Notepad++ Plugins

NppAIAssistant

e9537956-c938-5925-bbd8-d12c52a8a987 | v0.2.0.6
63/ 100
MEDIUM risk
No change since v0.1.0.0
Analyst verdict
Needs follow up

From the RiskyPlugins AI security review of the observed evidence.

Analysis record

Analysed
3 days ago
Version
v0.2.0.6
Artifact
SHA256 23B…621
Source
Findings (non-IoC)

Is NppAIAssistant safe?

NppAIAssistant is a Notepad++ native plugin for visible, single-turn AI prompts. The supplied metadata declares no permissions, while its endpoint list includes free.fr, fsf.org, www.gnu.org, and script-like names such as install-npp-ai-plugin.ps. The native file NppAIAssistant.dll:0 runs inside Notepad++ and receives the host process's access to the user's system.

The main issue is OBFUSCATION-supply_chain_binary, attached directly to NppAIAssistant.dll:0. If that finding reflects hidden behavior, the plugin could conceal file access, process launches, or network activity. The available findings do not name .env files, SSH keys, cloud credentials, or a request that sends document contents to a remote service.

The concern remains open because the DLL's code cannot be assessed from this finding, and the listed script names do not explain the assistant's stated purpose. The scanner did not report a malware signature, so runtime checks are needed to separate ordinary compiled plugin code from unsafe behavior.

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

31 detail rows

YARA Rule Matches

6 rules
SeverityRuleHitsFilesMetadata
LOWpostinstall crypto operations 1
doc/NppAIAssistant/SECURITY_REMEDIATION.md
-
LOWpostinstall file manipulation 5
doc/NppAIAssistant/README.mddoc/NppAIAssistant/SECURITY_VERIFICATION.mddoc/NppAIAssistant/SECURITY_REMEDIATION.md +2 more
-
LOWpostinstall obfuscation 1
doc/NppAIAssistant/SECURITY_REMEDIATION.md
-
LOWpostinstall network communication 4
doc/NppAIAssistant/README.mddoc/NppAIAssistant/USAGE.mddoc/NppAIAssistant/DEVELOPMENT_LOG.md +1 more
-
LOWpostinstall system command 7
doc/NppAIAssistant/README.mddoc/NppAIAssistant/README_zh-TW.mddoc/NppAIAssistant/SECURITY_VERIFICATION.md +4 more
-
LOWpostinstall file download 4
doc/NppAIAssistant/README.mddoc/NppAIAssistant/SECURITY_REMEDIATION.mddoc/NppAIAssistant/README_zh-TW.md +1 more
-

Network Indicators

Concrete URLs, domains, IPs, emails, and hashes extracted from the analyzed artifact.

13 total
...

Network indicators are queued for lazy loading

Scroll this section into view to load the detailed rows.

Finding Categories

1
Obfuscation
13
IoC Indicators

YARA Rules Matched

6 rules(22 hits)
postinstall crypto operations postinstall file manipulation postinstall obfuscation postinstall network communication postinstall system command postinstall file download

AI Security Report

AI Security Review

Evidence context: threat category supply chain; evidence quality moderate.

NppAIAssistant is described as a lightweight Notepad++ assistant with visible prompts and single-turn behavior, while NppAIAssistant.dll:0 identifies the delivered component as a native DLL. A native Notepad++ DLL runs inside the editor process and therefore has access to the privileges available to that process. That access is consistent with an assistant that must receive editor text and return a response, yet OBFUSCATION-supply_chain_binary adds a separate concern because the scanner could not readily inspect the DLL’s code. The finding title specifically classifies the issue as supply-chain binary obfuscation, and its severity is critical. [NppAIAssistant.dll:0] [OBFUSCATION-supply_chain_binary]

The supplied metadata declares no host permissions and lists no explicit permission strings. [NppAIAssistant.dll:0] The endpoint list includes free.fr, fsf.org, www.gnu.org, and names such as install-npp-ai-plugin.ps, package-npp-ai-plugin.ps, and verify-security-regressions.ps. [NppAIAssistant.dll:0] Those names do not establish that the DLL sends user text or downloads code, and the network category contains no direct network-behavior finding. [NppAIAssistant.dll:0] They do make provenance and installation behavior worth checking because script-like names are unrelated to the stated single-turn assistant function. [OBFUSCATION-supply_chain_binary]

Credential access is not shown as targeting real secrets. The supplied findings contain no secret finding and no title naming .env, .ssh, cloud credential files, editor secret storage, or credential providers. [NppAIAssistant.dll:0] The available evidence therefore does not support a credential-theft conclusion. The same limitation applies to source-code exfiltration: no finding identifies workspace reads joined to an external request, and the listed endpoints alone do not prove that behavior. [NppAIAssistant.dll:0]

The strongest counterargument is that OBFUSCATION-supply_chain_binary can result from ordinary compiled native code, while a Notepad++ assistant reasonably needs native execution inside the editor. [OBFUSCATION-supply_chain_binary] That argument reduces confidence in malicious intent, yet it does not clear the finding because NppAIAssistant.dll:0 provides no readable implementation detail and the publisher has zero recorded users in the supplied metadata. [NppAIAssistant.dll:0] JavaScript bundle noise rules do not explain a critical finding attached directly to a native DLL. [OBFUSCATION-supply_chain_binary] Runtime tracing should confirm whether the DLL reads files beyond the active document, starts child processes, contacts the listed domains, or alters Notepad++ files. Until those behaviors are checked, the correct public assessment is an unresolved supply-chain concern rather than a malware determination. [NppAIAssistant.dll:0]

Key Reasons

  • OBFUSCATION-supply_chain_binary is a critical finding attached directly to the native NppAIAssistant.dll:0.
  • A native Notepad++ DLL runs with the editor process's privileges, giving the plugin broad host access even though no permission strings are declared.
  • The listed endpoints include free.fr, fsf.org, www.gnu.org, and script-like names such as install-npp-ai-plugin.ps, which require provenance checks.
  • No supplied finding identifies .env, .ssh, cloud credentials, secret storage, document exfiltration, or a malware signature.

False Positive Considerations

  • Native compiled DLLs can trigger binary obfuscation heuristics without malicious intent.
  • The supplied metadata contains no direct network-behavior finding despite listing several endpoints.
  • No malware-signature or credential-access finding is present.
  • The extension's stated single-turn assistant function can justify access to the active Notepad++ document.

Reviewed 2026-09-29; recommended action: runtime analysis; model confidence 76%.

Notepad++ version history

Risk trend by version

2 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.

Selected
63
Change since first
No change
Change from previous
No change
Versions:
First analyzed version
0.1.0.0
Apr 18, 2026
Risk range
63 to 63
Across analyzed versions
Latest analyzed version
0.2.0.6
Sep 28, 2026
Selected version
medium
Version
v0.2.0.6
3 days ago
Risk score
63
Findings
44
Change vs previous
0

Pick any point on the chart to explore that version's code below.

Frequently Asked Questions