OpenVSX Registry

BOO UI编辑器

b92905e5-2065-52be-85b6-b8ad3c4733e4 | v4.3.5
100/ 100
CRITICAL risk
+35 since v4.2.5
Analyst verdict
Do not install

The AI review rates the findings as likely false positive, but the risk score (100/100) still counts them.

Analysis record

Analysed
5 days ago
Version
v4.3.5
Artifact
SHA256 40A…FEC
Source
Findings (non-IoC)

Is BOO UI编辑器 safe?

boo-NGOM-editor is a toolkit for running Legend of Mir style game servers. It gives you script intellisense, a visual UI editor, readers for PAK and JPK game archives, database and map viewers, and a command to reload the M2 server. It declares no special permissions and no host permissions, and the only network calls found are inside the bundled sql.js library loading its own WebAssembly file.

Most of what the scanner flagged comes from the bundled tools folder. The extension ships an embedded Python runtime at extension/tools/PakBridge/bin/python312.dll along with the usual support libraries, and it uses that bridge to open and rewrite game files. A rule called OBFUSCATION-NATIVE_BINARY_ADDON fired on all of those DLLs. If that were real, it would mean someone had deliberately scrambled compiled code to hide what it does. Here it means the scanner looked at ordinary compiled Windows libraries, which never read like source code, and flagged them for it.

One finding deserves a straight answer. A signature called YARA--Emotet matched extension/tools/PakBridge/bin/lib/unicorn/lib/unicorn.dll. Emotet is a banking trojan, but those signatures are written against packed samples and they match plenty of emulation and crypto libraries. Unicorn is a well known open source CPU emulator, the sort of thing a tool for reading game client archives would include. There is no install step that runs code, nothing that reads your .env files or SSH keys, and no outbound traffic beyond the extension's own package files.

If you run a Legend of Mir server and want these tools, the extension does what it says with the access that takes.

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

337 detail rows

YARA Rule Matches

18 rules
SeverityRuleHitsFilesMetadata
HIGHEmotet

detect Emotet in memory

1
tools/PakBridge/bin/lib/unicorn/lib/unicorn.dll
JPCERT/CC Incident Response Group FP 5%
LOWLocalStorageShouldNotBeUsed 1
media/vendor/tabulator/tabulator.min.js
-
LOWDebuggerStatementsShouldNotBeUsed 1
tools/PakBridge/bin/python312.dll
-
LOWcredential env files 10
out/utils/pak-reader.jsout/utils/cache-storage.jsout/providers/deepseek-view.js +7 more
-
LOWWeakSSLTLSProtocolsShouldNotBeUsed 2
tools/PakBridge/bin/lib/_ssl.pydtools/PakBridge/bin/lib/libssl-3-x64.dll
-
LOWpostinstall persistence mechanism 10
out/providers/map-preview.jsout/utils/map-effects.jsreadme.md +7 more
-
LOWpostinstall file download 13
data/constants-996pc.jsondata/functions-996pc.jsonmedia/map-preview.html +10 more
-
LOWSQLInjection 2
media/editor.htmlout/assistant.js
-
LOWNoUseEval 1
tools/PakBridge/bin/python312.dll
-
LOWNoUseWeakRandom 3
out/utils/database-browser.jsout/utils/custom-language.jsout/assistant.js
-
LOWpostinstall obfuscation 59
out/ui-dialog/preview-script-source.jsout/utils/drop-rate-external.jsout/utils/map-marker-state.js +56 more
-
LOWpostinstall system command 94
media/vendor/tabulator/tabulator.min.jsreadme.mddata/commands.json +91 more
-
LOWUsingShellInterpreterWhenExecutingOSCommands 1
out/reload.js
-
LOWpostinstall crypto operations 20
out/utils/jpk-reader.jsout/utils/pak-password.jsout/assistant.js +17 more
-
LOWpostinstall network communication 27
out/ui-dialog/variable-resolver.jsout/ui-dialog/source-parser.jsout/reload.js +24 more
-
LOWpostinstall registry modification 15
out/utils/engine-detect.jsout/utils/custom-language.jsout/providers/map-preview.js +12 more
-
LOWAlertStatementsShouldNotBeUsed 1
out/assistant.js
-
LOWpostinstall file manipulation 51
out/utils/pak-reader.jsout/ui-dialog/preview-inputs.jsout/providers/patch-manager.js +48 more
-

Network Indicators

Concrete URLs, domains, IPs, emails, and hashes extracted from the analyzed artifact.

3,968 total
...

Network indicators are queued for lazy loading

Scroll this section into view to load the detailed rows.

Publisher Evidence

Limited evidence

boo1213

Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.

20
Noisy-finding weight
x1.00
Publisher domain
No domain
Missing
Store verification signal
Not exposed
Not exposed
Extension portfolio
1
Portfolio

13 evidence rows available.

Finding Categories

1
Malware Signatures
19
Obfuscation
2
Network
3,968
IoC Indicators

YARA Rules Matched

18 rules(312 hits)
Emotet LocalStorageShouldNotBeUsed DebuggerStatementsShouldNotBeUsed credential env files WeakSSLTLSProtocolsShouldNotBeUsed postinstall persistence mechanism postinstall file download SQLInjection NoUseEval NoUseWeakRandom postinstall obfuscation postinstall system command UsingShellInterpreterWhenExecutingOSCommands postinstall crypto operations postinstall network communication postinstall registry modification +2 more

AI Security Report

AI Security Review

Evidence context: threat category none; evidence quality moderate.

boo-NGOM-editor is a GM toolkit for Legend of Mir style game servers: script intellisense, a UI editor, PAK and JPK archive reading, database and map viewers, and an M2 reload command. Every native-binary finding sits inside that job description. The DLLs flagged as OBFUSCATION-NATIVE_BINARY_ADDON are extension/tools/PakBridge/bin/python312.dll, vcruntime140.dll, msvcp140.dll, libssl-3-x64.dll, libcrypto-3-x64.dll and libffi-8.dll. That group is the standard payload of an embedded CPython runtime: the interpreter, the Visual C++ redistributable it links against, and the TLS and FFI libraries it loads. extension/tools/PakBridge/bin/lib/unicorn/lib/unicorn.dll is the Unicorn CPU emulator, which a PAK/JPK bridge would use to decode or emulate game client code. These are public libraries shipped in a bin/ folder, not custom artefacts. An entropy rule run against a compiled binary cannot tell a normal DLL from a packed one, which is why all of them fired.

Process and filesystem reach here is broad, and it is meant to be. PakBridge runs an embedded Python interpreter as a child process to parse archives and query game databases, so the extension can read and write game files outside the workspace and run code with the user's own privileges. For a tool whose stated purpose is editing server-side scripts and unpacking game archives, that reach is the feature.

Credential findings are absent. Nothing matched secret scanning, and nothing touches .env, .ssh, .git/config or cloud credential paths. The two network findings are both in extension/node_modules/sql.js/dist/sql-wasm.js at lines 97 and 100, the loader that pulls in sql.js's own .wasm binary from the extension package.

The malware signature to weigh is YARA--Emotet on extension/tools/PakBridge/bin/lib/unicorn/lib/unicorn.dll. Emotet rules are written against packed banking-trojan samples and routinely match emulator and crypto-heavy binaries. Unicorn is a widely used open-source emulation library, and its presence next to Python and OpenSSL in a game-data bridge is unremarkable.

The strongest counterargument is that bundling a full Python runtime, OpenSSL and a CPU emulator inside a VS Code extension hands a large amount of trusted code to the extension host, and any of those binaries could in principle be swapped for something hostile in a future release. That argument would carry weight if the binaries were custom, unidentifiable, or unique to this package, or if a finding showed them being written to disk, launched from a postinstall step, or contacting an external host. Nothing here shows that. There is no install-time execution, no credential read, and the external endpoints reported by IoC extraction are fragments such as act-ui-preview-panel.show, arc2.py and basehttprequesthandler.date, which are property chains and file extensions pulled out of library code.

Broad but expected capability, standard runtime libraries, and no evidence of payload execution, theft or exfiltration.

Key Reasons

  • All OBFUSCATION-NATIVE_BINARY_ADDON hits are standard runtime DLLs under extension/tools/PakBridge/bin/ (python312.dll, msvcp140.dll, vcruntime140.dll, libssl-3-x64.dll, libcrypto-3-x64.dll, libffi-8.dll), the normal payload of an embedded CPython distribution.
  • YARA--Emotet matched extension/tools/PakBridge/bin/lib/unicorn/lib/unicorn.dll, the public Unicorn CPU emulator, a well-documented source of false hits from Emotet rules.
  • Both NET-FETCH findings are in extension/node_modules/sql.js/dist/sql-wasm.js at lines 97 and 100, the loader fetching sql.js's own .wasm asset, not an outbound channel.
  • No credential, secret or postinstall findings; the reported network endpoints are extraction artefacts such as act-ui-preview-panel.show, arc2.py and basehttprequesthandler.date.
  • Bundled Python plus PAK/JPK parsing explains the process and file access, which matches the extension's stated server-management purpose.

False Positive Considerations

  • Native-binary entropy rule firing on unmodified MSVC, OpenSSL, libffi and Python runtime DLLs
  • Broad Emotet YARA family rule matching the Unicorn emulator library
  • NET-FETCH hits inside a minified bundled dependency loading its own WASM file
  • Thousands of IoC entries that are property access chains, file extensions and library substrings rather than hosts

Reviewed 2026-09-26; recommended action: suppress false positive; model confidence 78%.

Open VSX version history

Risk trend by version

4 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.

Selected
100
Change since first
+35
Change from previous
+35
Versions:
First analyzed version
4.1.8
Jul 20, 2026
Risk range
65 to 100
Across analyzed versions
Latest analyzed version
4.3.5
Sep 26, 2026
Selected version
critical
Version
v4.3.5
5 days ago
Risk score
100
Findings
4305
Change vs previous
+35

Pick any point on the chart to explore that version's code below.

About This Extension

面向传奇类游戏 GM 的 VS Code 开发工具,提供脚本智能提示、UI 可视化编辑、PAK/JPK 读取、数据库与地图查看及 M2 重载。

Frequently Asked Questions