VS Code Marketplace Verified

Oracle Developer Tools for VS Code (SQL and PLSQL)

by Oracle Corporation · 720.0K users · 3.3 rating
9166e209-f019-52bf-b296-37a18a1f01c7 | v23.4.1
100/ 100
CRITICAL risk
Risk verdict
Do not install

Score-based assessment (critical risk, 100/100). No analyst review available.

Analysis record

Analysed
2 weeks ago
Version
v23.4.1
Artifact
SHA256 CD9…B50
Source
Findings (non-IoC)

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

1000 detail rows
Showing 25 of 170 · highest severity first

YARA Rule Matches

16 rules
SeverityRuleHitsFilesMetadata
HIGHSLServer dialog remains 1
out/server/Oracle.ManagedDataAccess.dll
Matt Brooks, @cmatthewbrooks FP 20%
HIGHsupply chain sourcemap appended iife 1
out/ui/js/bundle.js
-
LOWcredential env files 33
out/ui/js/libs/oraclejet-preact/amd/useColorScheme-504ab80c.jsout/ui/js/libs/persist/min/offline-persistence-toolkit-core-1.5.7.jsout/ui/js/libs/oraclejet-preact/amd/TopLayerHost-1134809b.js +30 more
-
LOWpostinstall persistence mechanism 12
out/ui/js/libs/oj/16.1.3/resources/internal-deps/dvt/thematicMap/basemaps/ojthematicmap-world-countries.jsout/ui/js/libs/oj/16.1.3/resources/internal-deps/dvt/thematicMap/basemaps/resourceBundles/WorldCountriesBundle_fr.jsout/infrastructure/oracleAutoCompletionHelper.js +9 more
-
LOWcredential vscode credentials 1
out/utilities/helper.js
-
LOWDebuggerStatementsShouldNotBeUsed 26
out/ui/js/common/localizedConstants.jsout/ui/js/viewModels/settingsModule.jsout/constants/localizedConstants.en.json +23 more
-
LOWLocalStorageShouldNotBeUsed 7
out/ui/js/libs/persist/min/offline-persistence-toolkit-filesystemstore-1.5.7.jsout/ui/js/libs/persist/min/impl/localPersistenceStore.jsout/ui/js/libs/persist/min/offline-persistence-toolkit-responseproxy-1.5.7.js +4 more
-
LOWpostinstall file download 247
out/ui/js/libs/oj/16.1.3/min/ojdvt-base.jsout/ui/js/utilities.jsout/ui/js/viewModels/queryResultsModule.js +244 more
-
LOWNoUseWeakRandom 27
out/ui/js/libs/oraclejet-preact/amd/LegendUtils-b7e1ee6f.jsout/ui/js/libs/knockout/knockout-3.5.1.jsout/ui/js/libs/jquery/jquery-3.6.4.min.js +24 more
-
LOWNoUseEval 1
out/ui/js/libs/require/require.js
-
LOWSQLInjection 5
out/ui/js/libs/oj/16.1.3/min/ojgauge.jsout/ui/js/libs/oj/16.1.3/min/ojbufferingdataprovider.jsout/ui/js/bundle.js +2 more
-
LOWpostinstall file manipulation 92
out/ui/js/libs/oj/16.1.3/min/ojmutateeventfilteringdataprovider.jsout/ui/js/libs/oj/16.1.3/min/ojjsontreedatasource.jsout/ui/js/libs/oj/16.1.3/min/ojtree.js +89 more
-
LOWpostinstall obfuscation 128
out/ui/js/libs/oj/16.1.3/min/ojradioset.jsout/ui/js/viewModels/filterSettingsModule.jsout/ui/js/viewModels/queryResultsModule.js +125 more
-
LOWpostinstall registry modification 20
out/ui/js/libs/oj/16.1.3/min/ojvcomponent.jsout/webview/module-aggrid.jsout/ui/js/libs/require/require.js +17 more
-
LOWpostinstall environment access 191
out/ui/js/libs/oraclejet-preact/amd/UNSAFE_RadioItem.jsout/ui/js/libs/oraclejet-preact/amd/UNSAFE_Environment.jsout/ui/js/libs/oraclejet-preact/amd/PRIVATE_ThemedIcons/MinusIcon.js +188 more
-
LOWpostinstall crypto operations 38
out/server/OracleVSCodePlsqlDebugger80.deps.jsonout/ui/js/libs/persist/min/pouchdb.find.jsout/ui/js/libs/oraclejet-preact/amd/utils/UNSAFE_stringUtils.js +35 more
-

Network Indicators

Concrete URLs, domains, IPs, emails, and hashes extracted from the analyzed artifact.

7,548 total
...

Network indicators are queued for lazy loading

Scroll this section into view to load the detailed rows.

Publisher Evidence

Low

Oracle Corporation

Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.

97
Noisy-finding weight
x1.00
Publisher domain
oracle.com
Observed
Store verification signal
Verified publisher
Verified
Extension portfolio
28
Portfolio

11 evidence rows available.

Finding Categories

2
Malware Signatures
117
Obfuscation
47
Network
7,548
IoC Indicators

YARA Rules Matched

16 rules(830 hits)
SLServer dialog remains supply chain sourcemap appended iife credential env files postinstall persistence mechanism credential vscode credentials DebuggerStatementsShouldNotBeUsed LocalStorageShouldNotBeUsed postinstall file download NoUseWeakRandom NoUseEval SQLInjection postinstall file manipulation postinstall obfuscation postinstall registry modification postinstall environment access postinstall crypto operations

Security Analysis Summary

Security Analysis Overview

Oracle Developer Tools for VS Code (SQL and PLSQL) is a Visual Studio Code Marketplace extension published by Oracle Corporation. Version 23.4.1 has been analyzed by the Risky Plugins security platform, receiving a risk score of 100/100 (CRITICAL risk) based on 9771 security findings.

Risk Assessment

This extension presents critical security risk. Severe issues were detected, potentially including malware indicators, exposed secrets, or dangerous behaviors. Installation is strongly discouraged until these issues are addressed.

Findings Breakdown

  • Critical: 41 finding(s)
  • High: 69 finding(s)
  • Medium: 7604 finding(s)
  • Low: 2057 finding(s)

What Was Analyzed

The security assessment covers multiple analysis categories:

  • Malware Detection: YARA rule matching against 2,400+ malware signatures
  • Secret Detection: Scanning for exposed API keys, tokens, and credentials
  • Static Analysis: Code-level security analysis for common vulnerability patterns
  • Network Analysis: Detection of suspicious network communications and endpoints
  • Obfuscation Detection: Identification of code obfuscation techniques

Developer Information

Oracle Developer Tools for VS Code (SQL and PLSQL) is published by Oracle Corporation on the Visual Studio Code Marketplace marketplace. The extension has approximately 720K users.

Recommendation

This extension is not recommended for installation without thorough manual review. Consider alternatives with lower risk scores, or contact the developer to address the identified security concerns.

About This Extension

Develop SQL and PL/SQL with Oracle Database and Oracle Autonomous Database

Frequently Asked Questions