Based on the RiskyPlugins AI security review of the observed evidence.
Analysis record
- Analysed
- 7 months ago
- Version
- v2.6
- Source
- Findings (non-IoC)
Evidence ledger
Ranked by severity · findings with a source location link to the code viewer
YARA Rule Matches
2 rules| Severity | Rule | Hits | Files | Metadata |
|---|---|---|---|---|
| HIGH | postinstall system command System command execution detected | 3 | license.txtConfig/pork2Sausage.inidemo/zip.base64/zipB64.java | Risky Plugins Authors FP 10% |
| HIGH | postinstall obfuscation Code obfuscation techniques detected | 5 | Config/pork2Sausage.inireadme.txtdemo/zip.base64/commons-codec-1.4.jar +2 more | Risky Plugins Authors FP 20% |
Finding Categories
YARA Rules Matched
2 rules(8 hits)AI Security Report
AI Security Review
Evidence context: threat category none; evidence quality moderate.
The extension 'Pork to Sausage' is a Notepad++ plugin by Don HO that passes selected text to command line programs and replaces it with the output. This filesystem/process access is fully justified by the extension's stated purpose.
Filesystem/Process Access Justification: The extension's description explicitly states it passes text to command line programs. Process spawning for executing external commands is the core functionality, not suspicious behavior. No findings indicate unauthorized file access beyond the selected text scope.
Credential-Access Findings: The evidence contains zero credential-access findings. The findings_summary shows "secret":"0" in the threat_indicators. The IOC findings include developer email addresses ([email protected] in [email protected], [email protected] in [email protected]) which are legitimate contact information, not credential theft.
IOC Findings Are False Positives: All 13 IOC findings are known false-positive patterns:
- IPv6 fragments:
::(XIOC-IP-::),e::badb(XIOC-IP-e::badb),e::fa(XIOC-IP-e::fa),e::e(XIOC-IP-e::e) are hex substrings from minified JavaScript, not real IP addresses - Java class references misread as domains:
java.io(XIOC-DOMAIN-java.io),java.util.zip(XIOC-DOMAIN-java.util.zip),zipb64.java(XIOC-DOMAIN-zipb64.java),inflater.read(XIOC-DOMAIN-inflater.read) are Java class/method names, not network domains - Email domains:
free.fr(XIOC-DOMAIN-free.fr),altern.org(XIOC-DOMAIN-altern.org) are from developer contact emails
Code-Smell Findings: The 8 code-smell findings are classified as noise per CVEQ guidelines. These fire on basic Node.js patterns and do not indicate malicious behavior.
Strongest Counterargument: The 0 user count could suggest a suspicious new extension. However, this alone does not indicate malicious intent. The developer Don HO is a known Notepad++ contributor, and all technical findings are explainable false positives. No malware signatures, network calls, obfuscation, or credential access were detected.
Key Reasons
- All IOC findings are known false-positive patterns
- No malware signatures detected
- No network or credential findings
- Process spawning justified by extension purpose
- Developer email addresses are legitimate contact info
False Positive Considerations
- IPv6 hex fragments misclassified as IPs
- Java class names misclassified as domains
- Developer email addresses extracted as IOCs
- Code-smell rules on benign patterns
Reviewed 2026-04-27; recommended action: suppress false positive; model confidence 85%.
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace