JetBrains Marketplace Verified

Quokka

by 6d7ed77e-b276-469c-b88b-5bcc16fae09c · 524.0K users · 4.3 rating
bccf6b19-a506-56f6-a26b-4bf69456175b | v1.0.546
74/ 100
HIGH risk
No change since v1.0.545
Analyst verdict
Review before use

The AI review rates the findings as likely false positive, but the risk score (74/100) still counts them.

Analysis record

Analysed
Yesterday
Version
v1.0.546
Artifact
SHA256 94C…C7B
Source
Findings (non-IoC)

Is Quokka safe?

Quokka runs JavaScript and TypeScript inside your JetBrains IDE and shows the value of every expression as you type. It declares no special permissions and lists no network endpoints, so the reach it has comes from the job itself: attaching to a Node.js process and reading the file you have open.

The scanner's loudest flags land on library files inside quokka-intellij/dist/node_modules. Two WebSocket findings come from chrome-remote-interface/lib/chrome.js and chrome-remote-interface/lib/websocket-wrapper.js, which is the Chrome DevTools Protocol client Quokka uses to talk to the runtime it started. A batch of XMLHttpRequest findings come from source-map-support, sockjs-client, coffee-script and phantom, all of which ship inside larger npm packages as browser-targeted helpers. None of them contact a server on their own.

One finding is worth naming directly. A rule called YARA--supply_chain_sourcemap_appended_iife matched quokka-intellij/dist/server.js at line 364. That rule looks for an IIFE appended after a sourceMappingURL comment, a trick used to hide code from debuggers. In this file, the append is how the bundled source-map-support package installs its stack trace hook. Nothing in the bundle is obfuscated, and nothing reads credentials.

That is why the flags describe the scanner more than they describe Quokka. The signals are named after a bundler pattern and a debugging library, and both are needed by an extension whose whole purpose is evaluating your code live.

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

10 detail rows

YARA Rule Matches

1 rule
SeverityRuleHitsFilesMetadata
HIGHsupply chain sourcemap appended iife 1
quokka-intellij/dist/server.js
-

Publisher Evidence

Low

6d7ed77e-b276-469c-b88b-5bcc16fae09c

Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.

88
Noisy-finding weight
x1.00
Publisher domain
wallabyjs.com
Observed
Store verification signal
Verified publisher
Verified
Extension portfolio
8
Portfolio

12 evidence rows available.

Finding Categories

1
Malware Signatures

YARA Rules Matched

1 rule
supply chain sourcemap appended iife

AI Security Report

AI Security Review

Evidence context: threat category none; evidence quality moderate.

Quokka is a live JavaScript and TypeScript scratchpad for JetBrains IDEs. It evaluates your code as you type and shows the resulting values inline. That job requires two capabilities the scanner flagged: a persistent connection to a Node.js runtime, and code that reads and writes the file you are editing. Both show up in the findings, and both are load-bearing for the product.

The network hits are bundled library code, not plugin behavior. quokka-intellij/dist/node_modules/chrome-remote-interface/lib/chrome.js:223 and quokka-intellij/dist/node_modules/chrome-remote-interface/lib/websocket-wrapper.js:10 are the Chrome DevTools Protocol client Quokka uses to attach to the runtime it spawns and evaluate expressions against it. quokka-intellij/dist/node_modules/source-map-support/source-map-support.js:115 and quokka-intellij/dist/node_modules/@cspotcode/source-map-support/source-map-support.js:234 register hooks so that a thrown error points at your TypeScript line rather than the generated JavaScript. quokka-intellij/dist/node_modules/coffee-script/lib/coffee-script/browser.js:57 and quokka-intellij/dist/node_modules/phantom/shim.js:1756 are browser-targeted shims shipped inside those packages; a JetBrains plugin never reaches the code paths that use them.

Credential access is absent. There are no secret-category findings, no matches against .env, .ssh, .git/config, or any cloud credential path. Nothing in the scanned tree reaches for developer secrets, and the manifest declares no permissions and no network endpoints, so there is no declared channel for exfiltration even if something wanted one.

The strongest counterargument is the single high-severity hit: YARA--supply_chain_sourcemap_appended_iife fired on quokka-intellij/dist/server.js:364. Appending an IIFE after a sourceMappingURL comment is a documented way to hide a payload from debuggers, which is why the rule exists. It does not change the verdict. The two packages in this bundle that append code that way, source-map-support and @cspotcode/source-map-support, install their stack-trace hook with exactly that pattern by design. The flagged file is a bundle of hundreds of npm packages, and the same scan reports no obfuscation findings, no IoC hits, no secrets, and no tool-poisoning indicators anywhere in the tree.

What remains is an established listing, version 1.0.546, with 524,021 users and a release history long enough to have had many chances to be caught. An extension that executes user code for a living will always look like an extension that executes code. The signals here name a bundler pattern and a debugging library, not behavior.

Key Reasons

  • Sole high-severity finding, YARA--supply_chain_sourcemap_appended_iife at quokka-intellij/dist/server.js:364, matches the by-design install hook of the bundled source-map-support packages rather than an injected payload.
  • All 17 network findings are XMLHttpRequest or WebSocket references inside dist/node_modules (chrome-remote-interface, source-map-support, sockjs-client, coffee-script, phantom), which is expected bundle content for a live code evaluation plugin.
  • Zero secret, credential, obfuscation, IoC, or tool-poisoning findings across the scanned tree.
  • No declared permissions and no declared network endpoints, so no exfiltration channel is described by the manifest.
  • 524,021 users on the JetBrains marketplace with a long release history (version 1.0.546), inconsistent with a freshly planted supply chain payload.

False Positive Considerations

  • YARA supply_chain_sourcemap_appended_iife rule matching the standard install hook of bundled source-map-support libraries
  • Network category populated by XMLHttpRequest and WebSocket references in third-party dist/node_modules code rather than plugin logic
  • Browser-targeted shim files (coffee-script/lib/coffee-script/browser.js, phantom/shim.js) counted as live network activity in a JetBrains plugin
  • Bundled dependency tree producing per-library matches that multiply total finding count without indicating malicious behavior

Reviewed 2026-10-01; recommended action: suppress false positive; model confidence 87%.

JetBrains version history

Risk trend by version

11 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.

Selected
74
Change since first
+17
Change from previous
No change
Versions:
First analyzed version
1.0.534
Apr 5, 2026
Risk range
57 to 76
Across analyzed versions
Latest analyzed version
1.0.546
Sep 23, 2026
Selected version
high
Version
v1.0.546
1 weeks ago
Risk score
74
Findings
27
Change vs previous
No change

Pick any point on the chart to explore that version's code below.

About This Extension

Quokka is a rapid prototyping playground in your editor, with access to your project's files, inline reporting, code coverage and rich output formatting.

Frequently Asked Questions