VS Code Marketplace Verified

Verso Notebook

by Datafication · 1.3K users · 5.0 rating
dd4613ff-691e-555b-b354-46e9824fd1cd | v1.2.2
100/ 100
CRITICAL risk
Risk verdict
Do not install

Score-based assessment (critical risk, 100/100). No analyst review available.

Analysis record

Analysed
3 weeks ago
Version
v1.2.2
Artifact
SHA256 D06…FEB
Source
Findings (non-IoC)

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

985 detail rows
Showing 25 of 563 · highest severity first

YARA Rule Matches

15 rules
SeverityRuleHitsFilesMetadata
HIGHNjrat

Njrat

2
host/runtimes/win/lib/net8.0/System.Management.Automation.dllhost/runtimes/unix/lib/net8.0/System.Management.Automation.dll
botherder https://github.com/botherder FP 10%
LOWpostinstall persistence mechanism 14
blazor-wasm/wwwroot/_framework/Verso.Blazor.Shared.wasmblazor-wasm/wwwroot/_framework/dotnet.jshost/Verso.xml +11 more
-
LOWcredential env files 7
blazor-wasm/wwwroot/_framework/dotnet.runtime.jsblazor-wasm/wwwroot/_framework/dotnet.native.wasmdist/extension.js.map +4 more
-
LOWpostinstall file download 36
host/Verso.DataFrame.pdbblazor-wasm/wwwroot/_framework/Verso.Blazor.Shared.wasmhost/Verso.pdb +33 more
-
LOWNoUseEval 1
host/Verso.Python.dll
-
LOWDebuggerStatementsShouldNotBeUsed 33
host/Microsoft.CodeAnalysis.Features.dllhost/FSharp.Compiler.Service.dllblazor-wasm/wwwroot/_framework/dotnet.native.wasm +30 more
-
LOWLocalStorageShouldNotBeUsed 1
blazor-wasm/wwwroot/_content/Verso.Blazor.Shared/js/user-prefs-interop.js
-
LOWpostinstall file manipulation 68
host/Verso.xmlblazor-wasm/wwwroot/_framework/Microsoft.AspNetCore.Components.wasmblazor-wasm/wwwroot/_framework/Verso.Abstractions.wasm +65 more
-
LOWpostinstall network communication 57
blazor-wasm/wwwroot/_framework/Microsoft.AspNetCore.Components.wasmhost/Verso.DataFrame.pdbblazor-wasm/wwwroot/_framework/de/Verso.Blazor.Shared.resources.wasm +54 more
-
LOWpostinstall crypto operations 49
blazor-wasm/wwwroot/_framework/Microsoft.JSInterop.wasmblazor-wasm/wwwroot/_framework/Verso.Abstractions.wasmhost/Verso.FSharp.pdb +46 more
-
LOWUsingShellInterpreterWhenExecutingOSCommands 2
dist/extension.jsdist/extension.js.map
-
LOWOriginsNotVerified 2
blazor-wasm/wwwroot/_content/Verso.Blazor.Shared/js/verso-layout-frame.jsblazor-wasm/wwwroot/_framework/dotnet.runtime.js
-
LOWpostinstall system command 98
host/runtimes/win/lib/net8.0/Modules/CimCmdlets/CimCmdlets.psd1blazor-wasm/wwwroot/_framework/Microsoft.Extensions.DependencyInjection.Abstractions.wasmblazor-wasm/wwwroot/_framework/Microsoft.Extensions.Configuration.Abstractions.wasm +95 more
-
LOWpostinstall obfuscation 36
host/runtimes/linux-arm/native/libpsl-native.soblazor-wasm/wwwroot/_framework/blazor.webassembly.jshost/Verso.Abstractions.xml +33 more
-
LOWpostinstall registry modification 16
host/Verso.Abstractions.pdbhost/Verso.Python.pdbhost/Verso.Host.deps.json +13 more
-

Network Indicators

Concrete URLs, domains, IPs, emails, and hashes extracted from the analyzed artifact.

1,290 total
...

Network indicators are queued for lazy loading

Scroll this section into view to load the detailed rows.

Publisher Evidence

Limited evidence

Datafication

Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.

32
Noisy-finding weight
x1.00
Publisher domain
datafication.co
Observed
Store verification signal
Not exposed
Not exposed
Extension portfolio
1
Portfolio

13 evidence rows available.

Finding Categories

2
Malware Signatures
556
Obfuscation
7
Network
1,290
IoC Indicators

YARA Rules Matched

15 rules(422 hits)
Njrat postinstall persistence mechanism credential env files postinstall file download NoUseEval DebuggerStatementsShouldNotBeUsed LocalStorageShouldNotBeUsed postinstall file manipulation postinstall network communication postinstall crypto operations UsingShellInterpreterWhenExecutingOSCommands OriginsNotVerified postinstall system command postinstall obfuscation postinstall registry modification

Security Analysis Summary

Security Analysis Overview

Verso Notebook is a Visual Studio Code Marketplace extension published by Datafication. Version 1.2.2 has been analyzed by the Risky Plugins security platform, receiving a risk score of 100/100 (CRITICAL risk) based on 2275 security findings.

Risk Assessment

This extension presents critical security risk. Severe issues were detected, potentially including malware indicators, exposed secrets, or dangerous behaviors. Installation is strongly discouraged until these issues are addressed.

Findings Breakdown

  • Critical: 552 finding(s)
  • High: 2 finding(s)
  • Medium: 1301 finding(s)
  • Low: 420 finding(s)

What Was Analyzed

The security assessment covers multiple analysis categories:

  • Malware Detection: YARA rule matching against 2,400+ malware signatures
  • Secret Detection: Scanning for exposed API keys, tokens, and credentials
  • Static Analysis: Code-level security analysis for common vulnerability patterns
  • Network Analysis: Detection of suspicious network communications and endpoints
  • Obfuscation Detection: Identification of code obfuscation techniques

Developer Information

Verso Notebook is published by Datafication on the Visual Studio Code Marketplace marketplace. The extension has approximately 1K users.

Recommendation

This extension is not recommended for installation without thorough manual review. Consider alternatives with lower risk scores, or contact the developer to address the identified security concerns.

About This Extension

Polyglot .NET notebooks with C#, F#, Python, JavaScript, TypeScript, PowerShell, SQL, and HTTP cells. One shared variable store across languages, IntelliSense, dashboards, Jupyter import, and GitHub Copilot integration.

Frequently Asked Questions