Marketplace listing not found
Our last marketplace check could not find this listing in OpenVSX. It may have been removed or delisted. Existing installs may still run, but verify the publisher and package source before installing or updating.
Confirmed member of a tracked malicious supply-chain campaign.
Analysis record
- Analysed
- 2 months ago
- Version
- v1.7.0
- Artifact
- SHA256 AA7…875
- Source
- Findings (non-IoC)
Evidence ledger
Ranked by severity · findings with a source location link to the code viewer
Network Indicators
Concrete URLs, domains, IPs, emails, and hashes extracted from the analyzed artifact.
Network indicators are queued for lazy loading
Scroll this section into view to load the detailed rows.
Publisher Evidence
Limited evidenceCodebuddyAI
Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.
13 evidence rows available.
Finding Categories
AI Security Report
AI Security Review
Risky Plugins reviewed this extension with an AI-assisted security workflow on 2026-09-05. The review verdict is likely false positive with 78% confidence.
Recommended action: suppress false positive. Evidence context: threat category none; evidence quality weak.
Codebuddy AI is an AI assistant extension published on OpenVSX by CodebuddyAI. The evidence contains 201 IoC findings and 3 obfuscation findings. There are no malware signatures, no secret-access findings, no network findings, and no manifest-analysis findings.
The IoC findings are dominated by XIOC extractor artifacts. These do not represent real network destinations. Titles such as XIOC-DOMAIN-wtf8.rs, XIOC-DOMAIN-f32.rs, XIOC-DOMAIN-waitforprocessing2.mp, XIOC-DOMAIN-recode.no, XIOC-DOMAIN-1.ci, XIOC-DOMAIN-eu.nr, and XIOC-DOMAIN-cl.lk are fragments of code identifiers or country-code TLD substrings. They do not resolve to destinations an extension would contact. The URL findings include http://schemas.openxmlformats.org/package/2006/content-types, a standard Office Open XML schema namespace; https://evilmartians.com/chronicles/postcss-8-plugin-migration, a public technical blog post; and https://codebuddy.ca/blog/getting-started-jetbrains, the publisher's own documentation. A Discord invite URL (https://discord.gg/Qa9vYdE78a) is a community link with no exfiltration purpose. None of these IoCs indicate malicious network activity.
The three obfuscation findings are the only critical-severity items. They are consistent with minified or bundled JavaScript in the extension's dist/ output, which is standard for VS Code extensions and does not indicate intentional hiding. The absence of code-smell findings, secret findings, and network findings means there is no evidence of credential access, source-code exfiltration, or postinstall payload execution. No manifest-analysis findings were reported, so there is no evidence of excessive permission requests. No code-smell findings such as postinstall_* or credential_* rules fired, which are common noise but would at least indicate the presence of Node.js patterns; their absence here means the extension does not even contain the typical patterns that trigger those rules. The extension's stated purpose justifies reading workspace files, but the evidence does not show any filesystem or process access beyond that baseline.
The strongest counterargument is that a zero-user OpenVSX extension with 201 IoCs and 3 critical obfuscation findings could be a supply-chain attempt. However, the IoCs are extractor noise. They are not real domains, and the obfuscation findings lack any accompanying malicious indicators such as malware signatures, secret access, or suspicious network calls. The publisher's own blog URL and a Discord invite are normal for a developer tool. Without a single malware signature or secret-access finding, the evidence supports a false positive from automated extractors rather than malicious behavior.
Key Reasons
- All 201 IoC findings are XIOC extractor artifacts (wtf8.rs, f32.rs, waitforprocessing2.mp, recode.no, 1.ci, eu.nr, cl.lk) that are not real domains.
- No malware signatures, secret-access findings, or network findings were detected.
- The three obfuscation findings are consistent with minified/bundled JavaScript, not intentional hiding.
- URLs include standard schemas, a public blog, the publisher's own documentation, and a Discord invite — all benign.
- No manifest-analysis or code-smell findings indicate excessive permissions or suspicious Node.js patterns.
False Positive Considerations
- XIOC extractor garbage domains from minified code
- Minified/bundled JavaScript triggering obfuscation rules
- No malware signatures or secret/network findings to corroborate IoCs
- Benign URLs (schemas.openxmlformats.org, evilmartians.com, codebuddy.ca, discord.gg) misclassified as IoCs
Source Code Not Available
Source code is not available for this version of the extension.