The AI review rates the findings as likely false positive, but the risk score (100/100) still counts them.
Analysis record
- Analysed
- 5 days ago
- Version
- v4.3.5
- Artifact
- SHA256 40A…FEC
- Source
- Findings (non-IoC)
Is BOO UI编辑器 safe?
boo-NGOM-editor is a toolkit for running Legend of Mir style game servers. It gives you script intellisense, a visual UI editor, readers for PAK and JPK game archives, database and map viewers, and a command to reload the M2 server. It declares no special permissions and no host permissions, and the only network calls found are inside the bundled sql.js library loading its own WebAssembly file.
Most of what the scanner flagged comes from the bundled tools folder. The extension ships an embedded Python runtime at extension/tools/PakBridge/bin/python312.dll along with the usual support libraries, and it uses that bridge to open and rewrite game files. A rule called OBFUSCATION-NATIVE_BINARY_ADDON fired on all of those DLLs. If that were real, it would mean someone had deliberately scrambled compiled code to hide what it does. Here it means the scanner looked at ordinary compiled Windows libraries, which never read like source code, and flagged them for it.
One finding deserves a straight answer. A signature called YARA--Emotet matched extension/tools/PakBridge/bin/lib/unicorn/lib/unicorn.dll. Emotet is a banking trojan, but those signatures are written against packed samples and they match plenty of emulation and crypto libraries. Unicorn is a well known open source CPU emulator, the sort of thing a tool for reading game client archives would include. There is no install step that runs code, nothing that reads your .env files or SSH keys, and no outbound traffic beyond the extension's own package files.
If you run a Legend of Mir server and want these tools, the extension does what it says with the access that takes.
Evidence ledger
Ranked by severity · findings with a source location link to the code viewer
YARA Rule Matches
18 rules| Severity | Rule | Hits | Files | Metadata |
|---|---|---|---|---|
| HIGH | Emotet detect Emotet in memory | 1 | tools/PakBridge/bin/lib/unicorn/lib/unicorn.dll | JPCERT/CC Incident Response Group FP 5% |
| LOW | LocalStorageShouldNotBeUsed | 1 | media/vendor/tabulator/tabulator.min.js | - |
| LOW | DebuggerStatementsShouldNotBeUsed | 1 | tools/PakBridge/bin/python312.dll | - |
| LOW | credential env files | 10 | out/utils/pak-reader.jsout/utils/cache-storage.jsout/providers/deepseek-view.js +7 more | - |
| LOW | WeakSSLTLSProtocolsShouldNotBeUsed | 2 | tools/PakBridge/bin/lib/_ssl.pydtools/PakBridge/bin/lib/libssl-3-x64.dll | - |
| LOW | postinstall persistence mechanism | 10 | out/providers/map-preview.jsout/utils/map-effects.jsreadme.md +7 more | - |
| LOW | postinstall file download | 13 | data/constants-996pc.jsondata/functions-996pc.jsonmedia/map-preview.html +10 more | - |
| LOW | SQLInjection | 2 | media/editor.htmlout/assistant.js | - |
| LOW | NoUseEval | 1 | tools/PakBridge/bin/python312.dll | - |
| LOW | NoUseWeakRandom | 3 | out/utils/database-browser.jsout/utils/custom-language.jsout/assistant.js | - |
| LOW | postinstall obfuscation | 59 | out/ui-dialog/preview-script-source.jsout/utils/drop-rate-external.jsout/utils/map-marker-state.js +56 more | - |
| LOW | postinstall system command | 94 | media/vendor/tabulator/tabulator.min.jsreadme.mddata/commands.json +91 more | - |
| LOW | UsingShellInterpreterWhenExecutingOSCommands | 1 | out/reload.js | - |
| LOW | postinstall crypto operations | 20 | out/utils/jpk-reader.jsout/utils/pak-password.jsout/assistant.js +17 more | - |
| LOW | postinstall network communication | 27 | out/ui-dialog/variable-resolver.jsout/ui-dialog/source-parser.jsout/reload.js +24 more | - |
| LOW | postinstall registry modification | 15 | out/utils/engine-detect.jsout/utils/custom-language.jsout/providers/map-preview.js +12 more | - |
| LOW | AlertStatementsShouldNotBeUsed | 1 | out/assistant.js | - |
| LOW | postinstall file manipulation | 51 | out/utils/pak-reader.jsout/ui-dialog/preview-inputs.jsout/providers/patch-manager.js +48 more | - |
Network Indicators
Concrete URLs, domains, IPs, emails, and hashes extracted from the analyzed artifact.
Network indicators are queued for lazy loading
Scroll this section into view to load the detailed rows.
Publisher Evidence
Limited evidenceboo1213
Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.
13 evidence rows available.
Finding Categories
YARA Rules Matched
18 rules(312 hits)AI Security Report
AI Security Review
Evidence context: threat category none; evidence quality moderate.
boo-NGOM-editor is a GM toolkit for Legend of Mir style game servers: script intellisense, a UI editor, PAK and JPK archive reading, database and map viewers, and an M2 reload command. Every native-binary finding sits inside that job description. The DLLs flagged as OBFUSCATION-NATIVE_BINARY_ADDON are extension/tools/PakBridge/bin/python312.dll, vcruntime140.dll, msvcp140.dll, libssl-3-x64.dll, libcrypto-3-x64.dll and libffi-8.dll. That group is the standard payload of an embedded CPython runtime: the interpreter, the Visual C++ redistributable it links against, and the TLS and FFI libraries it loads. extension/tools/PakBridge/bin/lib/unicorn/lib/unicorn.dll is the Unicorn CPU emulator, which a PAK/JPK bridge would use to decode or emulate game client code. These are public libraries shipped in a bin/ folder, not custom artefacts. An entropy rule run against a compiled binary cannot tell a normal DLL from a packed one, which is why all of them fired.
Process and filesystem reach here is broad, and it is meant to be. PakBridge runs an embedded Python interpreter as a child process to parse archives and query game databases, so the extension can read and write game files outside the workspace and run code with the user's own privileges. For a tool whose stated purpose is editing server-side scripts and unpacking game archives, that reach is the feature.
Credential findings are absent. Nothing matched secret scanning, and nothing touches .env, .ssh, .git/config or cloud credential paths. The two network findings are both in extension/node_modules/sql.js/dist/sql-wasm.js at lines 97 and 100, the loader that pulls in sql.js's own .wasm binary from the extension package.
The malware signature to weigh is YARA--Emotet on extension/tools/PakBridge/bin/lib/unicorn/lib/unicorn.dll. Emotet rules are written against packed banking-trojan samples and routinely match emulator and crypto-heavy binaries. Unicorn is a widely used open-source emulation library, and its presence next to Python and OpenSSL in a game-data bridge is unremarkable.
The strongest counterargument is that bundling a full Python runtime, OpenSSL and a CPU emulator inside a VS Code extension hands a large amount of trusted code to the extension host, and any of those binaries could in principle be swapped for something hostile in a future release. That argument would carry weight if the binaries were custom, unidentifiable, or unique to this package, or if a finding showed them being written to disk, launched from a postinstall step, or contacting an external host. Nothing here shows that. There is no install-time execution, no credential read, and the external endpoints reported by IoC extraction are fragments such as act-ui-preview-panel.show, arc2.py and basehttprequesthandler.date, which are property chains and file extensions pulled out of library code.
Broad but expected capability, standard runtime libraries, and no evidence of payload execution, theft or exfiltration.
Key Reasons
- All OBFUSCATION-NATIVE_BINARY_ADDON hits are standard runtime DLLs under extension/tools/PakBridge/bin/ (python312.dll, msvcp140.dll, vcruntime140.dll, libssl-3-x64.dll, libcrypto-3-x64.dll, libffi-8.dll), the normal payload of an embedded CPython distribution.
- YARA--Emotet matched extension/tools/PakBridge/bin/lib/unicorn/lib/unicorn.dll, the public Unicorn CPU emulator, a well-documented source of false hits from Emotet rules.
- Both NET-FETCH findings are in extension/node_modules/sql.js/dist/sql-wasm.js at lines 97 and 100, the loader fetching sql.js's own .wasm asset, not an outbound channel.
- No credential, secret or postinstall findings; the reported network endpoints are extraction artefacts such as act-ui-preview-panel.show, arc2.py and basehttprequesthandler.date.
- Bundled Python plus PAK/JPK parsing explains the process and file access, which matches the extension's stated server-management purpose.
False Positive Considerations
- Native-binary entropy rule firing on unmodified MSVC, OpenSSL, libffi and Python runtime DLLs
- Broad Emotet YARA family rule matching the Unicorn emulator library
- NET-FETCH hits inside a minified bundled dependency loading its own WASM file
- Thousands of IoC entries that are property access chains, file extensions and library substrings rather than hosts
Reviewed 2026-09-26; recommended action: suppress false positive; model confidence 78%.
Open VSX version history
Risk trend by version
4 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.
Pick any point on the chart to explore that version's code below.
Source Code Not Available
Source code is not available for this version of the extension.
About This Extension
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace