Quokka
The AI review rates the findings as likely false positive, but the risk score (74/100) still counts them.
Analysis record
- Analysed
- Yesterday
- Version
- v1.0.546
- Artifact
- SHA256 94C…C7B
- Source
- Findings (non-IoC)
Is Quokka safe?
Quokka runs JavaScript and TypeScript inside your JetBrains IDE and shows the value of every expression as you type. It declares no special permissions and lists no network endpoints, so the reach it has comes from the job itself: attaching to a Node.js process and reading the file you have open.
The scanner's loudest flags land on library files inside quokka-intellij/dist/node_modules. Two WebSocket findings come from chrome-remote-interface/lib/chrome.js and chrome-remote-interface/lib/websocket-wrapper.js, which is the Chrome DevTools Protocol client Quokka uses to talk to the runtime it started. A batch of XMLHttpRequest findings come from source-map-support, sockjs-client, coffee-script and phantom, all of which ship inside larger npm packages as browser-targeted helpers. None of them contact a server on their own.
One finding is worth naming directly. A rule called YARA--supply_chain_sourcemap_appended_iife matched quokka-intellij/dist/server.js at line 364. That rule looks for an IIFE appended after a sourceMappingURL comment, a trick used to hide code from debuggers. In this file, the append is how the bundled source-map-support package installs its stack trace hook. Nothing in the bundle is obfuscated, and nothing reads credentials.
That is why the flags describe the scanner more than they describe Quokka. The signals are named after a bundler pattern and a debugging library, and both are needed by an extension whose whole purpose is evaluating your code live.
Evidence ledger
Ranked by severity · findings with a source location link to the code viewer
YARA Rule Matches
1 rule| Severity | Rule | Hits | Files | Metadata |
|---|---|---|---|---|
| HIGH | supply chain sourcemap appended iife | 1 | quokka-intellij/dist/server.js | - |
Publisher Evidence
Low6d7ed77e-b276-469c-b88b-5bcc16fae09c
Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.
12 evidence rows available.
Finding Categories
YARA Rules Matched
1 ruleAI Security Report
AI Security Review
Evidence context: threat category none; evidence quality moderate.
Quokka is a live JavaScript and TypeScript scratchpad for JetBrains IDEs. It evaluates your code as you type and shows the resulting values inline. That job requires two capabilities the scanner flagged: a persistent connection to a Node.js runtime, and code that reads and writes the file you are editing. Both show up in the findings, and both are load-bearing for the product.
The network hits are bundled library code, not plugin behavior. quokka-intellij/dist/node_modules/chrome-remote-interface/lib/chrome.js:223 and quokka-intellij/dist/node_modules/chrome-remote-interface/lib/websocket-wrapper.js:10 are the Chrome DevTools Protocol client Quokka uses to attach to the runtime it spawns and evaluate expressions against it. quokka-intellij/dist/node_modules/source-map-support/source-map-support.js:115 and quokka-intellij/dist/node_modules/@cspotcode/source-map-support/source-map-support.js:234 register hooks so that a thrown error points at your TypeScript line rather than the generated JavaScript. quokka-intellij/dist/node_modules/coffee-script/lib/coffee-script/browser.js:57 and quokka-intellij/dist/node_modules/phantom/shim.js:1756 are browser-targeted shims shipped inside those packages; a JetBrains plugin never reaches the code paths that use them.
Credential access is absent. There are no secret-category findings, no matches against .env, .ssh, .git/config, or any cloud credential path. Nothing in the scanned tree reaches for developer secrets, and the manifest declares no permissions and no network endpoints, so there is no declared channel for exfiltration even if something wanted one.
The strongest counterargument is the single high-severity hit: YARA--supply_chain_sourcemap_appended_iife fired on quokka-intellij/dist/server.js:364. Appending an IIFE after a sourceMappingURL comment is a documented way to hide a payload from debuggers, which is why the rule exists. It does not change the verdict. The two packages in this bundle that append code that way, source-map-support and @cspotcode/source-map-support, install their stack-trace hook with exactly that pattern by design. The flagged file is a bundle of hundreds of npm packages, and the same scan reports no obfuscation findings, no IoC hits, no secrets, and no tool-poisoning indicators anywhere in the tree.
What remains is an established listing, version 1.0.546, with 524,021 users and a release history long enough to have had many chances to be caught. An extension that executes user code for a living will always look like an extension that executes code. The signals here name a bundler pattern and a debugging library, not behavior.
Key Reasons
- Sole high-severity finding, YARA--supply_chain_sourcemap_appended_iife at quokka-intellij/dist/server.js:364, matches the by-design install hook of the bundled source-map-support packages rather than an injected payload.
- All 17 network findings are XMLHttpRequest or WebSocket references inside dist/node_modules (chrome-remote-interface, source-map-support, sockjs-client, coffee-script, phantom), which is expected bundle content for a live code evaluation plugin.
- Zero secret, credential, obfuscation, IoC, or tool-poisoning findings across the scanned tree.
- No declared permissions and no declared network endpoints, so no exfiltration channel is described by the manifest.
- 524,021 users on the JetBrains marketplace with a long release history (version 1.0.546), inconsistent with a freshly planted supply chain payload.
False Positive Considerations
- YARA supply_chain_sourcemap_appended_iife rule matching the standard install hook of bundled source-map-support libraries
- Network category populated by XMLHttpRequest and WebSocket references in third-party dist/node_modules code rather than plugin logic
- Browser-targeted shim files (coffee-script/lib/coffee-script/browser.js, phantom/shim.js) counted as live network activity in a JetBrains plugin
- Bundled dependency tree producing per-library matches that multiply total finding count without indicating malicious behavior
Reviewed 2026-10-01; recommended action: suppress false positive; model confidence 87%.
JetBrains version history
Risk trend by version
11 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.
Pick any point on the chart to explore that version's code below.
About This Extension
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace