From the RiskyPlugins AI security review of the observed evidence.
Analysis record
- Analysed
- 4 days ago
- Version
- v1.0.0
- Artifact
- SHA256 394…96D
- Source
- Findings (non-IoC)
Is NppMarkdownNext safe?
NppMarkdownNext is a native Notepad++ Markdown reader with WebView2 rendering, live preview, and math and diagram support. It declares no special permissions, while the listed endpoint img.shields.io can serve badge or image content. The native files NppMarkdownNext.dll:0 and WebView2Loader.dll:0 give the plugin the power that comes with code loaded inside Notepad++, even though the listing does not name a separate host permission.
The main concern is the finding titled OBFUSCATION-supply_chain_binary on both NppMarkdownNext.dll:0 and WebView2Loader.dll:0. If that detection reflects hidden native logic, the plugin could do more than render Markdown. The supplied findings do not name .env, .ssh, cloud credentials, shell commands, or document uploads.
A normal WebView2 loader and a C++ preview plugin explain why native binaries are present, and strings such as input.select and mark.search look like interface names rather than remote addresses. The duplicate critical binary finding still needs runtime checks because static results do not show what these DLLs do after Notepad++ loads them.
Evidence ledger
Ranked by severity · findings with a source location link to the code viewer
YARA Rule Matches
6 rules| Severity | Rule | Hits | Files | Metadata |
|---|---|---|---|---|
| LOW | postinstall file manipulation | 2 | WebView2Loader.dllNppMarkdownNext.dll | - |
| LOW | postinstall obfuscation | 2 | WebView2Loader.dllNppMarkdownNext.dll | - |
| LOW | postinstall network communication | 3 | WebView2Loader.dllLicense.txtNppMarkdownNext.dll | - |
| LOW | postinstall system command | 2 | WebView2Loader.dllNppMarkdownNext.dll | - |
| LOW | postinstall file download | 1 | NppMarkdownNext.dll | - |
| LOW | postinstall persistence mechanism | 1 | WebView2Loader.dll | - |
Network Indicators
Concrete URLs, domains, IPs, emails, and hashes extracted from the analyzed artifact.
Network indicators are queued for lazy loading
Scroll this section into view to load the detailed rows.
Finding Categories
YARA Rules Matched
6 rules(11 hits)AI Security Report
AI Security Review
Evidence context: threat category supply chain; evidence quality moderate.
NppMarkdownNext is described as a Notepad++ Markdown preview and reader, so native code in NppMarkdownNext.dll:0 is consistent with rendering Markdown, handling caret sync, and connecting to WebView2. A native Notepad++ plugin still runs with the host process's machine-level capabilities. The finding titled OBFUSCATION-supply_chain_binary in NppMarkdownNext.dll:0 therefore deserves more weight than a JavaScript minification alert. The same finding title in WebView2Loader.dll:0 is compatible with a bundled WebView2 loader, although the scan cannot establish from that title whether either DLL contains harmful logic. No finding supplied here proves file reads, process creation, or command execution, so the filesystem and process access cannot be confirmed as either excessive or fully justified from the available evidence.
The stated Markdown preview purpose supports workspace access for opening and rendering the document being viewed. That purpose does not by itself justify silent access to unrelated files or child-process execution. The two native paths, NppMarkdownNext.dll:0 and WebView2Loader.dll:0, are the only files tied to the critical detection, and neither path is accompanied by a finding naming workspace collection, shell execution, or persistence. The listed endpoint img.shields.io is a badge and image-hosting domain. Strings such as input.select, mark.search, nodefilter.show, and toast-notification.show are interface-style names, so they do not establish that the plugin sends document content to a remote service.
Credential access is not supported by the supplied findings. Neither NppMarkdownNext.dll:0 nor WebView2Loader.dll:0 is linked to a .env file, .ssh directory, cloud credential store, IDE secret storage, or a credential-provider API. The absence of a named secret path limits the case for credential theft. It does not clear the native binaries, because a DLL can contain behavior that static pattern results do not describe.
The strongest benign counterargument is that WebView2Loader.dll:0 is a normal native component for a Chromium-based preview, while NppMarkdownNext.dll:0 is the expected implementation for a C++ Notepad++ plugin. That explanation fits the extension's stated rendering features and the lack of a named malware signature on either path. It does not resolve the duplicate critical OBFUSCATION-supply_chain_binary detections, and the publisher theneet0 has no recorded users in the supplied listing. Runtime inspection should check DLL imports, child-process creation, file access outside the active document, and outbound requests before the extension is treated as safe.
Key Reasons
OBFUSCATION-supply_chain_binaryis marked critical for bothNppMarkdownNext.dll:0andWebView2Loader.dll:0.- No supplied finding links either
NppMarkdownNext.dll:0orWebView2Loader.dll:0to.env,.ssh, cloud credentials, or secret storage. - The endpoint
img.shields.iois generic, whileinput.selectandmark.searchare interface-style strings rather than clear exfiltration destinations. - The native DLLs fit the stated Notepad++ Markdown preview purpose, so the current record does not prove malicious behavior.
False Positive Considerations
OBFUSCATION-supply_chain_binarycan flag legitimate native release binaries such asWebView2Loader.dll:0.input.select,mark.search,nodefilter.show, andtoast-notification.showresemble property or UI names, not suspicious domains.- The C++ Markdown preview purpose is consistent with native code in
NppMarkdownNext.dll:0. img.shields.iois a common badge or image endpoint and does not by itself show document exfiltration.
Reviewed 2026-09-29; recommended action: runtime analysis; model confidence 78%.
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace