The AI review rates the findings as likely false positive, but the risk score (42/100) still counts them.
Analysis record
- Analysed
- 7 months ago
- Version
- v2.8.1.2
- Source
- Findings (non-IoC)
Evidence ledger
Ranked by severity · findings with a source location link to the code viewer
YARA Rule Matches
5 rules| Severity | Rule | Hits | Files | Metadata |
|---|---|---|---|---|
| HIGH | postinstall network communication Network communication detected | 1 | Config/WebEdit.ini | Risky Plugins Authors FP 30% |
| HIGH | postinstall file manipulation File system manipulation detected | 1 | Config/WebEdit.ini | Risky Plugins Authors FP 20% |
| HIGH | postinstall system command System command execution detected | 1 | Config/WebEdit.ini | Risky Plugins Authors FP 10% |
| HIGH | postinstall file download File download activity detected | 1 | Config/WebEdit.ini | Risky Plugins Authors FP 30% |
| HIGH | postinstall obfuscation Code obfuscation techniques detected | 1 | Config/WebEdit.ini | Risky Plugins Authors FP 20% |
Network Indicators
Concrete URLs, domains, IPs, emails, and hashes extracted from the analyzed artifact.
Network indicators are queued for lazy loading
Scroll this section into view to load the detailed rows.
Finding Categories
YARA Rules Matched
5 rulesAI Security Report
AI Security Review
Evidence context: threat category none; evidence quality moderate.
WebEdit is a Notepad++ plugin that provides configurable code templates and keyboard shortcuts for text manipulation. The extension's stated purpose is creating menu commands for pasting text with optional selection wrapping, which justifies minimal filesystem access for reading template configurations.
Filesystem/Process Access Assessment: The findings summary shows 5 code-smell findings but no manifest-analysis or network findings. Notepad++ plugins are native DLLs that run within the editor process. The code-smell findings (severity=low) match standard IDE extension patterns for text manipulation and do not indicate malicious process execution. There is no evidence of postinstall payload execution or shell command execution in the findings.
Credential Access Assessment: The findings summary shows 0 secret findings. None of the IoC findings target actual secrets like .env, .ssh, or cloud credentials. The domain users.sourceforge.net in XIOC-DOMAIN-users.sourceforge.net is a legitimate open-source hosting platform, not a credential exfiltration endpoint. The domain example.com in XIOC-DOMAIN-example.com is a standard documentation placeholder domain.
IoC Finding Analysis: All 16 IoC findings are documented false positives. The IPv6 fragments (XIOC-IP-::, XIOC-IP-3::, XIOC-IP-e::, XIOC-IP-f::, XIOC-IP-::e, XIOC-IP-e::d) are hex substrings from minified code, not real IP addresses. The domains XIOC-DOMAIN-window.open, XIOC-DOMAIN-smart.post, and XIOC-DOMAIN-smarty.post are property access chains misread as domains by the XIOC extractor. The IP XIOC-IP-2.8.1.2 lacks context but appears in the same false-positive cluster as the IPv6 fragments.
Strongest Counterargument: The zero user count (user_count: 0) could indicate a newly published extension with potential supply chain risk. However, the developer name Alexander Iljin is associated with legitimate Notepad++ plugins, and there is no evidence of typosquatting or malicious capability. The extension's functionality (text templates) does not require network access or credential handling, and the findings do not show either capability being exploited.
Conclusion: The 83 total findings stem from IoC extraction noise and code-smell patterns that are expected for Notepad++ plugins. No finding demonstrates malicious intent, credential theft, or data exfiltration. The verdict is likely_false_positive.
Key Reasons
- All IoC findings are documented false positives
- Zero secret findings - no credential access evidence
- No malware signatures or network exfiltration findings
- Code-smell findings are low severity and expected for IDE extensions
False Positive Considerations
- IPv6 fragment false positives (::, 3::, e::, f::)
- Property access chains misread as domains (window.open, smart.post)
- Standard example domain (example.com)
- Legitimate hosting platform (users.sourceforge.net)
Reviewed 2026-04-27; recommended action: suppress false positive; model confidence 85%.
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace