JetBrains Marketplace Verified

Red Hat OpenShift Dev Spaces

by Red-Hat · 1.1K users
c28019c5-bce3-5bf1-9bbf-df8cbc9506fc | v0.0.5
36/ 100
LOW risk
No change since v0.0.4
Analyst verdict
No high-risk signal observed

Based on the RiskyPlugins AI security review of the observed evidence.

No individual score drivers were recorded for this analysis.

Analysis record

Analysed
Today
Version
v0.0.5
Artifact
SHA256 FC8…06A
Source
Findings (non-IoC)

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

190 detail rows
Showing 25 of 72 · highest severity first

YARA Rule Matches

10 rules
SeverityRuleHitsFilesMetadata
LOWpostinstall crypto operations 13
jackson-databind-2.20.0.jarvertx-core-4.5.24.jaropenshift-model-hive-7.6.1.jar +10 more
-
LOWpostinstall network communication 37
kubernetes-model-admissionregistration-7.6.1.jarjackson-databind-2.20.0.jarkubernetes-model-gatewayapi-7.6.1.jar +34 more
-
LOWpostinstall file manipulation 8
netty-codec-http-4.1.130.Final.jarkubernetes-client-7.6.1.jaropenshift-client-api-7.6.1.jar +5 more
-
LOWpostinstall system command 19
kubernetes-model-rbac-7.6.1.jarnetty-common-4.1.130.Final.jarkubernetes-model-batch-7.6.1.jar +16 more
-
LOWJavaDropper 9
openshift-model-7.6.1.jaropenshift-model-operatorhub-7.6.1.jarkubernetes-model-admissionregistration-7.6.1.jar +6 more
-
LOWpostinstall registry modification 8
openshift-model-machineconfiguration-7.6.1.jaropenshift-model-7.6.1.jaropenshift-model-operator-7.6.1.jar +5 more
-
LOWpostinstall obfuscation 16
jackson-databind-2.20.0.jarkubernetes-model-networking-7.6.1.jarjackson-core-2.20.0.jar +13 more
-
LOWpostinstall file download 3
jackson-databind-2.20.0.jarkubernetes-httpclient-vertx-7.6.1.jaropenshift-model-console-7.6.1.jar
-
LOWPM Zip with js 1
plugin-0.0.5.jar
-
LOWpostinstall persistence mechanism 4
kubernetes-model-core-7.6.1.jaropenshift-model-machine-7.6.1.jarkubernetes-model-batch-7.6.1.jar +1 more
-

Publisher Evidence

Low

Red-Hat

Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.

86
Noisy-finding weight
x1.00
Publisher domain
redhat.com
Observed
Store verification signal
Verified publisher
Verified
Extension portfolio
64
Portfolio

11 evidence rows available.

Finding Categories

YARA Rules Matched

10 rules(118 hits)
postinstall crypto operations postinstall network communication postinstall file manipulation postinstall system command JavaDropper postinstall registry modification postinstall obfuscation postinstall file download PM Zip with js postinstall persistence mechanism

AI Security Report

AI Security Review

Evidence context: threat category none; evidence quality strong.

This Red Hat OpenShift Dev Spaces extension for JetBrains shows a concerning finding count at first glance—484 IoC detections—but the nature of these findings reveals they are artifacts from automated extraction tools rather than actual malicious behavior.

The extension's filesystem and process access is fully justified by its stated purpose. OpenShift Dev Spaces is a legitimate development tool that enables developers to create cloud-hosted development environments for OpenShift clusters. Such tools legitimately need to read workspace files, spawn build processes, and communicate with OpenShift APIs. The evidence shows zero findings in categories that would indicate unauthorized access: no secret detection findings, no code-smell findings related to credential theft, and no obfuscation findings. This aligns with expected behavior for a development environment tool.

All 484 IoC findings share the same pattern: they are XIOC-DOMAIN detections with file paths showing "extracted_from_files" rather than actual network call logs. The detected "domains" include patterns like 1.bt, sz.im, p.ke, l.sl, lm.sc, and 8.fi—these are clearly false positives where the XIOC extractor misread character sequences from minified JavaScript or configuration files as domain names. Legitimate domains do not consist of single characters followed by two-letter country TLDs. The presence of ܤ.mc (containing a non-ASCII Syriac character) further confirms these are text extraction artifacts, not actual network destinations.

Credential access findings are absent entirely. The findings summary shows zero detections in the secret category, meaning no code was identified reading .env files, .git/config, SSH keys, or cloud credentials. For an extension that legitimately needs to authenticate with OpenShift clusters, this is the expected behavior—credentials are handled through proper authentication flows, not file scraping.

The strongest counterargument is the sheer volume of 484 IoC findings, which could suggest sophisticated evasion or embedded malicious infrastructure. However, this argument fails because: (1) all findings come from the XIOC extractor, a known source of false positives that misreads minified JavaScript as domain strings; (2) zero malware signatures matched any of the code; (3) zero obfuscation findings indicate no intentional code hiding; (4) Red Hat is a verified publisher with established security practices; and (5) the domain patterns detected (single character + TLD) are not valid or functional domains.

The extension is from Red Hat, a major enterprise software company with significant reputation at stake. The findings pattern matches known false-positive behavior from the IoC extractor rather than actual malicious infrastructure.

Key Reasons

  • Zero malware signatures or malware detections
  • All IoC findings from known false-positive-prone XIOC extractor
  • Red Hat is verified legitimate publisher
  • No credential access or secret detection findings
  • No obfuscation or code-smell findings

False Positive Considerations

  • XIOC domain extraction from minified files
  • Short TLD patterns misread as domains
  • Character sequences from JS misidentified as URLs
  • Bundled dependency false positives

Reviewed 2026-05-30; recommended action: suppress false positive; model confidence 85%.

JetBrains version history

Risk trend by version

2 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.

Selected
36
Change since first
No change
Change from previous
No change
Versions:
First analyzed version
0.0.4
May 29, 2026
Risk range
36 to 36
Across analyzed versions
Latest analyzed version
0.0.5
Aug 27, 2026
Selected version
low
Version
v0.0.5
1 months ago
Risk score
36
Findings
190
Change vs previous
No change

Pick any point on the chart to explore that version's code below.

About This Extension

Red Hat OpenShift Dev Spaces Plugin for JetBrains Toolbox.

Frequently Asked Questions