

Analysis record

Analysed
3 days ago
Version
v2025.05.1-SNAPSHOT
Artifact
SHA256 2D5…C0F
Source
Findings (non-IoC)

Is Assertive safe?

Assertive is a JetBrains IDE plugin from the publisher assertive, with about 220 users. Its package metadata declares no special permissions and no host scope entries, so nothing in the manifest asks for broad access on its own. The endpoint list attached to this build is not a list of real servers. Entries like 0c.by and 0ۯ.gg are two-character fragments pulled out of compiled Java, and the network category recorded no live network findings at all.

The one finding that sounds alarming points at lib/jna-platform-5.5.0.jar, where a signature named YARA--CAP_HookExKeylogger matched. That signature is named after a Windows keyboard hook. The file it matched is JNA Platform, the standard Java bridge for calling native code, and it ships inside the IntelliJ Platform itself. A rule looking for keyboard hook routines will always match that library, because the library lists those Windows functions by name so other code can call them. Nothing in this build installs a hook or sends anything anywhere.

Everything else the scan flagged is the usual noise from a package full of compiled libraries: hundreds of short letter pairs read as domain names, and a pile of low-severity code-quality matches. We found no reads of credential files, no obfuscation, and no suspicious host in the results.

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

145 detail rows
Showing 25 of 144 · highest severity first

YARA Rule Matches

1 rule
SeverityRuleHitsFilesMetadata
HIGHCAP HookExKeylogger 1
assertive-intellij-main/lib/jna-platform-5.5.0.jar
Brian C. Bell -- @biebsmalwareguy FP 5%

Publisher Evidence

Low

assertive

Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.

62
Noisy-finding weight
x1.00
Publisher domain
assertiveai.ca
Observed
Store verification signal
Verified publisher
Verified
Extension portfolio
1
Portfolio

13 evidence rows available.

Finding Categories

1
Malware Signatures

YARA Rules Matched

1 rule
CAP HookExKeylogger

AI Security Report

AI Security Review

Evidence context: threat category none; evidence quality moderate.

Assertive is a JetBrains marketplace plugin published by the account assertive, version 2025.05.1-SNAPSHOT, with roughly 220 installs. The build scan returned 2,249 items, and nearly all of them land in two buckets that carry no weight: 1,842 IoC entries and 262 code-smell matches. One high-severity item sits apart from those, and it is the only thing worth examining.

Filesystem and process access. The build is a Jar collection. The one file path tied to a real finding is lib/jna-platform-5.5.0.jar, the JNA Platform library, which exists to bind Java methods to native operating system calls. That is the standard mechanism JetBrains plugins use for hotkeys, window focus and desktop integration. There are no manifest-analysis findings, no dependency findings, and the package metadata declares no host permissions. Native binding inside an IDE plugin is the tool doing its job.

Credential access. The secret category is empty. Nothing in this build reads .env files, .ssh material, or a credential store, and no finding targets JetBrains or VS Code secret storage. The strings in the endpoint list that look like they might be hosts are not hosts at all, as covered below.

Network. The endpoint list is extractor output rather than a server inventory. Entries such as 0c.by, 0m.dj, 0ۯ.gg and 2ԉ.me are two-character strings, several with non-Latin characters mixed in, which is how hex or base64 fragments inside compiled bytecode get read as hostnames. The network category recorded zero findings of its own, meaning no finding tied a live call to any of these strings.

The counterargument. YARA--CAP_HookExKeylogger, high severity, matched inside lib/jna-platform-5.5.0.jar. If that rule had fired on plugin code, it would describe a Windows keyboard hook, which is precisely how a keylogger collects keystrokes, and that would justify escalation to a confirmed credential-theft finding. It fired on JNA Platform instead. JNA Platform ships with the IntelliJ Platform and with any plugin that talks to Win32, and its class files contain the declarations the rule looks for (SetWindowsHookEx, WH_KEYBOARD_LL, KBDLLHOOKSTRUCT) as named method bindings. A signature written for hook-installing code matches a library that only names the API. Nothing else in the build corroborates it: no obfuscation findings, no exfiltration endpoint, no credential reads, and no process-spawn anomalies.

Residual unknowns. The published version is a SNAPSHOT, the publisher has a single plugin, and the install count is small, so there is little history to compare against. That gap does not turn an API declaration into a keylogger, but it is the reason this is not a clean bill of health on provenance alone.

Key Reasons

  • The single high-severity match, YARA--CAP_HookExKeylogger, fired on lib/jna-platform-5.5.0.jar, the JNA Platform native-binding library bundled with the IntelliJ Platform, not on plugin code
  • The 1,842 IoC entries are two-character fragments and mixed-script strings such as 0c.by, 0m.dj and 2ԉ.me, and the network category recorded zero findings
  • No secret-category findings: nothing reads .env files, SSH keys or credential stores
  • No manifest-analysis, dependency or obfuscation findings anywhere in the build
  • The 262 code-smell matches are low-severity rule noise on compiled Java, which does not drive a verdict

False Positive Considerations

  • Generic YARA rule (CAP_HookExKeylogger) matching Win32 API declarations inside the bundled jna-platform jar
  • IoC extractor reading hex and base64 fragments in compiled bytecode as hostnames, producing 1,842 bogus endpoints
  • Low-severity code-smell rules firing across bundled third-party libraries
  • JetBrains plugins bundle the platform's own library set, so native-binding artifacts appear in every such package

Reviewed 2026-09-30; recommended action: suppress false positive; model confidence 85%.

About This Extension

Assertive helps developers quickly generate robust unit tests for Java projects. Streamline your testing process with auto-generated test cases and an intuitive tool...

Frequently Asked Questions