Python Debugger (PyDev)
The AI review rates the findings as likely false positive, but the risk score (46/100) still counts them.
Analysis record
- Analysed
- 8 months ago
- Version
- v0.3.0
- Source
- Findings (non-IoC)
Evidence ledger
Ranked by severity · findings with a source location link to the code viewer
YARA Rule Matches
16 rules| Severity | Rule | Hits | Files | Metadata |
|---|---|---|---|---|
| HIGH | DebuggerStatementsShouldNotBeUsed The debugger statement can be placed anywhere in procedures to suspend execution. Using the debugger statement is similar to setting a breakpoint in the code. By definition such statement must absolutely be removed from the source code to prevent any unexpected behavior or added vulnerability to attacks in production. For more information checkout the CWE-489 (https://cwe.mitre.org/data/definitions/489.html) advisory. | 103 | PyDev.Debugger/_pydevd_bundle/_debug_adapter/pydevd_schema.pysrc_adapter/pydevd_dap_adapter/debug_adapter_comm.pysrc_adapter/pydevd_dap_adapter/_process_attach.py +100 more | FP 10% |
| HIGH | postinstall process injection Process injection techniques detected | 4 | PyDev.Debugger/pydevd_attach_to_process/winappdbg/process.pyPyDev.Debugger/pydevd_attach_to_process/winappdbg/thread.pyPyDev.Debugger/pydevd_attach_to_process/winappdbg/win32/kernel32.py +1 more | Risky Plugins Authors FP 10% |
| HIGH | postinstall crypto operations Cryptographic operations detected | 22 | PyDev.Debugger/pydevd_attach_to_process/windows/attach.cppPyDev.Debugger/_pydev_bundle/_pydev_jy_imports_tipper.pyPyDev.Debugger/_pydevd_bundle/pydevd_cython.c +19 more | Risky Plugins Authors FP 30% |
| HIGH | postinstall file manipulation File system manipulation detected | 125 | PyDev.Debugger/_pydev_runfiles/pydev_runfiles.pyPyDev.Debugger/third_party/pep8/autopep8.pyPyDev.Debugger/_pydevd_frame_eval/vendored/bytecode/tests/test_cfg.py +122 more | Risky Plugins Authors FP 20% |
| HIGH | postinstall system command System command execution detected | 153 | PyDev.Debugger/pydev_ipython/inputhookglut.pypackage.jsonPyDev.Debugger/_pydev_bundle/fsnotify/__init__.py +150 more | Risky Plugins Authors FP 10% |
| HIGH | UsingShellInterpreterWhenExecutingOSCommands Arbitrary OS command injection vulnerabilities are more likely when a shell is spawned rather than a new process, indeed shell meta-chars can be used (when parameters are user-controlled for instance) to inject OS commands. For more information checkout the CWE-78 (https://cwe.mitre.org/data/definitions/78.html) advisory. | 1 | PyDev.Debugger/_pydev_bundle/pydev_monkey.py | FP 10% |
| HIGH | postinstall persistence mechanism Persistence mechanism detected | 18 | PyDev.Debugger/pydevd_attach_to_process/winappdbg/process.pyPyDev.Debugger/pydevd_attach_to_process/winappdbg/win32/peb_teb.pyPyDev.Debugger/_pydevd_bundle/pydevd_command_line_handling.py +15 more | Risky Plugins Authors FP 20% |
| HIGH | postinstall environment access Environment variable access detected | 32 | PyDev.Debugger/_pydevd_bundle/pydevd_concurrency_analyser/pydevd_concurrency_logger.pyPyDev.Debugger/_pydevd_bundle/pydevd_process_net_command.pyPyDev.Debugger/_pydevd_bundle/pydevd_process_net_command_json.py +29 more | Risky Plugins Authors FP 40% |
| HIGH | postinstall network communication Network communication detected | 96 | PyDev.Debugger/pydevd_attach_to_process/add_code_to_python_process.pyPyDev.Debugger/third_party/pep8/autopep8.pyPyDev.Debugger/_pydevd_frame_eval/vendored/bytecode-0.13.0.dev0.dist-info/COPYING +93 more | Risky Plugins Authors FP 30% |
| HIGH | postinstall file download File download activity detected | 34 | PyDev.Debugger/_pydevd_bundle/pydevd_console.pyPyDev.Debugger/_pydevd_bundle/_debug_adapter/debugProtocol.jsonPyDev.Debugger/pydevd_attach_to_process/winappdbg/win32/context_i386.py +31 more | Risky Plugins Authors FP 30% |
| HIGH | NoWriteOnDocumentContentFromRequest Cross-site scripting (XSS) is a type of computer security vulnerability typically found in web applications. XSS enables attackers to inject client-side scripts into web pages viewed by other users. For more information checkout the CWE-79 (https://cwe.mitre.org/data/definitions/79.html) advisory. | 2 | PyDev.Debugger/_pydevd_bundle/_debug_adapter/__main__pydevd_gen_debug_adapter_protocol.pysrc_adapter/pydevd_dap_adapter/debug_adapter_core/dap/__main__pydevd_gen_debug_adapter_protocol.py | FP 10% |
| HIGH | postinstall obfuscation Code obfuscation techniques detected | 130 | PyDev.Debugger/_pydevd_frame_eval/.gitignorePyDev.Debugger/_pydev_runfiles/pydev_runfiles_pytest2.pyPyDev.Debugger/_pydevd_bundle/_debug_adapter/debugProtocol.json +127 more | Risky Plugins Authors FP 20% |
| HIGH | credential env files Environment configuration file path detected | 34 | PyDev.Debugger/setup_pydevd_cython.pyPyDev.Debugger/_pydev_bundle/pydev_console_utils.pyPyDev.Debugger/pydevd_attach_to_process/_test_attach_to_process_linux.py +31 more | Risky Plugins Authors FP 10% |
| HIGH | NoUseEval The eval function is extremely dangerous. Because if any user input is not handled correctly and passed to it, it will be possible to execute code remotely in the context of your application (RCE - Remote Code Executuion). For more information checkout the CWE-94 (https://cwe.mitre.org/data/definitions/94.html) advisory. | 12 | PyDev.Debugger/_pydev_bundle/_pydev_completer.pyPyDev.Debugger/_pydevd_bundle/pydevd_suspended_frames.pyPyDev.Debugger/_pydevd_bundle/pydevconsole_code.py +9 more | FP 10% |
| HIGH | RedirectToUnknownPath Sanitizing untrusted URLs is an important technique for preventing attacks such as request forgeries and malicious redirections. Often, this is done by checking that the host of a URL is in a set of allowed hosts. For more information checkout the CWE-20 (https://cwe.mitre.org/data/definitions/20.html) advisory. | 5 | PyDev.Debugger/_pydev_runfiles/pydev_runfiles_unittest.pyPyDev.Debugger/pydevd.pyPyDev.Debugger/_pydev_runfiles/pydev_runfiles_pytest2.py +2 more | FP 30% |
| HIGH | postinstall registry modification Windows registry modification detected | 9 | PyDev.Debugger/third_party/pep8/pycodestyle.pyPyDev.Debugger/pydevd_attach_to_process/winappdbg/registry.pyPyDev.Debugger/pydevd_attach_to_process/winappdbg/__init__.py +6 more | Risky Plugins Authors FP 30% |
Publisher Evidence
Lowfabioz
Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.
12 evidence rows available.
Finding Categories
YARA Rules Matched
16 rules(780 hits)AI Security Report
AI Security Review
Evidence context: threat category none; evidence quality strong.
Security Analysis: Python Debugger (PyDev)
This extension implements the PyDev Debugger (pydevd), a legitimate Python debugging tool widely used in the Python development ecosystem. The analysis reveals no evidence of malicious behavior despite a high total finding count of 1105.
Filesystem and Process Access Justification
The extension's file paths align with standard debugger functionality. Files like extension/PyDev.Debugger/_pydevd_bundle/pydevd_command_line_handling.py handle command-line arguments for the debugger, while extension/PyDev.Debugger/pydevd_attach_to_process/windows/attach.h enables process attachment on Windows systems. The extension/src_adapter/pydevd_dap_adapter/_writer_thread.py implements the Debug Adapter Protocol for communication with VS Code, and extension/PyDev.Debugger/_pydevd_sys_monitoring/pydevd_sys_monitoring.py provides system monitoring capabilities. These components are standard for Python debuggers and justify the read_write workspace access needed to inspect source code, set breakpoints, and spawn debug processes.
Credential Access Analysis
The secret finding count is 0, indicating no credential theft patterns were detected. The extension does not access .env files, SSH keys, cloud credentials, or VS Code's secret storage. Any code-smell findings that reference environment variables match generic patterns that appear in any code reading configuration, not actual secret extraction. The extension's purpose as a debugger does not require credential access.
Strongest Counterargument
The 780 high-severity code-smell findings might suggest suspicious behavior at first glance. However, code-smell YARA rules fire on almost any non-trivial Python or JavaScript codebase. These findings match basic patterns like process.env access or child_process usage, which are legitimate for a debugger that spawns Python processes and reads configuration. More importantly, the threat indicators show 0 for all actual malicious categories: ioc, malware-signature, malware, network, obfuscation, and tool-poisoning. This confirms the code-smell findings are false positives, not indicators of malicious intent.
Conclusion
This extension is a legitimate Python debugger with expected IDE extension behavior. The high finding count stems from code-smell noise and bundled dependency artifacts, not malicious activity. The 9 dependency findings come from bundled packages, which is normal for IDE extensions. No action is required beyond suppressing false positives.
Key Reasons
- Zero findings in actual threat categories (ioc, malware, network, obfuscation)
- File paths correspond to legitimate debugger components (pydevd, DAP adapter)
- All 780 high-severity findings are code-smell noise per CVEQ false-positive patterns
- No credential access or secret extraction findings detected
- Extension serves stated purpose as Python debugger with expected capabilities
False Positive Considerations
- Code-smell YARA rules matching legitimate Python debugger code patterns
- Dependency findings from bundled npm packages and libraries
- High severity classification of code-smell findings despite being noise
- Standard debugger functionality triggering generic process-execution patterns
Reviewed 2026-05-23; recommended action: suppress false positive; model confidence 85%.
Source Code Not Available
Source code is not available for this version of the extension.
About This Extension
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace
vscode-pydev
fabioz
Python (PyDev)
Fabio Zadrozny
Python Debugger (PyDev)
Fabio Zadrozny
Profile Python with PyVmMonitor
Fabio Zadrozny
Eclipse/PyDev Windows Keymap
Fabio Zadrozny
quark-lang
quarkproject