TASKING winIDEA
From the RiskyPlugins AI security review of the observed evidence.
Analysis record
- Analysed
- 3 days ago
- Version
- v921.40800.258814
- Artifact
- SHA256 FFF…43A
- Source
- Findings (non-IoC)
Is TASKING winIDEA safe?
TASKING winIDEA is a JetBrains extension package with no declared permissions. Its listed network endpoints include alloc.cc and connection.ws, while the package contains native files named si.isystem.clion.debug/res/IConnectJNIx64.dll and si.isystem.clion.debug/res/libiconnectJava.so. Native files can run inside the IDE process and use that process’s access to local resources when the extension loads them.
Both native files carry the finding title YARA--EclipseSunCloudRAT. If that match is accurate, the files contain code associated with a remote-access malware family. Both files also carry OBFUSCATION-supply_chain_binary. The available results do not name .env, .ssh, cloud credentials, or IDE secret storage, so they do not show confirmed credential theft.
Compiled vendor code can trigger broad signatures, and endpoint strings such as alloc.cc can come from binary extraction. That explains why a scanner could flag the files, yet it does not explain the same malware-family match in both native binaries alongside matching obfuscation findings. The native payloads need isolation and publisher validation before the package is trusted.
Evidence ledger
Ranked by severity · findings with a source location link to the code viewer
YARA Rule Matches
12 rules| Severity | Rule | Hits | Files | Metadata |
|---|---|---|---|---|
| HIGH | EclipseSunCloudRAT | 2 | si.isystem.clion.debug/res/IConnectJNIx64.dllsi.isystem.clion.debug/res/libiconnectJava.so | AlienVault Labs FP 5% |
| LOW | Cerberus | 1 | si.isystem.clion.debug/res/libiconnectJava.so | - |
| LOW | postinstall persistence mechanism | 1 | si.isystem.clion.debug/res/libiconnectJava.so | - |
| LOW | postinstall file download | 6 | si.isystem.clion.debug/res/libiconnectJava.sosi.isystem.clion.debug/lib/si.isystem.winidea.update-921.40800.258814.jarsi.isystem.clion.debug/res/debug_adapter.py +3 more | - |
| LOW | DebuggerStatementsShouldNotBeUsed | 3 | si.isystem.clion.debug/lib/si.isystem.clion.debug-921.40800.258814.jarsi.isystem.clion.debug/res/libiconnectJava.sosi.isystem.clion.debug/res/IConnectJNIx64.dll | - |
| LOW | postinstall crypto operations | 3 | si.isystem.clion.debug/res/libiconnectJava.sosi.isystem.clion.debug/lib/kotlin-stdlib-2.3.0.jarsi.isystem.clion.debug/lib/kotlinx-serialization-core-jvm-1.10.0.jar | - |
| LOW | postinstall system command | 8 | si.isystem.clion.debug/lib/si.isystem.clion.debug-921.40800.258814.jarsi.isystem.clion.debug/lib/kotlin-stdlib-2.3.0.jarsi.isystem.clion.debug/res/debug_adapter.py +5 more | - |
| LOW | postinstall file manipulation | 3 | si.isystem.clion.debug/res/libiconnectJava.sosi.isystem.clion.debug/res/connection.pysi.isystem.clion.debug/res/debug_adapter.py | - |
| LOW | JavaDropper | 1 | si.isystem.clion.debug/lib/kotlin-stdlib-2.3.0.jar | - |
| LOW | postinstall environment access | 1 | si.isystem.clion.debug/res/debug_adapter.py | - |
| LOW | postinstall obfuscation | 9 | si.isystem.clion.debug/lib/si.isystem.clion.debug-921.40800.258814.jarsi.isystem.clion.debug/lib/IConnectJNI.jarsi.isystem.clion.debug/res/libiconnectJava.so +6 more | - |
| LOW | postinstall network communication | 7 | si.isystem.clion.debug/res/debug_adapter.pysi.isystem.clion.debug/lib/si.isystem.clion.debug-921.40800.258814.jarsi.isystem.clion.debug/lib/IConnectJNI.jar +4 more | - |
Network Indicators
Concrete URLs, domains, IPs, emails, and hashes extracted from the analyzed artifact.
Network indicators are queued for lazy loading
Scroll this section into view to load the detailed rows.
Publisher Evidence
LowTASKING
Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.
12 evidence rows available.
Finding Categories
YARA Rules Matched
12 rules(45 hits)AI Security Report
AI Security Review
Evidence context: threat category unknown malware; evidence quality strong.
The extension’s native code is the main concern. si.isystem.clion.debug/res/IConnectJNIx64.dll and si.isystem.clion.debug/res/libiconnectJava.so are packaged native binaries, so they can run with the privileges available to the JetBrains process and can access local files, processes, and network services when invoked. That capability fits a hardware or debugger integration only if the binaries implement the stated TASKING winIDEA function, yet the package has no stated description linking either binary to a debugger, compiler, or device workflow. The finding titled YARA--EclipseSunCloudRAT matches both native files, which is a direct malware-family signal rather than a generic JavaScript code smell.
The same two files are each marked OBFUSCATION-supply_chain_binary, at si.isystem.clion.debug/res/IConnectJNIx64.dll:0 and si.isystem.clion.debug/res/libiconnectJava.so:0. Obfuscation in native binaries can have legitimate reasons, such as protecting vendor code, but that explanation is weak when both files also receive the YARA--EclipseSunCloudRAT match. The endpoint list includes alloc.cc, connection.ws, cfg.bank, and clogger.java; those names are unusual for a development debugger and add to the concern around the native components. The available findings do not identify .env, .ssh, cloud credential files, IDE secret storage, or any other actual secret path. They also do not show a credential-theft finding. That limits the claim to suspicious native payloads and possible network activity, rather than proven credential theft.
The strongest counterargument is that YARA signatures can match shared code, and the two obfuscation findings can result from ordinary compiled vendor binaries. The endpoint strings can also be false positives from binary or symbol extraction, especially because alloc.cc and clogger.java are short names. That argument does not resolve the paired signals in IConnectJNIx64.dll and libiconnectJava.so: the same specific YARA--EclipseSunCloudRAT title occurs in both files, and each file is independently marked OBFUSCATION-supply_chain_binary. The package has 1,018 users, but the user count at version 921.40800.258814 does not validate native code or explain the malware-family matches. Native binaries in a JetBrains plugin deserve runtime isolation and publisher verification before continued distribution.
Key Reasons
YARA--EclipseSunCloudRATmatches bothsi.isystem.clion.debug/res/IConnectJNIx64.dll:13416andsi.isystem.clion.debug/res/libiconnectJava.so:11837.OBFUSCATION-supply_chain_binarymarks both native files at their file starts.- Unusual extracted endpoints include
alloc.cc,connection.ws,cfg.bank, andclogger.java. - No listed finding identifies
.env,.ssh, cloud credentials, or IDE secret storage.
False Positive Considerations
- YARA matches can occur on shared native-library code, including
YARA--EclipseSunCloudRAT. OBFUSCATION-supply_chain_binarycan flag legitimate compiled vendor binaries.- Short endpoint strings such as
alloc.ccandclogger.javacan result from binary extraction. - Native files can contain packed or optimized code that resembles obfuscation.
Reviewed 2026-09-30; recommended action: escalate; model confidence 90%.
About This Extension
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace