JetBrains Marketplace

JTools

by 8349aa96-e390-43d3-9aaf-5572ea8a8593 · 2.3K users · 4.6 rating
be3bceb9-57c7-5c0d-8948-134548968c31 | v1.1.5.7
48/ 100
MEDIUM risk
No change since v1.1.5.6
Analyst verdict
Review before use

The AI review rates the findings as likely false positive, but the risk score (48/100) still counts them.

Analysis record

Analysed
2 days ago
Version
v1.1.5.7
Artifact
SHA256 8F1…F6E
Source
Findings (non-IoC)

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

60 detail rows
Showing 25 of 60 · highest severity first

Publisher Evidence

Limited evidence

8349aa96-e390-43d3-9aaf-5572ea8a8593

Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.

34
Noisy-finding weight
x1.00
Publisher domain
No domain
Missing
Store verification signal
Not exposed
Not exposed
Extension portfolio
5
Portfolio

12 evidence rows available.

Finding Categories

AI Security Report

AI Security Review

Evidence context: threat category none; evidence quality weak.

The JTools extension for JetBrains declares no explicit permissions in the provided metadata. The permissions and host_permissions arrays are completely empty. For a general utility plugin, this aligns with standard behavior where the IDE grants baseline access without requiring elevated filesystem or process execution rights. We see no evidence of the extension spawning unauthorized child processes or reading files outside its expected scope. The lack of declared permissions means the plugin relies entirely on the default sandbox provided by the JetBrains platform, limiting its ability to access arbitrary system resources.

When evaluating credential access, the evidence is entirely clean. The scan results show zero secret detections across the entire codebase. There are no alerts for reading .env files, accessing .ssh directories, or harvesting cloud credentials. The extension does not attempt to interact with the IDE secret storage or credential providers. This complete absence of secret-access findings confirms the plugin is not attempting to steal developer credentials or exfiltrate sensitive configuration data.

The strongest counterargument to a clean verdict relies on the sheer volume of automated alerts. The scan results contain 452 medium-severity IoC findings and 155 low-severity code-smell findings. A reviewer might look at alerts like XIOC-DOMAIN-r.gt, XIOC-DOMAIN-g.pw, and XIOC-DOMAIN-ʞ.co and conclude the extension is beaconing to a vast network of suspicious domains. They might also point to the 155 code-smell alerts as evidence of hidden payloads or malicious logic buried deep within the compiled output.

Those conclusions ignore the actual content of the extracted indicators. The domains are structurally absurd. They include two-letter country codes, domains containing unicode characters like rī.au and 2ڊc.nz, and even a Java configuration file named sqlite-jdbc.properties misidentified as a web address. These are well-documented artifacts of a broken IoC extractor misinterpreting minified JavaScript, binary data, or bundled dependencies as network traffic, rather than actual outbound connections. The code-smell findings are standard noise that trigger on any non-trivial codebase containing basic file or network operations.

The network endpoints list further confirms this pattern. The scanner extracted addresses like 02m.ca, 0zx.fo, and 7蔧u.fi. These three-character domains and unicode-laden strings are not real infrastructure. They are hex substrings and binary fragments parsed incorrectly by the extraction tool. With zero malware signatures, zero secret detections, and no legitimate network endpoints, the extension poses no threat.

Key Reasons

  • Zero malware signatures and zero secret access findings
  • 452 IoC findings are structurally invalid garbage including unicode domains and properties files
  • No explicit permissions or host permissions declared in the package metadata
  • 155 code-smell findings are standard noise for non-trivial codebases

False Positive Considerations

  • Broken IoC extractor parsing minified JS and binary data as domains
  • Code-smell YARA rules firing on standard bundled dependencies
  • XIOC extractor misidentifying configuration filenames as network endpoints

Reviewed 2026-10-01; recommended action: suppress false positive; model confidence 95%.

JetBrains version history

Risk trend by version

21 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.

Selected
48
Change since first
+7
Change from previous
No change
Versions:
First analyzed version
1.1.3.8
Apr 16, 2026
Risk range
41 to 48
Across analyzed versions
Latest analyzed version
1.1.5.7
Sep 14, 2026
Selected version
medium
Version
v1.1.5.7
2 weeks ago
Risk score
48
Findings
670
Change vs previous
0

Pick any point on the chart to explore that version's code below.

About This Extension

JTools is a powerful and lightweight plugin management container designed specifically for JetBrains IDEs. It revolutionizes the plugin development experience by...

Frequently Asked Questions