Draw.io Integration
The AI review rates the findings as likely false positive, but the risk score (82/100) still counts them.
Analysis record
- Analysed
- 5 days ago
- Version
- v1.11.260924036
- Artifact
- SHA256 4EA…EDC
- Source
- Findings (non-IoC)
Evidence ledger
Ranked by severity · findings with a source location link to the code viewer
YARA Rule Matches
1 rule| Severity | Rule | Hits | Files | Metadata |
|---|---|---|---|---|
| HIGH | supply chain sourcemap appended iife | 4 | drawio/src/main/webapp/js/app.min.jsdrawio/src/main/webapp/js/viewer-static.min.jsdrawio/src/main/webapp/js/integrate.min.js +1 more | - |
Publisher Evidence
LowHenning Dieterichs
Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.
11 evidence rows available.
Finding Categories
YARA Rules Matched
1 rule(4 hits)AI Security Report
AI Security Review
Evidence context: threat category none; evidence quality strong.
The Draw.io Integration extension by hediet is a legitimate VS Code extension with over 3.8 million users that embeds the Draw.io diagramming tool into the development environment. Analysis reveals 1,359 total findings, but 1,355 of these are code-smell detections from YARA rules matching basic JavaScript patterns, not actual malicious behavior.
The eight malware-signature findings appear in minified and asset files rather than executable code. The YARA--postinstall_registry_modification and YARA--postinstall_crypto_operations detections occur in /extension/drawio/src/main/webapp/js/stencils.min.js, a minified JavaScript file that bundles legitimate stencil library code. Multiple YARA--postinstall_network_communication matches in SVG image files like /extension/drawio/src/main/webapp/img/lib/azure2/storage/Storage_Accounts_Classic.svg are false positives—SVG files contain XML markup that can trigger network-related YARA patterns but cannot execute code. The YARA--postinstall_file_manipulation finding in /extension/drawio/src/main/webapp/math/es5/input/mml/entities.js matches mathematical entity definitions, not file manipulation logic.
Four network findings are expected for this extension's functionality. The NET-XMLHTTPREQUEST detections in embed.dev.js and mxODPicker.js files support embedding and OneDrive integration features. The NET-WEBSOCKET call in app.min.js enables real-time collaboration, which is core to Draw.io's purpose.
No credential-access findings target sensitive files like .env, .ssh, or cloud credentials. Zero secret detections were recorded, confirming no credential theft indicators exist in the codebase.
The strongest counterargument is the 1,355 high-severity code-smell findings. However, these are known false positives from YARA rules designed to catch basic JavaScript patterns—fetch, exec, fs, crypto operations—that are normal for any non-trivial extension. The postinstall_* YARA rules match legitimate Node.js patterns, not malicious post-install payloads. This extension's network calls and file access are justified by its stated purpose of integrating a diagramming tool into VS Code.
Given the extension's popularity, verified developer status, and the nature of all findings being in minified/bundled code or known false-positive patterns, this is a clear false positive that should be suppressed.
Key Reasons
- 1,355 of 1,359 findings are code-smell YARA noise
- Malware-signature findings are in minified/bundled files and SVG images
- No credential-access or secret findings detected
- 3.8M+ users and verified developer indicate legitimacy
- Network calls justified by OneDrive and collaboration features
False Positive Considerations
- Code-smell YARA rules matching basic JavaScript patterns
- Minified/bundled JavaScript triggering false positives
- SVG image files incorrectly flagged by YARA rules
- Postinstall_* rules matching legitimate Node.js patterns
Reviewed 2026-05-23; recommended action: suppress false positive; model confidence 90%.
VS Code version history
Risk trend by version
7 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.
Pick any point on the chart to explore that version's code below.
Source Code Not Available
Source code is not available for this version of the extension.
About This Extension
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace
Real-Time Debugging
Henning Dieterichs
Debug Visualizer
Henning Dieterichs
Tasks Statusbar
Henning Dieterichs
Draw.io Integration - Insiders Build
Henning Dieterichs
DeLorean JS Debug
Henning Dieterichs
Browser Dev Tools
Henning Dieterichs