JetBrains Marketplace Verified

Junie, the AI coding agent by JetBrains

by JetBrains · 34.8M users · 2.9 rating
b4d72892-22ea-5a1d-bd35-2c8cc4dd7afb | v261.2144.120
49/ 100
MEDIUM risk
No change since v262.2144.110
Analyst verdict
Review before use

The AI review rates the findings as likely false positive, but the risk score (49/100) still counts them.

Analysis record

Analysed
Yesterday
Version
v261.2144.120
Artifact
SHA256 00A…3BE
Source
Findings (non-IoC)

Is Junie, the AI coding agent by JetBrains safe?

Junie is JetBrains' AI coding agent. It reads your project, writes and edits files, runs commands, and sends context to JetBrains' servers so the model can answer. The extension declares no special permissions of its own, and the network endpoints recorded for it are a mix of JetBrains service hosts and junk. One entry is literally 1alpha-2-3-map.properties, which is a Java resource-bundle filename, not a server anyone can connect to.

The individual findings follow the same pattern. The scanner's domain list includes entries like XIOC-DOMAIN-i.sk, XIOC-DOMAIN-y.tv, XIOC-DOMAIN-x.mc and XIOC-DOMAIN-αu.gh. If one of those were a real command-and-control host it would be serious. They show up because the extractor walks bundled, minified build output and reads short byte runs as hostnames. A Greek alpha sitting inside a label is the giveaway, since no registrar issues those. The rest of the matches are low-severity code-smell rules of the kind that fire on any code that opens a file or reads an environment variable.

That is why we don't treat this as a threat. Nothing matched a malware signature, no secret files are targeted, and no call to an outside server appears beyond the ones the product needs. Junie does send your code to JetBrains when you ask it to, which is the trade you make when you use it rather than a hidden behavior.

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

189 detail rows
Showing 25 of 189 · highest severity first

Publisher Evidence

High

JetBrains

Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.

100
Noisy-finding weight
x0.50
Publisher domain
jetbrains.com
Trusted match
Store verification signal
Verified publisher
Verified
Extension portfolio
945
Portfolio

12 evidence rows available.

Finding Categories

AI Security Report

AI Security Review

Evidence context: threat category none; evidence quality moderate.

Junie is JetBrains' AI coding agent, distributed through JetBrains' own marketplace under the publisher name JetBrains, with roughly 34.8 million installs recorded against version 261.2144.120. It reads project files, edits code, runs commands and calls JetBrains' hosted models to produce suggestions. Reading the workspace, writing to it and spawning helpers such as build tools and language servers are the mechanics of that job, and the manifest here declares no host permissions and no extension-specific permissions at all.

The domain indicators are parser noise, not infrastructure. Every entry has the shape of XIOC-DOMAIN-i.sk, XIOC-DOMAIN-4s.mr, XIOC-DOMAIN-y.tv, XIOC-DOMAIN-c.cy, XIOC-DOMAIN-x.mc, XIOC-DOMAIN-d.gd, XIOC-DOMAIN-p.im or XIOC-DOMAIN-αu.gh. Taken literally those would be registrations on small country-code TLDs, which is not where a campaign lives. Taken as what they are, they are one- and two-character byte runs lifted from compiled or minified output and reshaped into hostname syntax. The endpoint list shows the same extractor misfiring: 1alpha-2-3-map.properties is a Java resource-bundle filename, and 5ĵjllq.uk, 1-ҍ.pm and 5ϸ.gr carry glyphs mid-label that no registrar issues.

Nothing in the evidence points at credentials. There are no secret-detection hits, no malware-signature matches, no obfuscation findings, no dependency or tool-poisoning findings, and no reference to .env, .ssh, .git/config, cloud credential paths or IDE secret storage. The remaining signal is a set of low-severity code-smell matches, the rules that fire on any file touching fs, child_process, crypto or process.env. For a coding agent those calls are the product.

The strongest argument against this conclusion is that Junie holds the keys to your workspace. It reads your source and sends context to a remote model, which is the same shape as an exfiltration tool, and it can run shell commands on your behalf. That is a real trade, and it is why a coding agent deserves more scrutiny than a formatter. It does not change the conclusion, because the transfer is the declared function of the product and is aimed at JetBrains' own service, not at an unidentified host. Every hostname the scanner flagged as suspicious dissolves on inspection, and no finding connects workspace reads to a destination outside that service. A tool doing what it advertises, with a noisy scanner output, is not a finding.

What would move this: a postinstall script that fetches and executes a payload, a read of .env or ~/.ssh paired with an outbound call, or an endpoint outside JetBrains' domains. None of those appear in the evidence for version 261.2144.120.

Key Reasons

  • Official JetBrains marketplace listing with about 34.8 million installs and zero malware-signature, secret-access or tool-poisoning findings
  • All domain indicators are malformed fragments (single-character labels, non-Latin glyphs) scraped from bundled build output
  • Code-smell matches are low severity and expected for an agent that reads files and spawns build tools
  • Empty permission and host-permission sets, with no targeting of .env, .ssh, .git/config or IDE secret storage

False Positive Considerations

  • IoC extractor reshapes short byte runs from bundled output into domain syntax, as in XIOC-DOMAIN-i.sk and XIOC-DOMAIN-αu.gh
  • Low-severity code-smell rules fire on any code touching fs, child_process, crypto or process.env
  • Non-Latin and numeric segments such as 5ĵjllq.uk, 1-ҍ.pm and 5ϸ.gr are not registrable hostnames
  • Resource-bundle filenames like 1alpha-2-3-map.properties misparsed as network endpoints

Reviewed 2026-10-01; recommended action: suppress false positive; model confidence 89%.

JetBrains version history

Risk trend by version

8 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.

Selected
49
Change since first
+7
Change from previous
No change
Versions:
First analyzed version
262.2144.50
Jul 13, 2026
Risk range
42 to 49
Across analyzed versions
Latest analyzed version
261.2144.120
Sep 9, 2026
Selected version
medium
Version
v261.2144.120
3 weeks ago
Risk score
49
Findings
1344
Change vs previous
0

Pick any point on the chart to explore that version's code below.

About This Extension

Junie is an AI coding agent by JetBrains that handles tasks autonomously or in collaboration with a developer. Developers can either fully delegate routine tasks to...

Frequently Asked Questions