Go Nightly
The AI review rates the findings as likely false positive, but the risk score (50/100) still counts them.
Analysis record
- Analysed
- 8 months ago
- Version
- v2024.8.2217
- Artifact
- SHA256 280…5D1
- Source
- Findings (non-IoC)
Evidence ledger
Ranked by severity · findings with a source location link to the code viewer
YARA Rule Matches
12 rules| Severity | Rule | Hits | Files | Metadata |
|---|---|---|---|---|
| HIGH | NoUseWeakRandom When software generates predictable values in a context requiring unpredictability, it may be possible for an attacker to guess the next value that will be generated, and use this guess to impersonate another user or access sensitive information. As the Math.random() function relies on a weak pseudorandom number generator, this function should not be used for security-critical applications or for protecting sensitive data. In such context, a cryptographically strong pseudorandom number generator (CSPRNG) should be used instead. For more information checkout the CWE-338 (https://cwe.mitre.org/data/definitions/338.html) advisory. | 2 | dist/goMain.jsdist/debugAdapter.js | FP 5% |
| HIGH | UsingShellInterpreterWhenExecutingOSCommands Arbitrary OS command injection vulnerabilities are more likely when a shell is spawned rather than a new process, indeed shell meta-chars can be used (when parameters are user-controlled for instance) to inject OS commands. For more information checkout the CWE-78 (https://cwe.mitre.org/data/definitions/78.html) advisory. | 2 | dist/debugAdapter.jsdist/goMain.js | FP 10% |
| HIGH | postinstall system command System command execution detected | 7 | media/codicon.ttfREADME.mddist/goMain.js +4 more | Risky Plugins Authors FP 10% |
| HIGH | postinstall network communication Network communication detected | 8 | CHANGELOG.mdLICENSE.txtmedia/codicon.ttf +5 more | Risky Plugins Authors FP 30% |
| HIGH | postinstall file manipulation File system manipulation detected | 6 | CHANGELOG.mdmedia/codicon.ttfmedia/codicon.css +3 more | Risky Plugins Authors FP 20% |
| HIGH | postinstall file download File download activity detected | 7 | CHANGELOG.mdmedia/codicon.ttfmedia/codicon.css +4 more | Risky Plugins Authors FP 30% |
| HIGH | postinstall obfuscation Code obfuscation techniques detected | 4 | CHANGELOG.mdpackage.jsondist/goMain.js +1 more | Risky Plugins Authors FP 20% |
| HIGH | credential env files Environment configuration file path detected | 4 | CHANGELOG.mdpackage.jsondist/goMain.js +1 more | Risky Plugins Authors FP 10% |
| HIGH | UsingCommandLineArguments Command line arguments can be dangerous just like any other user input. They should never be used without being first validated and sanitized. Remember also that any user can retrieve the list of processes running on a system, which makes the arguments provided to them visible. Thus passing sensitive information via command line arguments should be considered as insecure. This rule raises an issue when on every program entry points (main methods) when command line arguments are used. The goal is to guide security code reviews. Sanitize all command line arguments before using them. For more information checkout the CWE-88 (https://cwe.mitre.org/data/definitions/88.html) advisory. | 2 | dist/goMain.jsdist/debugAdapter.js | FP 20% |
| HIGH | NoUseSocketManually Sockets are vulnerable in multiple ways: They enable a software to interact with the outside world. As this world is full of attackers it is necessary to check that they cannot receive sensitive information or inject dangerous input.The number of sockets is limited and can be exhausted. Which makes the application unresponsive to users who need additional sockets. In many cases there is no need to open a socket yourself. Use instead libraries and existing protocols For more information checkout the CWE-20 (https://cwe.mitre.org/data/definitions/20.html) advisory. | 1 | dist/debugAdapter.js | FP 20% |
| HIGH | postinstall crypto operations Cryptographic operations detected | 4 | CHANGELOG.mdsyntaxes/go.sum.tmGrammar.jsondist/goMain.js +1 more | Risky Plugins Authors FP 30% |
| HIGH | DebuggerStatementsShouldNotBeUsed The debugger statement can be placed anywhere in procedures to suspend execution. Using the debugger statement is similar to setting a breakpoint in the code. By definition such statement must absolutely be removed from the source code to prevent any unexpected behavior or added vulnerability to attacks in production. For more information checkout the CWE-489 (https://cwe.mitre.org/data/definitions/489.html) advisory. | 5 | CHANGELOG.mdextension.vsixmanifestpackage.json +2 more | FP 10% |
Publisher Evidence
LowGo Team at Google
Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.
12 evidence rows available.
Finding Categories
YARA Rules Matched
12 rules(52 hits)AI Security Report
AI Security Review
Evidence context: threat category none; evidence quality strong.
The Go Nightly extension from developer "golang" is the official Go language support for Visual Studio Code with 579,348 users. This extension's filesystem and process access patterns are entirely justified by its stated purpose as a language server and debugger.
The 12 dependency findings in /tmp/extract-280fd257876623e4b1fc08400067f8077b19e1870333c596b2246551324245d1-3980004134/extension/package.json are standard VS Code SDK packages: [email protected], [email protected], [email protected], and [email protected]. These are the official packages that Microsoft provides for building language server extensions. Additional utilities like tree-kill, [email protected], and [email protected] are common Node.js libraries for process management and HTTP requests—expected for an extension that manages language server processes.
The single network finding NET-WEBSOCKET-extension/dist/debugAdapter.js:13571 represents WebSocket communication in the debug adapter. This is standard behavior for VS Code debug extensions, which communicate with the IDE's debug engine via WebSocket protocol. The debug adapter is essential for providing debugging capabilities to Go developers.
The 52 code-smell findings flagged by YARA rules are noise from minified JavaScript in bundled dependencies. These rules match common patterns in any non-trivial JavaScript codebase and do not indicate malicious behavior. Critically, there are zero malware signatures, zero suspicious IoCs, zero obfuscation findings, and zero credential theft indicators.
No credential-access findings target actual secrets like .env files, SSH keys, or cloud credentials. The extension does not request permissions beyond what a language server requires.
The strongest counterargument is the high count of 52 code-smell findings, which might suggest suspicious behavior to a reader unfamiliar with IDE extension analysis. However, code-smell findings are well-documented false positives that match basic Node.js patterns like fetch, exec, fs, and crypto usage. These are necessary for any language server that needs to spawn processes, read files, and communicate with language servers. The findings_summary explicitly shows "malware-signature":"0" and "ioc":"0", confirming no actual threats were detected.
This extension is published by the official Go team, has nearly 600,000 users, and exhibits exactly the behavior expected of a legitimate language server extension.
Key Reasons
- Official publisher 'golang' with 579,348 users indicates verified extension
- Zero malware signatures, zero IoCs, zero obfuscation findings
- All dependencies are standard VS Code SDK packages
- WebSocket usage is expected debug adapter behavior
- Code-smell findings are YARA noise from minified JavaScript
False Positive Considerations
- YARA code-smell rules matching minified JavaScript patterns
- Dependency scanning of standard VS Code SDK packages
- WebSocket detection for legitimate debug adapter communication
- High finding count from bundled dependencies in dist/
Reviewed 2026-05-23; recommended action: suppress false positive; model confidence 95%.
Source Code Not Available
Source code is not available for this version of the extension.
About This Extension
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace