Based on the RiskyPlugins AI security review of the observed evidence.
Analysis record
- Analysed
- 7 months ago
- Version
- v2.6
- Source
- Findings (non-IoC)
Evidence ledger
Ranked by severity · findings with a source location link to the code viewer
YARA Rule Matches
2 rules| Severity | Rule | Hits | Files | Metadata |
|---|---|---|---|---|
| HIGH | postinstall system command System command execution detected | 3 | demo/zip.base64/zipB64.javalicense.txtConfig/pork2Sausage.ini | Risky Plugins Authors FP 10% |
| HIGH | postinstall obfuscation Code obfuscation techniques detected | 5 | readme.txtdemo/zip.base64/readme.txtdemo/zip.base64/commons-codec-1.4.jar +2 more | Risky Plugins Authors FP 20% |
Finding Categories
YARA Rules Matched
2 rules(8 hits)AI Security Report
AI Security Review
Evidence context: threat category none; evidence quality moderate.
This Notepad++ plugin, 'Pork to Sausage' by Don HO, performs legitimate text processing: passing selected text to command-line programs and replacing selections with output. The filesystem/process access is justified by the extension's stated purpose—command-line execution is the core functionality, not suspicious behavior.
All 13 IoC findings are documented false positive patterns. The IPv6 fragments ::, e::fa, e::badb, e::e are hex substrings from minified code, not real IP addresses. The 'domains' java.io, java.util.zip, inflater.read, and c.cg are Java package names and property access chains misread as domains by the XIOC extractor. The email addresses [email protected] and [email protected] are developer contact information, not malicious indicators. The domains free.fr and altern.org are email provider domains from the developer's contact info.
The 8 code-smell findings (shown as high severity in the summary) are standard YARA noise for IDE extensions. These rules match basic Node.js patterns like fetch, exec, fs, and crypto operations. For a Notepad++ plugin that legitimately executes command-line programs, these findings are expected behavior, not malicious intent.
No actual malware signatures, network exfiltration patterns, or credential theft indicators exist in the findings. The 0 user count is notable but does not indicate malicious behavior—a new or niche plugin may have no downloads. The extension's purpose (text-to-command-line processing) justifies its process execution capability.
The strongest counterargument is that Notepad++ plugins are native DLLs, and any findings should carry more weight than JavaScript extensions. However, this does not change the conclusion because the findings themselves are not evidence of malicious behavior—they are all documented false positive patterns. The XIOC extractor produced garbage on Java package names and hex strings, and the YARA code-smell rules fired on legitimate command-line execution patterns. Without actual malware signatures, credential theft, or data exfiltration evidence, the high severity ratings are artifacts of the scoring system's known bias toward IoC volume and code-smell counts.
This extension performs its stated function without malicious indicators.
Key Reasons
- All IoC findings are documented XIOC false positive patterns
- No malware signatures or actual malicious indicators
- Command-line execution is the extension's stated purpose
- Code-smell findings are expected YARA noise for IDE extensions
False Positive Considerations
- XIOC IPv6 fragment false positives (::, e::fa, e::badb)
- XIOC property access chains misread as domains (java.io, java.util.zip)
- YARA code-smell rules on legitimate command-line execution
- Developer contact emails extracted as IoCs
Reviewed 2026-04-27; recommended action: suppress false positive; model confidence 85%.
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace