Notepad++ Plugins

WebEdit

a4619050-cba9-5984-baf3-0bf59fb2b24a | v2.8.1.2
42/ 100
MEDIUM risk
Analyst verdict
Review before use

The AI review rates the findings as likely false positive, but the risk score (42/100) still counts them.

Analysis record

Analysed
7 months ago
Version
v2.8.1.2
Source
Findings (non-IoC)

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

67 detail rows
Showing 25 of 62 · highest severity first

YARA Rule Matches

5 rules
SeverityRuleHitsFilesMetadata
HIGHpostinstall network communication

Network communication detected

1
Config/WebEdit.ini
Risky Plugins Authors FP 30%
HIGHpostinstall file manipulation

File system manipulation detected

1
Config/WebEdit.ini
Risky Plugins Authors FP 20%
HIGHpostinstall system command

System command execution detected

1
Config/WebEdit.ini
Risky Plugins Authors FP 10%
HIGHpostinstall file download

File download activity detected

1
Config/WebEdit.ini
Risky Plugins Authors FP 30%
HIGHpostinstall obfuscation

Code obfuscation techniques detected

1
Config/WebEdit.ini
Risky Plugins Authors FP 20%

Network Indicators

Concrete URLs, domains, IPs, emails, and hashes extracted from the analyzed artifact.

15 total
...

Network indicators are queued for lazy loading

Scroll this section into view to load the detailed rows.

Finding Categories

5
Malware Signatures
15
IoC Indicators

YARA Rules Matched

5 rules
postinstall network communication postinstall file manipulation postinstall system command postinstall file download postinstall obfuscation

AI Security Report

AI Security Review

Evidence context: threat category none; evidence quality moderate.

WebEdit is a Notepad++ plugin that provides configurable code templates and keyboard shortcuts for text manipulation. The extension's stated purpose is creating menu commands for pasting text with optional selection wrapping, which justifies minimal filesystem access for reading template configurations.

Filesystem/Process Access Assessment: The findings summary shows 5 code-smell findings but no manifest-analysis or network findings. Notepad++ plugins are native DLLs that run within the editor process. The code-smell findings (severity=low) match standard IDE extension patterns for text manipulation and do not indicate malicious process execution. There is no evidence of postinstall payload execution or shell command execution in the findings.

Credential Access Assessment: The findings summary shows 0 secret findings. None of the IoC findings target actual secrets like .env, .ssh, or cloud credentials. The domain users.sourceforge.net in XIOC-DOMAIN-users.sourceforge.net is a legitimate open-source hosting platform, not a credential exfiltration endpoint. The domain example.com in XIOC-DOMAIN-example.com is a standard documentation placeholder domain.

IoC Finding Analysis: All 16 IoC findings are documented false positives. The IPv6 fragments (XIOC-IP-::, XIOC-IP-3::, XIOC-IP-e::, XIOC-IP-f::, XIOC-IP-::e, XIOC-IP-e::d) are hex substrings from minified code, not real IP addresses. The domains XIOC-DOMAIN-window.open, XIOC-DOMAIN-smart.post, and XIOC-DOMAIN-smarty.post are property access chains misread as domains by the XIOC extractor. The IP XIOC-IP-2.8.1.2 lacks context but appears in the same false-positive cluster as the IPv6 fragments.

Strongest Counterargument: The zero user count (user_count: 0) could indicate a newly published extension with potential supply chain risk. However, the developer name Alexander Iljin is associated with legitimate Notepad++ plugins, and there is no evidence of typosquatting or malicious capability. The extension's functionality (text templates) does not require network access or credential handling, and the findings do not show either capability being exploited.

Conclusion: The 83 total findings stem from IoC extraction noise and code-smell patterns that are expected for Notepad++ plugins. No finding demonstrates malicious intent, credential theft, or data exfiltration. The verdict is likely_false_positive.

Key Reasons

  • All IoC findings are documented false positives
  • Zero secret findings - no credential access evidence
  • No malware signatures or network exfiltration findings
  • Code-smell findings are low severity and expected for IDE extensions

False Positive Considerations

  • IPv6 fragment false positives (::, 3::, e::, f::)
  • Property access chains misread as domains (window.open, smart.post)
  • Standard example domain (example.com)
  • Legitimate hosting platform (users.sourceforge.net)

Reviewed 2026-04-27; recommended action: suppress false positive; model confidence 85%.

Frequently Asked Questions