Notepad++ Plugins

Pork to Sausage

by Don HO
c0abdbc1-9683-529a-9ddb-bc5cd89ebc82 | v2.6
36/ 100
LOW risk
Analyst verdict
No high-risk signal observed

Based on the RiskyPlugins AI security review of the observed evidence.

Analysis record

Analysed
7 months ago
Version
v2.6
Source
Findings (non-IoC)

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

16 detail rows

YARA Rule Matches

2 rules
SeverityRuleHitsFilesMetadata
HIGHpostinstall system command

System command execution detected

3
license.txtConfig/pork2Sausage.inidemo/zip.base64/zipB64.java
Risky Plugins Authors FP 10%
HIGHpostinstall obfuscation

Code obfuscation techniques detected

5
Config/pork2Sausage.inireadme.txtdemo/zip.base64/commons-codec-1.4.jar +2 more
Risky Plugins Authors FP 20%

Finding Categories

8
Malware Signatures

YARA Rules Matched

2 rules(8 hits)
postinstall system command postinstall obfuscation

AI Security Report

AI Security Review

Evidence context: threat category none; evidence quality moderate.

The extension 'Pork to Sausage' is a Notepad++ plugin by Don HO that passes selected text to command line programs and replaces it with the output. This filesystem/process access is fully justified by the extension's stated purpose.

Filesystem/Process Access Justification: The extension's description explicitly states it passes text to command line programs. Process spawning for executing external commands is the core functionality, not suspicious behavior. No findings indicate unauthorized file access beyond the selected text scope.

Credential-Access Findings: The evidence contains zero credential-access findings. The findings_summary shows "secret":"0" in the threat_indicators. The IOC findings include developer email addresses ([email protected] in [email protected], [email protected] in [email protected]) which are legitimate contact information, not credential theft.

IOC Findings Are False Positives: All 13 IOC findings are known false-positive patterns:

  • IPv6 fragments: :: (XIOC-IP-::), e::badb (XIOC-IP-e::badb), e::fa (XIOC-IP-e::fa), e::e (XIOC-IP-e::e) are hex substrings from minified JavaScript, not real IP addresses
  • Java class references misread as domains: java.io (XIOC-DOMAIN-java.io), java.util.zip (XIOC-DOMAIN-java.util.zip), zipb64.java (XIOC-DOMAIN-zipb64.java), inflater.read (XIOC-DOMAIN-inflater.read) are Java class/method names, not network domains
  • Email domains: free.fr (XIOC-DOMAIN-free.fr), altern.org (XIOC-DOMAIN-altern.org) are from developer contact emails

Code-Smell Findings: The 8 code-smell findings are classified as noise per CVEQ guidelines. These fire on basic Node.js patterns and do not indicate malicious behavior.

Strongest Counterargument: The 0 user count could suggest a suspicious new extension. However, this alone does not indicate malicious intent. The developer Don HO is a known Notepad++ contributor, and all technical findings are explainable false positives. No malware signatures, network calls, obfuscation, or credential access were detected.

Key Reasons

  • All IOC findings are known false-positive patterns
  • No malware signatures detected
  • No network or credential findings
  • Process spawning justified by extension purpose
  • Developer email addresses are legitimate contact info

False Positive Considerations

  • IPv6 hex fragments misclassified as IPs
  • Java class names misclassified as domains
  • Developer email addresses extracted as IOCs
  • Code-smell rules on benign patterns

Reviewed 2026-04-27; recommended action: suppress false positive; model confidence 85%.

Frequently Asked Questions