VS Code Marketplace Verified

Pylance

by Microsoft · 205.1M users · 3.0 rating
a5ad2453-ec97-56d7-8226-6458f181e613 | v2026.4.1
70/ 100
HIGH risk
No change since v2026.3.104
Risk verdict
Review before use

Score-based assessment (high risk, 70/100). Last analyst review covers version 2026.2.103.

Analysis record

Analysed
6 days ago
Version
v2026.4.1
Artifact
SHA256 3E6…CFB
Source
Findings (non-IoC)

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

24 detail rows

YARA Rule Matches

1 rule
SeverityRuleHitsFilesMetadata
HIGHCAP HookExKeylogger 1
dist/typeshed-fallback/stubs/pywin32/win32/lib/win32con.pyi
Brian C. Bell -- @biebsmalwareguy FP 5%

Publisher Evidence

High

Microsoft

Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.

100
Noisy-finding weight
x0.50
Publisher domain
microsoft.com
Trusted match
Store verification signal
Verified publisher
Verified
Extension portfolio
653
Portfolio

11 evidence rows available.

Finding Categories

1
Malware Signatures

YARA Rules Matched

1 rule
CAP HookExKeylogger

AI Security Report

AI Security Review

Evidence context: threat category none; evidence quality strong.

The Pylance extension is a performant, feature-rich language server for Python in VS Code. Its filesystem and process access are justified by its purpose as a language server, which requires reading and writing files, as well as spawning processes for tasks like compilation and debugging. The extension's dependencies, such as semver, vscode-languageserver, and jsonc-parser, are typical for a language server and do not indicate malicious behavior. The strongest counterargument to a malicious verdict is that the extension is developed by ms-python, a verified publisher, and its functionality is consistent with its stated purpose. The findings in the evidence bundle, such as DEP-semver-^7.7.3 and DEP-vscode-languageserver-^10.0.0-next.13, are related to the extension's dependencies and do not suggest malicious activity. Therefore, the extension's behavior is likely legitimate and expected for a language server.

Key Reasons

  • The extension's filesystem and process access are justified by its purpose as a language server.
  • The extension's dependencies are typical for a language server and do not indicate malicious behavior.
  • The extension is developed by a verified publisher and its functionality is consistent with its stated purpose.

Reviewed 2026-05-23; recommended action: no action; model confidence 90%.

VS Code version history

Risk trend by version

11 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.

Selected
70
Change since first
-1
Change from previous
No change
Versions:
First analyzed version
2026.1.101
Mar 10, 2026
Risk range
31 to 72
Across analyzed versions
Latest analyzed version
2026.4.1
Sep 25, 2026
Selected version
high
Version
v2026.4.1
6 days ago
Risk score
70
Findings
24
Change vs previous
No change

Pick any point on the chart to explore that version's code below.

About This Extension

A performant, feature-rich language server for Python in VS Code

Frequently Asked Questions