JetBrains Marketplace Verified

Napi Generator

b09c2559-2813-5e09-a9e9-3c6bfbe9de0a | v1.0.3
47/ 100
MEDIUM risk
Analyst verdict
Review before use

The AI review rates the findings as likely false positive, but the risk score (47/100) still counts them.

Analysis record

Analysed
3 days ago
Version
v1.0.3
Artifact
SHA256 140…F75
Source
Findings (non-IoC)

Is Napi Generator safe?

Napi Generator is a JetBrains plugin that creates Node-API bindings so JavaScript can call native code, and about 1,420 developers have it installed. Its listing declares no host permissions, and the endpoint list attached to it is filled with entries like 0b.aw, 0r.hm and 4t.io, which are the kind of short strings you get when something scans a large minified JavaScript file looking for anything shaped like a web address.

The flagged domains are the same story. Entries such as XIOC-DOMAIN-kx.sz, XIOC-DOMAIN-u.tt and XIOC-DOMAIN-ƒ.sg were pulled from a file path recorded only as extracted_from_files. ƒ.sg contains a Latin ƒ character and another entry carries a Korean syllable, so neither could be a hostname anyone registered. A generator that quietly phoned home would need a working address, and these are fragments of property names and variables inside bundled code.

Alongside those, eleven low-severity code-quality matches fired on ordinary patterns that show up in any non-trivial JavaScript or Kotlin. No malware signature, no exposed secret and no obfuscation match turned up anywhere in the plugin. The plugin reads project sources and writes generated binding files, which is what a code generator does in an IDE.

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

13 detail rows

YARA Rule Matches

7 rules
SeverityRuleHitsFilesMetadata
LOWpostinstall file download 1
napi_generator/lib/napi_generator.jar
-
LOWpostinstall crypto operations 2
napi_generator/lib/fastjson2-2.0.42.jarnapi_generator/lib/napi_generator.jar
-
LOWpostinstall file manipulation 1
napi_generator/lib/fastjson2-2.0.42.jar
-
LOWJavaDropper 2
napi_generator/lib/fastjson2-2.0.42.jarnapi_generator/lib/napi_generator.jar
-
LOWpostinstall obfuscation 1
napi_generator/lib/fastjson2-2.0.42.jar
-
LOWpostinstall network communication 2
napi_generator/lib/fastjson2-2.0.42.jarnapi_generator/lib/napi_generator.jar
-
LOWpostinstall system command 2
napi_generator/lib/fastjson2-2.0.42.jarnapi_generator/lib/napi_generator.jar
-

Network Indicators

Concrete URLs, domains, IPs, emails, and hashes extracted from the analyzed artifact.

945 total
...

Network indicators are queued for lazy loading

Scroll this section into view to load the detailed rows.

Publisher Evidence

Limited evidence

a0afef8d-bb35-4ede-9d46-c1392258b5eb

Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.

37
Noisy-finding weight
x1.00
Publisher domain
kaihong.com
Observed
Store verification signal
Not exposed
Not exposed
Extension portfolio
3
Portfolio

12 evidence rows available.

Finding Categories

945
IoC Indicators

YARA Rules Matched

7 rules(11 hits)
postinstall file download postinstall crypto operations postinstall file manipulation JavaDropper postinstall obfuscation postinstall network communication postinstall system command

AI Security Report

AI Security Review

Evidence context: threat category none; evidence quality moderate.

Napi Generator is a JetBrains plugin, version 1.0.3, with roughly 1,420 installs, that helps developers build Node-API bindings. JetBrains plugins run inside the IDE process with the user's own file access, so the question worth asking is whether anything here reaches outside that job.

Nothing in the findings does. There are no malware signature matches, no secret matches, no obfuscation hits, and no dependency or tool-poisoning entries. What remains is 947 medium-severity indicators, all filed against the same generic path, extracted_from_files, with titles such as XIOC-DOMAIN-kx.sz, XIOC-DOMAIN-db.ad, XIOC-DOMAIN-u.tt and XIOC-DOMAIN-ƒ.sg.

Those are not domains. XIOC-DOMAIN-ƒ.sg carries a Latin ƒ (U+0192), the endpoint list includes 0쁄.ad with a Hangul syllable, and the rest are two- to four-character stems bolted onto country suffixes: kx.sz, r.cc, x.tk, q.bt. This is what a regex produces when it sweeps minified JavaScript for anything shaped like label-dot-label. The endpoint list runs alphabetically from 0b.aw through 4x.lu, which is the output of an extraction pass over a bundle, not a set of hosts a plugin contacts.

On filesystem and process access: generating bindings means reading a project's sources and running build tooling, and a JVM plugin operates with the IDE's own file access. The listing declares no host permissions, and the only file path attached to any indicator is the extraction bucket rather than a named config, key or credential file. Nothing here reads .env, .ssh, .git/config or a cloud credential store. A generator needs to see the project it is generating for.

On credentials: the secret category is empty. The eleven low-severity code-smell matches are code-quality heuristics; the same rules fire on any non-trivial JavaScript or Kotlin that touches process.env, an eval-shaped call or a crypto import. None of them name a file, and none carry a severity above low.

The strongest argument against this read is the raw number: 947 medium indicators is a lot, and one working command-and-control host buried in there would change everything. The individual entries defeat that argument. ƒ.sg and 0쁄.ad cannot resolve as written. kx.sz, u.tt and c.bs have the shape a minifier leaves behind when chains like b.call or h.next get split by an extraction pass. Someone hiding a real callback address would use a domain that resolves, not a single Hangul syllable in front of .ad. The volume tracks the size of the bundled code, not intent.

The finding set is scanner noise over build output, and the plugin's access matches what a binding generator is for.

Key Reasons

  • Every IoC indicator is a non-registrable fragment: XIOC-DOMAIN-ƒ.sg contains U+0192 and the endpoint 0쁄.ad contains a Hangul syllable, all extracted from minified code under the generic path extracted_from_files.
  • Zero matches in the malware-signature, secret, obfuscation, dependency and tool-poisoning categories.
  • The plugin declares no permissions and no host permissions, and no endpoint in the list resolves to a real host.
  • Filesystem and process use is consistent with a Node-API binding generator reading project sources and invoking build tooling inside the IDE process.
  • The eleven low-severity code-smell hits are code-quality heuristics with no attached file path.

False Positive Considerations

  • XIOC domain regex sweeping minified JavaScript produces two-character label plus ccTLD fragments such as kx.sz, r.cc, u.tt and x.tk.
  • Non-registrable strings in the IoC list: XIOC-DOMAIN-ƒ.sg contains U+0192 and 0쁄.ad contains a Hangul syllable.
  • Low-severity code-smell rules that fire on ordinary Node.js and JVM patterns, with no malware, secret or obfuscation category matching.
  • All indicators share the generic file path extracted_from_files rather than a named credential, config or executable file.

Reviewed 2026-09-30; recommended action: suppress false positive; model confidence 82%.

About This Extension

Introduction     One-click generation of NAPI framework code, business code framework, GN file, etc. according to the ts (typescript) interface...

Frequently Asked Questions