OpenVSX Registry Verified

Python Debugger (PyDev)

by fabioz
db0a92c5-53c2-5d3c-9562-f5ad8915438e | v0.3.0
46/ 100
MEDIUM risk
Analyst verdict
Review before use

The AI review rates the findings as likely false positive, but the risk score (46/100) still counts them.

Analysis record

Analysed
8 months ago
Version
v0.3.0
Source
Findings (non-IoC)

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

1000 detail rows
Showing 25 of 220 · highest severity first

YARA Rule Matches

16 rules
SeverityRuleHitsFilesMetadata
HIGHDebuggerStatementsShouldNotBeUsed

The debugger statement can be placed anywhere in procedures to suspend execution. Using the debugger statement is similar to setting a breakpoint in the code. By definition such statement must absolutely be removed from the source code to prevent any unexpected behavior or added vulnerability to attacks in production. For more information checkout the CWE-489 (https://cwe.mitre.org/data/definitions/489.html) advisory.

103
PyDev.Debugger/_pydevd_bundle/_debug_adapter/pydevd_schema.pysrc_adapter/pydevd_dap_adapter/debug_adapter_comm.pysrc_adapter/pydevd_dap_adapter/_process_attach.py +100 more
FP 10%
HIGHpostinstall process injection

Process injection techniques detected

4
PyDev.Debugger/pydevd_attach_to_process/winappdbg/process.pyPyDev.Debugger/pydevd_attach_to_process/winappdbg/thread.pyPyDev.Debugger/pydevd_attach_to_process/winappdbg/win32/kernel32.py +1 more
Risky Plugins Authors FP 10%
HIGHpostinstall crypto operations

Cryptographic operations detected

22
PyDev.Debugger/pydevd_attach_to_process/windows/attach.cppPyDev.Debugger/_pydev_bundle/_pydev_jy_imports_tipper.pyPyDev.Debugger/_pydevd_bundle/pydevd_cython.c +19 more
Risky Plugins Authors FP 30%
HIGHpostinstall file manipulation

File system manipulation detected

125
PyDev.Debugger/_pydev_runfiles/pydev_runfiles.pyPyDev.Debugger/third_party/pep8/autopep8.pyPyDev.Debugger/_pydevd_frame_eval/vendored/bytecode/tests/test_cfg.py +122 more
Risky Plugins Authors FP 20%
HIGHpostinstall system command

System command execution detected

153
PyDev.Debugger/pydev_ipython/inputhookglut.pypackage.jsonPyDev.Debugger/_pydev_bundle/fsnotify/__init__.py +150 more
Risky Plugins Authors FP 10%
HIGHUsingShellInterpreterWhenExecutingOSCommands

Arbitrary OS command injection vulnerabilities are more likely when a shell is spawned rather than a new process, indeed shell meta-chars can be used (when parameters are user-controlled for instance) to inject OS commands. For more information checkout the CWE-78 (https://cwe.mitre.org/data/definitions/78.html) advisory.

1
PyDev.Debugger/_pydev_bundle/pydev_monkey.py
FP 10%
HIGHpostinstall persistence mechanism

Persistence mechanism detected

18
PyDev.Debugger/pydevd_attach_to_process/winappdbg/process.pyPyDev.Debugger/pydevd_attach_to_process/winappdbg/win32/peb_teb.pyPyDev.Debugger/_pydevd_bundle/pydevd_command_line_handling.py +15 more
Risky Plugins Authors FP 20%
HIGHpostinstall environment access

Environment variable access detected

32
PyDev.Debugger/_pydevd_bundle/pydevd_concurrency_analyser/pydevd_concurrency_logger.pyPyDev.Debugger/_pydevd_bundle/pydevd_process_net_command.pyPyDev.Debugger/_pydevd_bundle/pydevd_process_net_command_json.py +29 more
Risky Plugins Authors FP 40%
HIGHpostinstall network communication

Network communication detected

96
PyDev.Debugger/pydevd_attach_to_process/add_code_to_python_process.pyPyDev.Debugger/third_party/pep8/autopep8.pyPyDev.Debugger/_pydevd_frame_eval/vendored/bytecode-0.13.0.dev0.dist-info/COPYING +93 more
Risky Plugins Authors FP 30%
HIGHpostinstall file download

File download activity detected

34
PyDev.Debugger/_pydevd_bundle/pydevd_console.pyPyDev.Debugger/_pydevd_bundle/_debug_adapter/debugProtocol.jsonPyDev.Debugger/pydevd_attach_to_process/winappdbg/win32/context_i386.py +31 more
Risky Plugins Authors FP 30%
HIGHNoWriteOnDocumentContentFromRequest

Cross-site scripting (XSS) is a type of computer security vulnerability typically found in web applications. XSS enables attackers to inject client-side scripts into web pages viewed by other users. For more information checkout the CWE-79 (https://cwe.mitre.org/data/definitions/79.html) advisory.

2
PyDev.Debugger/_pydevd_bundle/_debug_adapter/__main__pydevd_gen_debug_adapter_protocol.pysrc_adapter/pydevd_dap_adapter/debug_adapter_core/dap/__main__pydevd_gen_debug_adapter_protocol.py
FP 10%
HIGHpostinstall obfuscation

Code obfuscation techniques detected

130
PyDev.Debugger/_pydevd_frame_eval/.gitignorePyDev.Debugger/_pydev_runfiles/pydev_runfiles_pytest2.pyPyDev.Debugger/_pydevd_bundle/_debug_adapter/debugProtocol.json +127 more
Risky Plugins Authors FP 20%
HIGHcredential env files

Environment configuration file path detected

34
PyDev.Debugger/setup_pydevd_cython.pyPyDev.Debugger/_pydev_bundle/pydev_console_utils.pyPyDev.Debugger/pydevd_attach_to_process/_test_attach_to_process_linux.py +31 more
Risky Plugins Authors FP 10%
HIGHNoUseEval

The eval function is extremely dangerous. Because if any user input is not handled correctly and passed to it, it will be possible to execute code remotely in the context of your application (RCE - Remote Code Executuion). For more information checkout the CWE-94 (https://cwe.mitre.org/data/definitions/94.html) advisory.

12
PyDev.Debugger/_pydev_bundle/_pydev_completer.pyPyDev.Debugger/_pydevd_bundle/pydevd_suspended_frames.pyPyDev.Debugger/_pydevd_bundle/pydevconsole_code.py +9 more
FP 10%
HIGHRedirectToUnknownPath

Sanitizing untrusted URLs is an important technique for preventing attacks such as request forgeries and malicious redirections. Often, this is done by checking that the host of a URL is in a set of allowed hosts. For more information checkout the CWE-20 (https://cwe.mitre.org/data/definitions/20.html) advisory.

5
PyDev.Debugger/_pydev_runfiles/pydev_runfiles_unittest.pyPyDev.Debugger/pydevd.pyPyDev.Debugger/_pydev_runfiles/pydev_runfiles_pytest2.py +2 more
FP 30%
HIGHpostinstall registry modification

Windows registry modification detected

9
PyDev.Debugger/third_party/pep8/pycodestyle.pyPyDev.Debugger/pydevd_attach_to_process/winappdbg/registry.pyPyDev.Debugger/pydevd_attach_to_process/winappdbg/__init__.py +6 more
Risky Plugins Authors FP 30%

Publisher Evidence

Low

fabioz

Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.

55
Noisy-finding weight
x1.00
Publisher domain
No domain
Missing
Store verification signal
Verified publisher
Verified
Extension portfolio
2
Portfolio

12 evidence rows available.

Finding Categories

780
Malware Signatures

YARA Rules Matched

16 rules(780 hits)
DebuggerStatementsShouldNotBeUsed postinstall process injection postinstall crypto operations postinstall file manipulation postinstall system command UsingShellInterpreterWhenExecutingOSCommands postinstall persistence mechanism postinstall environment access postinstall network communication postinstall file download NoWriteOnDocumentContentFromRequest postinstall obfuscation credential env files NoUseEval RedirectToUnknownPath postinstall registry modification

AI Security Report

AI Security Review

Evidence context: threat category none; evidence quality strong.

Security Analysis: Python Debugger (PyDev)

This extension implements the PyDev Debugger (pydevd), a legitimate Python debugging tool widely used in the Python development ecosystem. The analysis reveals no evidence of malicious behavior despite a high total finding count of 1105.

Filesystem and Process Access Justification

The extension's file paths align with standard debugger functionality. Files like extension/PyDev.Debugger/_pydevd_bundle/pydevd_command_line_handling.py handle command-line arguments for the debugger, while extension/PyDev.Debugger/pydevd_attach_to_process/windows/attach.h enables process attachment on Windows systems. The extension/src_adapter/pydevd_dap_adapter/_writer_thread.py implements the Debug Adapter Protocol for communication with VS Code, and extension/PyDev.Debugger/_pydevd_sys_monitoring/pydevd_sys_monitoring.py provides system monitoring capabilities. These components are standard for Python debuggers and justify the read_write workspace access needed to inspect source code, set breakpoints, and spawn debug processes.

Credential Access Analysis

The secret finding count is 0, indicating no credential theft patterns were detected. The extension does not access .env files, SSH keys, cloud credentials, or VS Code's secret storage. Any code-smell findings that reference environment variables match generic patterns that appear in any code reading configuration, not actual secret extraction. The extension's purpose as a debugger does not require credential access.

Strongest Counterargument

The 780 high-severity code-smell findings might suggest suspicious behavior at first glance. However, code-smell YARA rules fire on almost any non-trivial Python or JavaScript codebase. These findings match basic patterns like process.env access or child_process usage, which are legitimate for a debugger that spawns Python processes and reads configuration. More importantly, the threat indicators show 0 for all actual malicious categories: ioc, malware-signature, malware, network, obfuscation, and tool-poisoning. This confirms the code-smell findings are false positives, not indicators of malicious intent.

Conclusion

This extension is a legitimate Python debugger with expected IDE extension behavior. The high finding count stems from code-smell noise and bundled dependency artifacts, not malicious activity. The 9 dependency findings come from bundled packages, which is normal for IDE extensions. No action is required beyond suppressing false positives.

Key Reasons

  • Zero findings in actual threat categories (ioc, malware, network, obfuscation)
  • File paths correspond to legitimate debugger components (pydevd, DAP adapter)
  • All 780 high-severity findings are code-smell noise per CVEQ false-positive patterns
  • No credential access or secret extraction findings detected
  • Extension serves stated purpose as Python debugger with expected capabilities

False Positive Considerations

  • Code-smell YARA rules matching legitimate Python debugger code patterns
  • Dependency findings from bundled npm packages and libraries
  • High severity classification of code-smell findings despite being noise
  • Standard debugger functionality triggering generic process-execution patterns

Reviewed 2026-05-23; recommended action: suppress false positive; model confidence 85%.

About This Extension

Python Debugger with the PyDev Debugger (pydevd)

Frequently Asked Questions