JetBrains Marketplace Verified

TASKING winIDEA

by TASKING · 1.0K users
e4855fa1-e408-51d3-856f-496c146ca9a9 | v921.40800.258814
83/ 100
HIGH risk
Analyst verdict
Confirmed risk

From the RiskyPlugins AI security review of the observed evidence.

Analysis record

Analysed
3 days ago
Version
v921.40800.258814
Artifact
SHA256 FFF…43A
Source
Findings (non-IoC)

Is TASKING winIDEA safe?

TASKING winIDEA is a JetBrains extension package with no declared permissions. Its listed network endpoints include alloc.cc and connection.ws, while the package contains native files named si.isystem.clion.debug/res/IConnectJNIx64.dll and si.isystem.clion.debug/res/libiconnectJava.so. Native files can run inside the IDE process and use that process’s access to local resources when the extension loads them.

Both native files carry the finding title YARA--EclipseSunCloudRAT. If that match is accurate, the files contain code associated with a remote-access malware family. Both files also carry OBFUSCATION-supply_chain_binary. The available results do not name .env, .ssh, cloud credentials, or IDE secret storage, so they do not show confirmed credential theft.

Compiled vendor code can trigger broad signatures, and endpoint strings such as alloc.cc can come from binary extraction. That explains why a scanner could flag the files, yet it does not explain the same malware-family match in both native binaries alongside matching obfuscation findings. The native payloads need isolation and publisher validation before the package is trusted.

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

60 detail rows

YARA Rule Matches

12 rules
SeverityRuleHitsFilesMetadata
HIGHEclipseSunCloudRAT 2
si.isystem.clion.debug/res/IConnectJNIx64.dllsi.isystem.clion.debug/res/libiconnectJava.so
AlienVault Labs FP 5%
LOWpostinstall crypto operations 3
si.isystem.clion.debug/lib/kotlin-stdlib-2.3.0.jarsi.isystem.clion.debug/lib/kotlinx-serialization-core-jvm-1.10.0.jarsi.isystem.clion.debug/res/libiconnectJava.so
-
LOWpostinstall system command 8
si.isystem.clion.debug/lib/si.isystem.clion.debug-921.40800.258814.jarsi.isystem.clion.debug/lib/appdirs-1.4.0.jarsi.isystem.clion.debug/res/debug_adapter.py +5 more
-
LOWpostinstall file manipulation 3
si.isystem.clion.debug/res/libiconnectJava.sosi.isystem.clion.debug/res/connection.pysi.isystem.clion.debug/res/debug_adapter.py
-
LOWJavaDropper 1
si.isystem.clion.debug/lib/kotlin-stdlib-2.3.0.jar
-
LOWpostinstall environment access 1
si.isystem.clion.debug/res/debug_adapter.py
-
LOWpostinstall obfuscation 9
si.isystem.clion.debug/lib/si.isystem.clion.debug-921.40800.258814.jarsi.isystem.clion.debug/lib/IConnectJNI.jarsi.isystem.clion.debug/res/IConnectJNI.jar +6 more
-
LOWpostinstall network communication 7
si.isystem.clion.debug/res/debug_adapter.pysi.isystem.clion.debug/lib/si.isystem.clion.debug-921.40800.258814.jarsi.isystem.clion.debug/lib/IConnectJNI.jar +4 more
-
LOWpostinstall file download 6
si.isystem.clion.debug/res/debug_adapter.pysi.isystem.clion.debug/lib/si.isystem.clion.debug-921.40800.258814.jarsi.isystem.clion.debug/lib/IConnectJNI.jar +3 more
-
LOWDebuggerStatementsShouldNotBeUsed 3
si.isystem.clion.debug/lib/si.isystem.clion.debug-921.40800.258814.jarsi.isystem.clion.debug/res/IConnectJNIx64.dllsi.isystem.clion.debug/res/libiconnectJava.so
-
LOWCerberus 1
si.isystem.clion.debug/res/libiconnectJava.so
-
LOWpostinstall persistence mechanism 1
si.isystem.clion.debug/res/libiconnectJava.so
-

Network Indicators

Concrete URLs, domains, IPs, emails, and hashes extracted from the analyzed artifact.

138 total
...

Network indicators are queued for lazy loading

Scroll this section into view to load the detailed rows.

Publisher Evidence

Low

TASKING

Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.

72
Noisy-finding weight
x1.00
Publisher domain
tasking.com
Observed
Store verification signal
Verified publisher
Verified
Extension portfolio
3
Portfolio

12 evidence rows available.

Finding Categories

2
Malware Signatures
2
Obfuscation
138
IoC Indicators

YARA Rules Matched

12 rules(45 hits)
EclipseSunCloudRAT postinstall crypto operations postinstall system command postinstall file manipulation JavaDropper postinstall environment access postinstall obfuscation postinstall network communication postinstall file download DebuggerStatementsShouldNotBeUsed Cerberus postinstall persistence mechanism

AI Security Report

AI Security Review

Evidence context: threat category unknown malware; evidence quality strong.

The extension’s native code is the main concern. si.isystem.clion.debug/res/IConnectJNIx64.dll and si.isystem.clion.debug/res/libiconnectJava.so are packaged native binaries, so they can run with the privileges available to the JetBrains process and can access local files, processes, and network services when invoked. That capability fits a hardware or debugger integration only if the binaries implement the stated TASKING winIDEA function, yet the package has no stated description linking either binary to a debugger, compiler, or device workflow. The finding titled YARA--EclipseSunCloudRAT matches both native files, which is a direct malware-family signal rather than a generic JavaScript code smell.

The same two files are each marked OBFUSCATION-supply_chain_binary, at si.isystem.clion.debug/res/IConnectJNIx64.dll:0 and si.isystem.clion.debug/res/libiconnectJava.so:0. Obfuscation in native binaries can have legitimate reasons, such as protecting vendor code, but that explanation is weak when both files also receive the YARA--EclipseSunCloudRAT match. The endpoint list includes alloc.cc, connection.ws, cfg.bank, and clogger.java; those names are unusual for a development debugger and add to the concern around the native components. The available findings do not identify .env, .ssh, cloud credential files, IDE secret storage, or any other actual secret path. They also do not show a credential-theft finding. That limits the claim to suspicious native payloads and possible network activity, rather than proven credential theft.

The strongest counterargument is that YARA signatures can match shared code, and the two obfuscation findings can result from ordinary compiled vendor binaries. The endpoint strings can also be false positives from binary or symbol extraction, especially because alloc.cc and clogger.java are short names. That argument does not resolve the paired signals in IConnectJNIx64.dll and libiconnectJava.so: the same specific YARA--EclipseSunCloudRAT title occurs in both files, and each file is independently marked OBFUSCATION-supply_chain_binary. The package has 1,018 users, but the user count at version 921.40800.258814 does not validate native code or explain the malware-family matches. Native binaries in a JetBrains plugin deserve runtime isolation and publisher verification before continued distribution.

Key Reasons

  • YARA--EclipseSunCloudRAT matches both si.isystem.clion.debug/res/IConnectJNIx64.dll:13416 and si.isystem.clion.debug/res/libiconnectJava.so:11837.
  • OBFUSCATION-supply_chain_binary marks both native files at their file starts.
  • Unusual extracted endpoints include alloc.cc, connection.ws, cfg.bank, and clogger.java.
  • No listed finding identifies .env, .ssh, cloud credentials, or IDE secret storage.

False Positive Considerations

  • YARA matches can occur on shared native-library code, including YARA--EclipseSunCloudRAT.
  • OBFUSCATION-supply_chain_binary can flag legitimate compiled vendor binaries.
  • Short endpoint strings such as alloc.cc and clogger.java can result from binary extraction.
  • Native files can contain packed or optimized code that resembles obfuscation.

Reviewed 2026-09-30; recommended action: escalate; model confidence 90%.

About This Extension

A TASKING plugin that integrates winIDEA’s tools into CLion. winIDEA is a powerful IDE known for its comprehensive debugging and testing capabilities. It supports a...

Frequently Asked Questions