JetBrains Marketplace

HDPro-Tools

ee8deb81-2492-5b69-824f-e7f089bc5400 | v1.1.4
69/ 100
HIGH risk
-12 since v1.1.3
Analyst verdict
Review before use

The AI review rates the findings as likely false positive, but the risk score (69/100) still counts them.

Analysis record

Analysed
6 days ago
Version
v1.1.4
Artifact
SHA256 BF9…784
Source
Findings (non-IoC)

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

84 detail rows
Showing 25 of 83 · highest severity first

YARA Rule Matches

1 rule
SeverityRuleHitsFilesMetadata
HIGHCAP HookExKeylogger 1
plugins/lib/jna-platform-5.6.0.jar
Brian C. Bell -- @biebsmalwareguy FP 5%

Publisher Evidence

Limited evidence

25a61557-85e1-4535-8ceb-f250781c2395

Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.

24
Noisy-finding weight
x1.00
Publisher domain
No domain
Missing
Store verification signal
Not exposed
Not exposed
Extension portfolio
1
Portfolio

13 evidence rows available.

Finding Categories

1
Malware Signatures

YARA Rules Matched

1 rule
CAP HookExKeylogger

AI Security Report

AI Security Review

Risky Plugins reviewed this extension with an AI-assisted security workflow on 2026-09-06. The review verdict is likely false positive with 85% confidence.

Recommended action: suppress false positive. Evidence context: threat category none; evidence quality weak.

HDPro-Tools is a JetBrains plugin from developer ruaconytl with 383 users. The available findings show no signs of malicious behavior. No manifest-analysis findings were reported, so there is no evidence of excessive filesystem or process permissions. The extension's stated purpose is not provided. The available data does not include a description of what the plugin does. The absence of any secret, network, or obfuscation findings means no credential access or exfiltration patterns were detected.

The secret category contains no findings at all. No findings target .env files, SSH keys, or cloud credentials. A single malware-signature match stands as the only high-severity item. The available data omits its title and description. No malware, network, or tool-poisoning findings accompany it. Given 783 IoC findings that are all false positives, this lone signature matches the pattern of a broad YARA rule firing on generic code.

The 12 listed IoC titles all result from the XIOC extractor misreading file names and property chains as domains. Examples include "tlbinterface.java", "message.properties", "macfileutils.java", "version.java", and "winsvc.java". The extractor treats these Java source file names as domains. The same extractor behavior produces the short random strings "j0o.hm", "f.ie", "kkx.gd", "z8.py", "x.ir", "ț.fj", and "b.mk". These strings consist of short random values. They match the known false-positive pattern of hex substrings and property access chains in minified or bundled code. The extractor mistakes file extensions and property names for domain labels. This pattern recurs in false positives. None of these represent real, non-generic suspicious domains.

The 161 low-severity code-smell findings fit the expected profile for any non-trivial Java/Kotlin plugin. They do not indicate malicious intent. They typically fire on common patterns like file I/O, process spawning, or string manipulation. Those patterns are normal for development tools. The findings do not point to a specific malicious action.

The strongest counterargument focuses on the single high-severity malware-signature match. Without a specific file path or rule name, and isolated among 783 false-positive IoCs and 161 code-smell findings, that match does not outweigh the absence of any network, secret, or obfuscation evidence. A real malicious plugin would typically show network calls to suspicious domains, credential access, or obfuscated payloads. None of those are present. That absence is decisive. The single match lacks the supporting evidence needed to treat it as a real threat.

The findings are consistent with a standard JetBrains plugin whose bundled or generated code triggers noisy extractors. No specific malicious behavior is demonstrated. The plugin shows no credential access, no network exfiltration, and no obfuscated payload.

Key Reasons

  • All 12 listed IoC titles are false positives: file names like tlbinterface.java and message.properties misread as domains, and short random strings like j0o.hm and f.ie match known XIOC extractor noise.
  • No secret, network, or obfuscation findings were reported, so there is no evidence of credential theft or data exfiltration.
  • The single high-severity malware-signature match is isolated and lacks a specific file path or rule name, making it consistent with a broad YARA false positive.
  • 161 low-severity code-smell findings are expected in bundled or generated Java/Kotlin code and do not indicate malicious behavior.
  • No manifest-analysis findings show excessive filesystem or process permissions beyond what a JetBrains tool plugin normally requires.

False Positive Considerations

  • XIOC extractor misreading Java file names and property access chains as domains
  • Short random TLD strings (j0o.hm, f.ie, kkx.gd) matching hex/property-chain noise
  • Broad YARA malware-signature rule firing on generic code without supporting network/secret evidence
  • Code-smell rules on bundled or generated plugin code

JetBrains version history

Risk trend by version

2 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.

Selected
69
Change since first
-12
Change from previous
-12
Versions:
First analyzed version
1.1.3
Apr 5, 2026
Risk range
69 to 81
Across analyzed versions
Latest analyzed version
1.1.4
Apr 23, 2026
Selected version
high
Version
v1.1.4
5 months ago
Risk score
69
Findings
84
Change vs previous
-12

Pick any point on the chart to explore that version's code below.

About This Extension

Ruacon Tools - Image Optimizer & TranslatorA lightweight plugin for Android Studio that helps you work more efficiently with images and translations:Image...

Frequently Asked Questions