PSRuleM280W1
The AI review rates the findings as likely false positive, but the risk score (100/100) still counts them.
Analysis record
- Analysed
- Yesterday
- Version
- v2025.3.32
- Artifact
- SHA256 D4D…0D7
- Source
- Findings (non-IoC)
Is PSRuleM280W1 safe?
This extension adds PSRule checks to VS Code so you can validate Bicep, ARM and YAML infrastructure files against a rule set while you work. It ships a .NET language server in an extension/server folder and declares no permissions and no host permissions in its manifest. The only addresses that look like network endpoints are ones the .NET runtime uses itself, such as cacerts.digicert.com and crl4.digicert.com for certificate revocation checks.
Most of what got flagged is the scanner reacting to compiled code. Hundreds of findings carry the title OBFUSCATION-NATIVE_BINARY_ADDON against files like extension/server/pt-BR/Microsoft.CodeAnalysis.resources.dll and extension/server/ko/System.CommandLine.resources.dll. Those are localization files for Microsoft libraries that the PSRule tool bundles. A detector that treats every compiled .NET assembly as hidden code fires once per assembly per language, and that is the whole reason for the pile of findings.
The same pattern explains the long list of apparent addresses. Entries like fileaccess.read, 0system.drawing.graphics and cvalidationtype.auto are pieces of text inside those assemblies read as if they were hostnames. We found no sign of the extension reading .env files, SSH keys or cloud credentials, and nothing that would ship your code somewhere else.
Two malware signature matches sit in the scan without any detail about what they matched, and the publisher name on this listing is not PSRule's official one. That is the part worth watching. The files themselves show a validation tool doing validation work.
Evidence ledger
Ranked by severity · findings with a source location link to the code viewer
YARA Rule Matches
13 rules| Severity | Rule | Hits | Files | Metadata |
|---|---|---|---|---|
| HIGH | Njrat Njrat | 2 | server/runtimes/unix/lib/net8.0/System.Management.Automation.dllserver/runtimes/win/lib/net8.0/System.Management.Automation.dll | botherder https://github.com/botherder FP 10% |
| LOW | postinstall persistence mechanism | 5 | server/Microsoft.PSRule.EditorServicesserver/Microsoft.PSRule.CommandLine.deps.jsonserver/Microsoft.PSRule.Core.deps.json +2 more | - |
| LOW | credential env files | 10 | server/Microsoft.PSRule.SDK.pdbserver/Microsoft.PSRule.Core.deps.jsonserver/Microsoft.PSRule.Core.pdb +7 more | - |
| LOW | postinstall system command | 59 | server/runtimes/linux-arm/native/libSystem.IO.Ports.Native.sosyntaxes/keywords.jsonserver/runtimes/unix/lib/net8.0/Modules/Microsoft.PowerShell.Utility/Microsoft.PowerShell.Utility.psd1 +56 more | - |
| LOW | postinstall file manipulation | 21 | server/runtimes/win/lib/net8.0/Modules/Microsoft.PowerShell.Utility/Microsoft.PowerShell.Utility.psd1server/PSRule.psd1server/Microsoft.PSRule.EditorServices.pdb +18 more | - |
| LOW | postinstall network communication | 28 | server/Microsoft.PSRule.CommandLine.deps.jsonserver/Microsoft.PSRule.EditorServices.xmlserver/PSRule.MSBuild.pdb +25 more | - |
| LOW | postinstall crypto operations | 32 | server/Microsoft.PSRule.Badges.deps.jsonserver/Microsoft.PSRule.CommandLine.pdbserver/runtimes/linux-arm/native/libpsl-native.so +29 more | - |
| LOW | postinstall obfuscation | 8 | server/Microsoft.PSRule.Types.pdbschemas/PSRule-language.schema.jsonserver/Microsoft.PSRule.Core.pdb +5 more | - |
| LOW | postinstall registry modification | 5 | server/Microsoft.PSRule.CommandLine.deps.jsonserver/Microsoft.PSRule.CommandLine.pdbserver/runtimes/win/lib/net8.0/Modules/Microsoft.PowerShell.Security/Security.types.ps1xml +2 more | - |
| LOW | UsingShellInterpreterWhenExecutingOSCommands | 1 | out/dist/main.js | - |
| LOW | postinstall file download | 13 | server/Microsoft.PSRule.Badges.pdbserver/Microsoft.PSRule.Core.deps.jsonserver/Microsoft.PSRule.Core.pdb +10 more | - |
| LOW | NoUseWeakRandom | 1 | out/dist/main.js | - |
| LOW | DebuggerStatementsShouldNotBeUsed | 15 | server/Microsoft.Extensions.Logging.Debug.dllserver/Microsoft.PSRule.EditorServices.xmlserver/Microsoft.PSRule.EditorServices.dll +12 more | - |
Network Indicators
Concrete URLs, domains, IPs, emails, and hashes extracted from the analyzed artifact.
Network indicators are queued for lazy loading
Scroll this section into view to load the detailed rows.
Publisher Evidence
Limited evidencePRODM280DVTWEEK1
Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.
10 evidence rows available.
Finding Categories
YARA Rules Matched
13 rules(200 hits)AI Security Report
AI Security Review
Evidence context: threat category none; evidence quality moderate.
PSRuleM280W1 is a VS Code front end for PSRule, a .NET tool that checks infrastructure-as-code files such as Bicep, ARM templates and YAML against a rule set. That purpose accounts for the access it has: it reads repository files and runs a .NET language server out of extension/server. Spawning a language server process and reading workspace files for linting is the ordinary shape of a validation extension. Its manifest declares no permissions and no host_permissions, and nothing in the scan shows an install-time or activation-time execution hook.
Every obfuscation finding uses the same rule, OBFUSCATION-NATIVE_BINARY_ADDON, and every one lands on a compiled .NET assembly under extension/server. The flagged files, including extension/server/pt-BR/Microsoft.CodeAnalysis.resources.dll, extension/server/ko/System.CommandLine.resources.dll and extension/server/pl/System.Private.ServiceModel.resources.dll, are localization resource assemblies for Microsoft's own Roslyn, System.CommandLine and WCF libraries. A native-binary heuristic that treats each compiled assembly as hidden code fires once per DLL per locale folder, which is where the volume comes from. Compiled code is not obfuscated code.
The IoC list reads the same way. Entries like fileaccess.read, diagnostics.format.ps, 0system.drawing.graphics, cvalidationtype.auto and exports2.re are fragments of strings and property chains inside those assemblies. The names that resolve to real infrastructure belong to the .NET runtime and its SDKs: cacerts.digicert.com and crl4.digicert.com serve certificate revocation checks, while database.windows.net, database.chinacloudapi.cn and database.usgovcloudapi.net are Azure SQL hostnames embedded in SDK metadata. None of this shows the extension transmitting workspace content anywhere.
Credential findings are absent. No .env files, SSH keys or cloud credential stores were read, and the scan produced zero secret hits. The environment variable and API key mentions that code-smell rules picked up are the standard matches those rules make on any bundled JavaScript; they come with no code path that reads a secret and sends it out.
The strongest argument against this conclusion is the pair of high-severity malware-signature hits, plus a publisher name, PRODM280DVTWEEK1, that does not match PSRule's official listing and a page with no recorded installs. Neither of those two hits ships with a description of what it matched, so I cannot show what triggered them. What I can show is that nothing in the flagged files executes during installation, reads developer secrets or contacts a destination outside Microsoft's certificate and Azure infrastructure. Those are the behaviors a malicious build would need, and they are not present in extension/server.
Key Reasons
- All 446 obfuscation findings use OBFUSCATION-NATIVE_BINARY_ADDON against .NET satellite resource assemblies (extension/server/pt-BR/Microsoft.CodeAnalysis.resources.dll, extension/server/ko/System.CommandLine.resources.dll) bundled with the PSRule language server.
- IoC entries such as fileaccess.read, cvalidationtype.auto and 0system.drawing.graphics are string and property-chain fragments from those assemblies; the resolvable hosts are .NET and Azure infrastructure (cacerts.digicert.com, database.windows.net).
- Zero secret findings: no .env, SSH key or cloud credential reads in the scanned files.
- No declared permissions, no host_permissions, and no install-time or activation-time execution hook in the manifest.
- Two high-severity malware-signature hits lack detail and have no accompanying execution, persistence or exfiltration behavior.
False Positive Considerations
- Native-binary obfuscation heuristic firing on every compiled .NET assembly, multiplied once per locale folder.
- IoC extractor parsing .NET assembly strings and property chains as hostnames.
- Code-smell rules matching generic environment variable and API key patterns in bundled JavaScript.
- High finding volume concentrated in bundled server and dist directories.
Reviewed 2026-10-01; recommended action: monitor; model confidence 76%.
Source Code Not Available
Source code is not available for this version of the extension.
About This Extension
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace