Notepad++ Plugins

Pork to Sausage

by Don HO
a3d98fa6-8832-5b38-b7f3-83bed6065760 | v2.6
36/ 100
LOW risk
Analyst verdict
No high-risk signal observed

Based on the RiskyPlugins AI security review of the observed evidence.

Analysis record

Analysed
7 months ago
Version
v2.6
Source
Findings (non-IoC)

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

16 detail rows

YARA Rule Matches

2 rules
SeverityRuleHitsFilesMetadata
HIGHpostinstall system command

System command execution detected

3
demo/zip.base64/zipB64.javalicense.txtConfig/pork2Sausage.ini
Risky Plugins Authors FP 10%
HIGHpostinstall obfuscation

Code obfuscation techniques detected

5
demo/zip.base64/commons-codec-1.4.jarreadme.txtdemo/zip.base64/readme.txt +2 more
Risky Plugins Authors FP 20%

Finding Categories

8
Malware Signatures

YARA Rules Matched

2 rules(8 hits)
postinstall system command postinstall obfuscation

AI Security Report

AI Security Review

Evidence context: threat category none; evidence quality moderate.

This Notepad++ plugin, 'Pork to Sausage' by Don HO, performs legitimate text processing: passing selected text to command-line programs and replacing selections with output. The filesystem/process access is justified by the extension's stated purpose—command-line execution is the core functionality, not suspicious behavior.

All 13 IoC findings are documented false positive patterns. The IPv6 fragments ::, e::fa, e::badb, e::e are hex substrings from minified code, not real IP addresses. The 'domains' java.io, java.util.zip, inflater.read, and c.cg are Java package names and property access chains misread as domains by the XIOC extractor. The email addresses [email protected] and [email protected] are developer contact information, not malicious indicators. The domains free.fr and altern.org are email provider domains from the developer's contact info.

The 8 code-smell findings (shown as high severity in the summary) are standard YARA noise for IDE extensions. These rules match basic Node.js patterns like fetch, exec, fs, and crypto operations. For a Notepad++ plugin that legitimately executes command-line programs, these findings are expected behavior, not malicious intent.

No actual malware signatures, network exfiltration patterns, or credential theft indicators exist in the findings. The 0 user count is notable but does not indicate malicious behavior—a new or niche plugin may have no downloads. The extension's purpose (text-to-command-line processing) justifies its process execution capability.

The strongest counterargument is that Notepad++ plugins are native DLLs, and any findings should carry more weight than JavaScript extensions. However, this does not change the conclusion because the findings themselves are not evidence of malicious behavior—they are all documented false positive patterns. The XIOC extractor produced garbage on Java package names and hex strings, and the YARA code-smell rules fired on legitimate command-line execution patterns. Without actual malware signatures, credential theft, or data exfiltration evidence, the high severity ratings are artifacts of the scoring system's known bias toward IoC volume and code-smell counts.

This extension performs its stated function without malicious indicators.

Key Reasons

  • All IoC findings are documented XIOC false positive patterns
  • No malware signatures or actual malicious indicators
  • Command-line execution is the extension's stated purpose
  • Code-smell findings are expected YARA noise for IDE extensions

False Positive Considerations

  • XIOC IPv6 fragment false positives (::, e::fa, e::badb)
  • XIOC property access chains misread as domains (java.io, java.util.zip)
  • YARA code-smell rules on legitimate command-line execution
  • Developer contact emails extracted as IoCs

Reviewed 2026-04-27; recommended action: suppress false positive; model confidence 85%.

Frequently Asked Questions