@microsoft/powerbi-modeling-mcp-linux-x64
From the RiskyPlugins AI security review of the observed evidence.
Analysis record
- Analysed
- 6 days ago
- Version
- v1.0.0
- Artifact
- SHA256 5D7…C50
- Source
- Findings (non-IoC)
Evidence ledger
Ranked by severity · findings with a source location link to the code viewer
YARA Rule Matches
14 rules| Severity | Rule | Hits | Files | Metadata |
|---|---|---|---|---|
| LOW | postinstall file download | 2 | dist/Resources/tools/tool-metadata.yamldist/powerbi-modeling-mcp | - |
| LOW | postinstall process injection | 1 | dist/powerbi-modeling-mcp | - |
| LOW | NoUseWeakRandom | 1 | dist/powerbi-modeling-mcp | - |
| LOW | DebuggerStatementsShouldNotBeUsed | 1 | dist/powerbi-modeling-mcp | - |
| LOW | UsingCommandLineArguments | 1 | index.js | - |
| LOW | postinstall crypto operations | 2 | NOTICE.txtdist/powerbi-modeling-mcp | - |
| LOW | postinstall system command | 7 | dist/powerbi-modeling-mcpdist/Resources/dax_udf_instructions_and_examples.mdindex.js +4 more | - |
| LOW | postinstall file manipulation | 5 | NOTICE.txtCHANGELOG.mddist/Resources/tools/tool-metadata.yaml +2 more | - |
| LOW | postinstall environment access | 2 | dist/Resources/tools/tool-metadata.yamlNOTICE.txt | - |
| LOW | postinstall registry modification | 1 | dist/powerbi-modeling-mcp | - |
| LOW | postinstall obfuscation | 5 | dist/Resources/dax_udf_instructions_and_examples.mdNOTICE.txtCHANGELOG.md +2 more | - |
| LOW | postinstall network communication | 5 | LICENSENOTICE.txtCHANGELOG.md +2 more | - |
| LOW | credential env files | 2 | index.jsdist/powerbi-modeling-mcp | - |
| LOW | postinstall persistence mechanism | 2 | CHANGELOG.mddist/powerbi-modeling-mcp | - |
Network Indicators
Concrete URLs, domains, IPs, emails, and hashes extracted from the analyzed artifact.
Network indicators are queued for lazy loading
Scroll this section into view to load the detailed rows.
Finding Categories
YARA Rules Matched
14 rules(37 hits)MCP Server Analysis
MCP servers expose tools and resources to AI assistants. Unlike browser extensions, they run as standalone processes with direct system access. Tool definitions are analyzed for prompt injection, data exfiltration, and tool poisoning patterns.
AI Security Report
AI Security Review
Evidence context: threat category supply chain; evidence quality moderate.
Tool Poisoning Analysis: No tool-poisoning findings were detected (0 findings in the tool-poisoning category). This package does not contain hidden AI manipulation directives in tool descriptions.
Credential/Network Access: No credential-access findings, network findings, or secret findings were detected. The evidence shows 0 findings for credential reads, network calls, or secret extraction. This is unusual for a package containing 649 domain IOCs—if these domains were actively used for C2 communication, network findings would be expected.
IOC Findings Analysis: The 649 IOC findings are all domain strings (XIOC-DOMAIN findings) including u.dk, ky.su, х.bt (Cyrillic character), cԣ.gl (Armenian character), yy.mt, zb.td, o.tz, 0.ma, dq.bi, f.bi, f.tz, s.vi. These domains exhibit classic DGA/C2 characteristics: short random strings, mixed scripts, and diverse TLDs. However, all findings show file_path as extracted_from_files without specific code locations, making it impossible to determine if these are actively called or merely embedded in bundled dependencies.
Developer Name Red Flag: The developer name is microsoft1es, not Microsoft. This is inconsistent with legitimate Microsoft publishing. While the package uses the @microsoft/ npm scope (which requires Microsoft ownership), the mismatch between scope and developer name is suspicious and warrants verification of whether Microsoft actually published this package.
Strongest Counterargument: The absence of network findings, credential-access findings, and code-smell findings suggests these domains may be embedded in bundled dependencies rather than actively used for malicious purposes. Pre-built binaries (indicated by -linux-x64 suffix) often contain numerous embedded strings from bundled libraries that trigger IOC extractors.
Why Counterargument Doesn't Resolve Concern: The combination of suspicious developer name (microsoft1es vs expected Microsoft) and 649 DGA-pattern domains is too concerning to dismiss. Manual binary analysis is required to determine if these domains are actively called or merely embedded.
Key Reasons
- Developer name 'microsoft1es' does not match expected Microsoft publishing patterns
- 649 domain IOCs with DGA/C2 characteristics (short random strings, mixed scripts)
- No network or credential findings to confirm active domain usage
- Pre-built binary format limits static analysis visibility
- No tool-poisoning or malware-signature findings detected
False Positive Considerations
- Bundled dependencies in pre-built binary may contain embedded domain strings
- IOC extractor may flag domain strings without confirming active network usage
- Pre-built binaries often contain numerous embedded strings from libraries
Reviewed 2026-04-27; recommended action: runtime analysis; model confidence 72%.
MCP version history
Risk trend by version
11 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.
Pick any point on the chart to explore that version's code below.
Source Code Not Available
Source code is not available for this version of the extension.
About This Extension
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace