VS Code Marketplace Verified

Go Nightly

by Go Team at Google · 581.6K users · 5.0 rating
c14a38a3-42cf-5043-90bc-3b8436865ef8 | v2024.8.2217
50/ 100
MEDIUM risk
Analyst verdict
Review before use

The AI review rates the findings as likely false positive, but the risk score (50/100) still counts them.

Analysis record

Analysed
8 months ago
Version
v2024.8.2217
Artifact
SHA256 280…5D1
Source
Findings (non-IoC)

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

65 detail rows

YARA Rule Matches

12 rules
SeverityRuleHitsFilesMetadata
HIGHNoUseWeakRandom

When software generates predictable values in a context requiring unpredictability, it may be possible for an attacker to guess the next value that will be generated, and use this guess to impersonate another user or access sensitive information. As the Math.random() function relies on a weak pseudorandom number generator, this function should not be used for security-critical applications or for protecting sensitive data. In such context, a cryptographically strong pseudorandom number generator (CSPRNG) should be used instead. For more information checkout the CWE-338 (https://cwe.mitre.org/data/definitions/338.html) advisory.

2
dist/goMain.jsdist/debugAdapter.js
FP 5%
HIGHUsingShellInterpreterWhenExecutingOSCommands

Arbitrary OS command injection vulnerabilities are more likely when a shell is spawned rather than a new process, indeed shell meta-chars can be used (when parameters are user-controlled for instance) to inject OS commands. For more information checkout the CWE-78 (https://cwe.mitre.org/data/definitions/78.html) advisory.

2
dist/debugAdapter.jsdist/goMain.js
FP 10%
HIGHpostinstall system command

System command execution detected

7
media/codicon.ttfREADME.mddist/goMain.js +4 more
Risky Plugins Authors FP 10%
HIGHpostinstall network communication

Network communication detected

8
CHANGELOG.mdLICENSE.txtmedia/codicon.ttf +5 more
Risky Plugins Authors FP 30%
HIGHpostinstall file manipulation

File system manipulation detected

6
CHANGELOG.mdmedia/codicon.ttfmedia/codicon.css +3 more
Risky Plugins Authors FP 20%
HIGHpostinstall file download

File download activity detected

7
CHANGELOG.mdmedia/codicon.ttfmedia/codicon.css +4 more
Risky Plugins Authors FP 30%
HIGHpostinstall obfuscation

Code obfuscation techniques detected

4
CHANGELOG.mdpackage.jsondist/goMain.js +1 more
Risky Plugins Authors FP 20%
HIGHcredential env files

Environment configuration file path detected

4
CHANGELOG.mdpackage.jsondist/goMain.js +1 more
Risky Plugins Authors FP 10%
HIGHUsingCommandLineArguments

Command line arguments can be dangerous just like any other user input. They should never be used without being first validated and sanitized. Remember also that any user can retrieve the list of processes running on a system, which makes the arguments provided to them visible. Thus passing sensitive information via command line arguments should be considered as insecure. This rule raises an issue when on every program entry points (main methods) when command line arguments are used. The goal is to guide security code reviews. Sanitize all command line arguments before using them. For more information checkout the CWE-88 (https://cwe.mitre.org/data/definitions/88.html) advisory.

2
dist/goMain.jsdist/debugAdapter.js
FP 20%
HIGHNoUseSocketManually

Sockets are vulnerable in multiple ways: They enable a software to interact with the outside world. As this world is full of attackers it is necessary to check that they cannot receive sensitive information or inject dangerous input.The number of sockets is limited and can be exhausted. Which makes the application unresponsive to users who need additional sockets. In many cases there is no need to open a socket yourself. Use instead libraries and existing protocols For more information checkout the CWE-20 (https://cwe.mitre.org/data/definitions/20.html) advisory.

1
dist/debugAdapter.js
FP 20%
HIGHpostinstall crypto operations

Cryptographic operations detected

4
CHANGELOG.mdsyntaxes/go.sum.tmGrammar.jsondist/goMain.js +1 more
Risky Plugins Authors FP 30%
HIGHDebuggerStatementsShouldNotBeUsed

The debugger statement can be placed anywhere in procedures to suspend execution. Using the debugger statement is similar to setting a breakpoint in the code. By definition such statement must absolutely be removed from the source code to prevent any unexpected behavior or added vulnerability to attacks in production. For more information checkout the CWE-489 (https://cwe.mitre.org/data/definitions/489.html) advisory.

5
CHANGELOG.mdextension.vsixmanifestpackage.json +2 more
FP 10%

Publisher Evidence

Low

Go Team at Google

Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.

78
Noisy-finding weight
x1.00
Publisher domain
go.dev
Observed
Store verification signal
Verified publisher
Verified
Extension portfolio
2
Portfolio

12 evidence rows available.

Finding Categories

52
Malware Signatures
1
Network

YARA Rules Matched

12 rules(52 hits)
NoUseWeakRandom UsingShellInterpreterWhenExecutingOSCommands postinstall system command postinstall network communication postinstall file manipulation postinstall file download postinstall obfuscation credential env files UsingCommandLineArguments NoUseSocketManually postinstall crypto operations DebuggerStatementsShouldNotBeUsed

AI Security Report

AI Security Review

Evidence context: threat category none; evidence quality strong.

The Go Nightly extension from developer "golang" is the official Go language support for Visual Studio Code with 579,348 users. This extension's filesystem and process access patterns are entirely justified by its stated purpose as a language server and debugger.

The 12 dependency findings in /tmp/extract-280fd257876623e4b1fc08400067f8077b19e1870333c596b2246551324245d1-3980004134/extension/package.json are standard VS Code SDK packages: [email protected], [email protected], [email protected], and [email protected]. These are the official packages that Microsoft provides for building language server extensions. Additional utilities like tree-kill, [email protected], and [email protected] are common Node.js libraries for process management and HTTP requests—expected for an extension that manages language server processes.

The single network finding NET-WEBSOCKET-extension/dist/debugAdapter.js:13571 represents WebSocket communication in the debug adapter. This is standard behavior for VS Code debug extensions, which communicate with the IDE's debug engine via WebSocket protocol. The debug adapter is essential for providing debugging capabilities to Go developers.

The 52 code-smell findings flagged by YARA rules are noise from minified JavaScript in bundled dependencies. These rules match common patterns in any non-trivial JavaScript codebase and do not indicate malicious behavior. Critically, there are zero malware signatures, zero suspicious IoCs, zero obfuscation findings, and zero credential theft indicators.

No credential-access findings target actual secrets like .env files, SSH keys, or cloud credentials. The extension does not request permissions beyond what a language server requires.

The strongest counterargument is the high count of 52 code-smell findings, which might suggest suspicious behavior to a reader unfamiliar with IDE extension analysis. However, code-smell findings are well-documented false positives that match basic Node.js patterns like fetch, exec, fs, and crypto usage. These are necessary for any language server that needs to spawn processes, read files, and communicate with language servers. The findings_summary explicitly shows "malware-signature":"0" and "ioc":"0", confirming no actual threats were detected.

This extension is published by the official Go team, has nearly 600,000 users, and exhibits exactly the behavior expected of a legitimate language server extension.

Key Reasons

  • Official publisher 'golang' with 579,348 users indicates verified extension
  • Zero malware signatures, zero IoCs, zero obfuscation findings
  • All dependencies are standard VS Code SDK packages
  • WebSocket usage is expected debug adapter behavior
  • Code-smell findings are YARA noise from minified JavaScript

False Positive Considerations

  • YARA code-smell rules matching minified JavaScript patterns
  • Dependency scanning of standard VS Code SDK packages
  • WebSocket detection for legitimate debug adapter communication
  • High finding count from bundled dependencies in dist/

Reviewed 2026-05-23; recommended action: suppress false positive; model confidence 95%.

About This Extension

Rich Go language support for Visual Studio Code (Nightly)

Frequently Asked Questions