EmmyLua
The AI review rates the findings as likely false positive, but the risk score (69/100) still counts them.
Analysis record
- Analysed
- 5 days ago
- Version
- v1.4.26-IDEA2026.2
- Artifact
- SHA256 CB4…B8F
- Source
- Findings (non-IoC)
Evidence ledger
Ranked by severity · findings with a source location link to the code viewer
YARA Rule Matches
1 rule| Severity | Rule | Hits | Files | Metadata |
|---|---|---|---|---|
| HIGH | CAP HookExKeylogger | 1 | IntelliJ-EmmyLua/lib/jna-platform-5.5.0.jar | Brian C. Bell -- @biebsmalwareguy FP 5% |
Publisher Evidence
Limited evidencefb7d5b35-ab79-47f8-b9b7-36162be34ea6
Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.
13 evidence rows available.
Finding Categories
YARA Rules Matched
1 ruleAI Security Report
AI Security Review
Risky Plugins reviewed this extension with an AI-assisted security workflow on 2026-09-06. The review verdict is likely false positive with 78% confidence.
Recommended action: suppress false positive. Evidence context: threat category none; evidence quality moderate.
EmmyLua provides Lua development support for JetBrains IDEs, version 1.4.26-IDEA2026.2, with approximately 998,644 users. The scan data contains 75 findings.
74 of them record info-level metadata hashes. The remaining one flags a high-severity malware-signature match. No other finding types show up. These metadata hashes do not raise concern. The metadata hashes list file hashes for standard plugin components. They include IntelliJ-EmmyLua/lib/luaj-jse-3.0.1.jar, a bundled LuaJ interpreter. They also include IntelliJ-EmmyLua/debugger/emmy/windows/x64/emmy_core.dll, a native debugger library, and Lua standard library stubs such as IntelliJ-EmmyLua/std/Lua52/io.lua and IntelliJ-EmmyLua/std/Lua53/table.lua. These files belong to a Lua language tool. The interpreter and debugger require process execution and filesystem access. They use that access to run and inspect Lua code, which matches the plugin's stated purpose. That access keeps the plugin functional. The standard library stubs ship with any Lua plugin. The file paths point to normal plugin internals.
The scan data shows no secret findings, credential-related code-smell findings, or network indicators. It records no attempt to read .env files, SSH keys, cloud credentials, or other sensitive workspace data. That absence matters a great deal.
A malicious IDE plugin would typically combine filesystem access with credential theft or exfiltration. A plugin that only runs and inspects Lua code has no reason to touch those files. The single high-severity malware-signature match stands as the only non-info finding. It comes with no IoC, network, obfuscation, or tool-poisoning indicators. This pattern matches a broad YARA rule hitting a bundled native binary or third-party JAR. The native debugger DLL and the LuaJ interpreter JAR both offer plausible triggers for generic malware family signatures. This holds especially when the rule lacks tailoring to IDE plugin components. The rule runs broad in practice. A generic signature can flag legitimate binaries that share byte sequences with known malware families. Signature-based detection carries this known limitation. The strongest counterargument reads the high-severity signature as a malicious payload inside the debugger DLL or interpreter JAR. That reading loses to the complete lack of corroborating behavioral evidence. No network calls, no obfuscation, no secret access, and no suspicious file operations appear. A malicious plugin would almost certainly exhibit at least one of those additional signals. The absence of any secondary signal decides the point.
Without at least one of those signals, the signature alone does not establish malicious behavior. A supply-chain attack would need more than one signature. The plugin's large user base and established identity as a Lua development tool further support a false positive. This points away from a supply-chain attack.
Key Reasons
- Only one high-severity malware-signature match, with no IoC, network, obfuscation, or secret findings to corroborate malicious behavior.
- All other 74 findings are info-level metadata hashes for standard Lua plugin components like luaj-jse-3.0.1.jar and emmy_core.dll.
- The plugin's purpose as a Lua language tool justifies process execution and filesystem access for running and debugging Lua code.
- No credential-access findings target real secrets such as .env, SSH keys, or cloud credentials.
- Widely used plugin (998,644 users) with an established developer identity, reducing likelihood of a targeted supply-chain attack.
False Positive Considerations
- Bundled LuaJ interpreter JAR (luaj-jse-3.0.1.jar) triggers a broad malware-signature YARA rule.
- Native debugger DLL (emmy_core.dll) matches a generic malware family pattern common to native binaries.
- No supporting IoC, network, obfuscation, or secret findings to indicate actual malicious activity.
- High user count and established plugin identity suggest the signature is a false positive rather than a real threat.
JetBrains version history
Risk trend by version
2 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.
Pick any point on the chart to explore that version's code below.
About This Extension
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace