JetBrains Marketplace Verified

Web Browser (JCEF)

by JetBrains · 797.6K users · 4.2 rating
bdef8b5d-2db8-5707-a258-2913785c1d96 | v263.5153.40-mac-arm64
96/ 100
CRITICAL risk
Risk verdict
Do not install

Score-based assessment (critical risk, 96/100). No analyst review available.

Analysis record

Analysed
1 weeks ago
Version
v263.3889.65-linux-x86_64
Artifact
SHA256 4C6…B64
Source
Findings (non-IoC)

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

734 detail rows
Showing 25 of 250 · highest severity first

YARA Rule Matches

18 rules
SeverityRuleHitsFilesMetadata
HIGHDatper

detect Datper in memory

1
jcef-plugin/jcef/libcef.so
JPCERT/CC Incident Response Group FP 10%
HIGHlost door

Lost Door

1
jcef-plugin/jcef/libcef.so
Kevin Falcoz FP 10%
LOWpostinstall persistence mechanism 28
jcef-plugin/jcef/locales/en-US.pakjcef-plugin/jcef/locales/it.pakjcef-plugin/lib/modules/intellij.internal.jcef.jar +25 more
-
LOWcredential env files 9
jcef-plugin/jcef/locales/ca.pakjcef-plugin/jcef/locales/fr.pakjcef-plugin/jcef/locales/pt-BR.pak +6 more
-
LOWNoUseWeakRandom 2
jcef-plugin/lib/modules/intellij.internal.jcef.jarjcef-plugin/jcef/libcef.so
-
LOWpostinstall file download 70
jcef-plugin/jcef/locales/bn.pakjcef-plugin/jcef/locales/ja.pakjcef-plugin/jcef/locales/pt-BR.pak +67 more
-
LOWNoUseEval 1
jcef-plugin/jcef/libcef.so
-
LOWpostinstall process injection 1
jcef-plugin/jcef/libGLESv2.so
-
LOWDebuggerStatementsShouldNotBeUsed 10
jcef-plugin/jcef/libcef.sojcef-plugin/lib/modules/intellij.platform.ide.impl.jcef.jarjcef-plugin/jcef/locales/id.pak +7 more
-
LOWspyeye 1
jcef-plugin/jcef/libcef.so
-
LOWLocalStorageShouldNotBeUsed 1
jcef-plugin/lib/modules/intellij.internal.jcef.jar
-
LOWpostinstall obfuscation 68
jcef-plugin/jcef/locales/hu.pakjcef-plugin/jcef/locales/tr.pakjcef-plugin/jcef/locales/it.pak +65 more
-
LOWpostinstall system command 73
jcef-plugin/jcef/locales/af.pakjcef-plugin/jcef/locales/ur.pakjcef-plugin/jcef/locales/en-US.pak +70 more
-
LOWpostinstall network communication 67
jcef-plugin/jcef/locales/tr.pakjcef-plugin/jcef/locales/it.pakjcef-plugin/jcef/resources.pak +64 more
-
LOWpostinstall file manipulation 71
jcef-plugin/jcef/locales/pt-PT.pakjcef-plugin/jcef/locales/tr.pakjcef-plugin/jcef/locales/it.pak +68 more
-
LOWpostinstall crypto operations 72
jcef-plugin/jcef/locales/sr.pakjcef-plugin/jcef/locales/ar.pakjcef-plugin/jcef/locales/de.pak +69 more
-
LOWpostinstall registry modification 7
jcef-plugin/jcef/libGLESv2.sojcef-plugin/jcef/libvk_swiftshader.sojcef-plugin/jcef/libcef.so +4 more
-
LOWUsingShellInterpreterWhenExecutingOSCommands 1
jcef-plugin/jcef/libcef.so
-

Network Indicators

Concrete URLs, domains, IPs, emails, and hashes extracted from the analyzed artifact.

8,110 total
...

Network indicators are queued for lazy loading

Scroll this section into view to load the detailed rows.

Publisher Evidence

High

JetBrains

Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.

100
Noisy-finding weight
x0.50
Publisher domain
jetbrains.com
Trusted match
Store verification signal
Verified publisher
Verified
Extension portfolio
940
Portfolio

12 evidence rows available.

Finding Categories

2
Malware Signatures
6
Obfuscation
8,110
IoC Indicators

YARA Rules Matched

18 rules(484 hits)
Datper lost door postinstall persistence mechanism credential env files NoUseWeakRandom postinstall file download NoUseEval postinstall process injection DebuggerStatementsShouldNotBeUsed spyeye LocalStorageShouldNotBeUsed postinstall obfuscation postinstall system command postinstall network communication postinstall file manipulation postinstall crypto operations +2 more

Security Analysis Summary

Security Analysis Overview

Web Browser (JCEF) is a JetBrains Marketplace extension published by JetBrains. Version 263.5153.40-mac-arm64 has been analyzed by the Risky Plugins security platform, receiving a risk score of 95.55/100 (CRITICAL risk) based on 8844 security findings.

Risk Assessment

This extension presents critical security risk. Severe issues were detected, potentially including malware indicators, exposed secrets, or dangerous behaviors. Installation is strongly discouraged until these issues are addressed.

Findings Breakdown

  • Critical: 6 finding(s)
  • High: 2 finding(s)
  • Medium: 8110 finding(s)
  • Low: 482 finding(s)

What Was Analyzed

The security assessment covers multiple analysis categories:

  • Malware Detection: YARA rule matching against 2,400+ malware signatures
  • Secret Detection: Scanning for exposed API keys, tokens, and credentials
  • Static Analysis: Code-level security analysis for common vulnerability patterns
  • Network Analysis: Detection of suspicious network communications and endpoints
  • Obfuscation Detection: Identification of code obfuscation techniques

Developer Information

Web Browser (JCEF) is published by JetBrains on the JetBrains Marketplace marketplace. The extension has approximately 798K users.

Recommendation

This extension is not recommended for installation without thorough manual review. Consider alternatives with lower risk scores, or contact the developer to address the identified security concerns.

About This Extension

Provides web browser integration based on JCEF, a framework for embedding Chromium-based browsers in Java applications.

Frequently Asked Questions