Migration Toolkit for Applications (MTA) by Red Hat
The AI review rates the findings as likely false positive, but the risk score (53/100) still counts them.
Analysis record
- Analysed
- 3 days ago
- Version
- v7.1.0.33486
- Artifact
- SHA256 41D…F41
- Source
- Findings (non-IoC)
Evidence ledger
Ranked by severity · findings with a source location link to the code viewer
YARA Rule Matches
11 rules| Severity | Rule | Hits | Files | Metadata |
|---|---|---|---|---|
| LOW | credential env files | 1 | org.jboss.tools.mta/lib/webroot/configuration-editor/lib/socket.io.js | - |
| LOW | postinstall persistence mechanism | 1 | org.jboss.tools.mta/lib/netty-common-4.1.49.Final.jar | - |
| LOW | SQLInjection | 1 | org.jboss.tools.mta/lib/webroot/configuration-editor/lib/jquery-3.3.1.min.js | - |
| LOW | NoUseWeakRandom | 2 | org.jboss.tools.mta/lib/webroot/configuration-editor/lib/socket.io.jsorg.jboss.tools.mta/lib/webroot/configuration-editor/lib/jquery-3.3.1.min.js | - |
| LOW | postinstall file download | 4 | org.jboss.tools.mta/lib/webroot/configuration-editor/views/body.htmlorg.jboss.tools.mta/lib/jackson-databind-2.12.4.jarorg.jboss.tools.mta/lib/webroot/configuration-editor/lib/configurationFrontendClient.js +1 more | - |
| LOW | postinstall crypto operations | 9 | org.jboss.tools.mta/lib/netty-codec-4.1.49.Final.jarorg.jboss.tools.mta/lib/webroot/configuration-editor/lib/jquery-3.3.1.min.jsorg.jboss.tools.mta/lib/webroot/configuration-editor/lib/socket.io.js +6 more | - |
| LOW | postinstall network communication | 20 | org.jboss.tools.mta/lib/vertx-core-3.9.4.jarorg.jboss.tools.mta/lib/netty-resolver-4.1.49.Final.jarorg.jboss.tools.mta/lib/org.eclipse.equinox.common-3.6.0.jar +17 more | - |
| LOW | postinstall file manipulation | 10 | org.jboss.tools.mta/lib/intellij-mta-7.1.0.33486.jarorg.jboss.tools.mta/lib/webroot/configuration-editor/views/unified.htmlorg.jboss.tools.mta/lib/org.eclipse.text-3.5.101.jar +7 more | - |
| LOW | postinstall system command | 16 | org.jboss.tools.mta/lib/webroot/dark/issue-details.cssorg.jboss.tools.mta/lib/vertx-core-3.9.4.jarorg.jboss.tools.mta/lib/webroot/configuration-editor/lib/socket.io.js +13 more | - |
| LOW | postinstall registry modification | 3 | org.jboss.tools.mta/lib/netty-transport-4.1.49.Final.jarorg.jboss.tools.mta/lib/netty-codec-http2-4.1.49.Final.jarorg.jboss.tools.mta/lib/org.eclipse.text-3.5.101.jar | - |
| LOW | postinstall obfuscation | 14 | org.jboss.tools.mta/lib/netty-codec-4.1.49.Final.jarorg.jboss.tools.mta/lib/jackson-core-2.12.4.jarorg.jboss.tools.mta/lib/vertx-web-3.9.4.jar +11 more | - |
Publisher Evidence
LowRed-Hat
Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.
11 evidence rows available.
Finding Categories
YARA Rules Matched
11 rules(81 hits)AI Security Report
AI Security Review
Evidence context: threat category none; evidence quality strong.
The Migration Toolkit for Applications (MTA) by Red Hat is a legitimate enterprise extension from a verified publisher on the JetBrains store with 4,515 users. All detected findings represent expected behavior for this type of application.
Filesystem and Process Access: The 76 metadata findings are hash identifiers for standard Java libraries in org.jboss.tools.mta/lib/ including commons-io-2.6.jar, jackson-annotations-2.12.4.jar, snakeyaml-1.27.jar, and hamcrest-core-1.3.jar. These are well-known, open-source dependencies used for configuration parsing and data processing—core functionality for a migration toolkit. There are zero findings indicating malicious filesystem access, credential theft, or unauthorized process execution.
Network Activity: The 7 medium-severity network findings are all jquery_ajax calls in org.jboss.tools.mta/lib/webroot/configuration-editor/lib/configurationFrontendClient.js at lines 17, 28, 39, 50, 63, 76, and 89. This is a configuration editor frontend client, and jQuery AJAX calls are the standard mechanism for web-based UIs to communicate with backend services. This pattern is entirely expected for a tool that provides a graphical configuration interface. There are zero findings for suspicious external domains, data exfiltration endpoints, or command-and-control infrastructure.
Credential and Secret Access: The findings summary shows zero secret findings and zero code-smell findings related to credentials. There is no evidence of the extension accessing .env files, SSH keys, cloud credentials, or VS Code/JetBrains secret storage. The extension does not require credential access for its stated purpose of application migration.
Strongest Counterargument: The 7 network findings could theoretically indicate data exfiltration. However, all calls are confined to a configuration editor frontend client making standard jQuery AJAX requests—this is how legitimate web UIs function. There are no findings for external suspicious domains, encoded payloads, or unusual data transfer patterns. The absence of malware signatures, obfuscation findings, or credential access findings further confirms benign behavior.
Conclusion: This extension from Red Hat exhibits no malicious characteristics. The findings are artifacts of standard library dependencies and expected web UI functionality. The extension's behavior aligns with its stated purpose as a migration toolkit, and all detected patterns are consistent with legitimate enterprise software development.
Key Reasons
- Verified publisher (Red Hat) with 4,515 users on JetBrains store
- All findings are standard library dependencies or expected web UI behavior
- Zero malware signatures, obfuscation, or credential access findings
- Network calls are jQuery AJAX in configuration editor frontend—expected behavior
- No suspicious external domains or exfiltration patterns detected
False Positive Considerations
- Metadata findings are hash identifiers for bundled JAR dependencies
- Network findings are standard jQuery AJAX calls in web UI component
- No malware signatures or obfuscation detected
- Verified publisher (Red Hat) on official JetBrains marketplace
Reviewed 2026-05-23; recommended action: no action; model confidence 92%.
About This Extension
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace