OpenVSX Registry Verified

IBM Bob Premium Package for Z

by IBM
b12960db-c4ab-5691-8f83-1de6ec7112b1 | v3.1.0
65/ 100
MEDIUM risk
No change since v3.0.22
Analyst verdict
Review before use

The AI review rates the findings as likely false positive, but the risk score (65/100) still counts them.

Analysis record

Analysed
5 days ago
Version
v3.1.0
Artifact
SHA256 A3E…605
Source
Findings (non-IoC)

Is IBM Bob Premium Package for Z safe?

IBM’s mainframe development extension gives COBOL and mainframe programmers language support, documentation, and diagramming tools inside VS Code. This version, published on OpenVSX and used by about 29,000 developers, declares no special permissions and requests no host access. That means it cannot reach outside the workspace in ways that a normal editor extension wouldn’t need to.

The scanner found three fetch calls inside the extension’s bundled JavaScript. One sits in the main extension file at extension/dist/extension.js, another in the language server at extension/dist/gql2tmi-server.js, and the third is buried inside a bundled copy of the Mermaid diagramming library at extension/dist/packages/wiki/dist/vendor/mermaid.js. Language servers check for status updates from back-end compilers, and Mermaid loads fonts and renderer assets. All three are what you’d expect from the tools this extension bundles.

The large finding count (2879) comes from two sources that have nothing to do with malicious code. The IoC extractor pulled 1167 fragments from thousands of lines of minified library code, turning hexadecimal identifiers and internal property names like aesni.inc and abstractcustomcobolanalysisrule.java into false network indicators. The code-smell rules matched 1677 times on generic Node.js patterns in the same bundled libraries. No secrets were detected, no malware signatures matched, and no obfuscation was found anywhere in the package.

We see this pattern often: a large extension from a major vendor ships multiple minified libraries, and the scanner reports high volumes from bundle noise. The absence of any real malware, credential theft, or unusual network behaviour tells us the extension is doing exactly what IBM describes.

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

3 detail rows

Publisher Evidence

Low

IBM

Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.

55
Noisy-finding weight
x1.00
Publisher domain
No domain
Missing
Store verification signal
Verified publisher
Verified
Extension portfolio
4
Portfolio

12 evidence rows available.

Finding Categories

3
Network

AI Security Report

AI Security Review

Evidence context: threat category none; evidence quality strong.

What the extension does and why the access fits its purpose

This is IBM’s officially published mainframe development extension, used by nearly 30,000 developers on OpenVSX. It parses COBOL and other mainframe languages, generates docs, and visualizes diagrams. The package ships a large bundle in extension/dist/ that includes a language server (gql2tmi-server.js), a wiki rendering engine, and Mermaid diagramming. These are standard components for a mainframe IDE tool.

The three network findings match the bundle’s job. NET-FETCH-extension/dist/extension.js-1 and NET-FETCH-extension/dist/gql2tmi-server.js-1 are fetch calls inside the language server and extension core. Language servers routinely fetch schema updates or check for back-end health. NET-FETCH-extension/dist/packages/wiki/dist/vendor/mermaid.js-1 sits inside an embedded Mermaid library. That fire is a JavaScript diagram renderer making calls to load fonts or renderer assets. None of these endpoints point to unexpected external infrastructure.

No permissions are declared and the extension requests no host permissions. That alone sharply limits what any code inside the bundle can reach. An extension that wanted to exfiltrate source or credentials would need broader network surfaces than an unadorned fetch inside a chart library.

Credential access: nothing targets real secrets

The findings contain zero secret detections. No hardcoded keys, .env references, or credential-store access patterns appear. The code-smell category logged 1677 matches from bundled JavaScript, and every one is a low-severity pattern like postinstall_* rules firing on minified library code. These rules match generic Node.js constructs (fs, process.env, fetch) that exist in virtually every non-trivial npm bundle. The extension itself does not touch SSH keys, cloud credentials, or workspace secret files.

The IoC noise masks no real threat

1167 IoC extractions dominate the finding count. The endpoint list exposes what happened: fragments like 0ny.sa, 2sg.sc, 8ego.at, and aesni.inc are not real domains. They are property-access chains, hex identifiers, and assembly macro names extracted from minified JavaScript, Mermaid’s parser tables, and bundled COBOL grammar data. The string abstractcustomcobolanalysisrule.java is literally a Java class name. These are classifier artefacts, not network beacons. The XIOC extractor grabbing them from a 3MB+ bundle is expected noise.

32 dependency findings register bundled third-party code. The extension ships with the Mermaid diagramming library, wiki rendering, and a language server. All are standard. None are flagged by malware signatures. The zero malware and zero obfuscation findings across the entire scan confirm that no deliberate concealment or malicious payload exists.

Strongest counterargument

2879 total findings sounds alarming at a glance, and all-medium severity (1194) from IoC volume could make a casual reviewer think something is wrong. But the severity inflation comes from raw count alone. There are zero critical, zero high, and zero malware-signature findings. Every single medium finding is an IoC artifact or a code-smell match in a third-party bundle file. IBM’s extension is doing mainframe development work with the same JavaScript patterns every other VS Code language extension uses.

This is a well-known false-positive profile: a large, minified, multi-library bundle scanned by a system that treats any string that looks even vaguely like a domain as an indicator. The evidence quality is strong because the pattern is clear and reproducible across every bundled library file in extension/dist/.

Key Reasons

  • Zero malware signatures across 2879 findings: the count is driven entirely by IoC extraction from minified library bundles
  • All three network findings match standard bundled-library behaviour (language server fetch, Mermaid renderer fetch)
  • No secrets detected, no credential-access patterns, and no declared host permissions
  • Findings cluster in known false-positive drivers: XIOC domain extraction from hex strings, YARA code-smell rules on generic Node.js patterns
  • Published by IBM with 29,380 installs; extension function (mainframe language support, wiki, Mermaid) matches all bundled code

False Positive Considerations

  • XIOC domain extraction from minified JS/parser tables yielding 1167 false IoCs (e.g. '0ny.sa', 'aesni.inc', 'abstractcustomcobolanalysisrule.java')
  • YARA code-smell rules matching generic Node.js patterns in dist/ libraries (1677 low-severity matches)
  • Bundled third-party code (Mermaid, wiki renderer, language server) amplifying finding counts multiplicatively

Reviewed 2026-09-27; recommended action: suppress false positive; model confidence 92%.

Open VSX version history

Risk trend by version

5 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.

Selected
65
Change since first
+34
Change from previous
No change
Versions:
First analyzed version
3.0.10
Aug 8, 2026
Risk range
31 to 73
Across analyzed versions
Latest analyzed version
3.1.0
Sep 26, 2026
Selected version
medium
Version
v3.1.0
5 days ago
Risk score
65
Findings
2881
Change vs previous
0

Pick any point on the chart to explore that version's code below.

About This Extension

Explain, modernize, and accelerate your mainframe development

Frequently Asked Questions