JetBrains Marketplace Verified

Spring Theme

by Codigrate · 36 users
f45b4d92-804f-5803-87c5-597d45436f5d | v2026.1.2
44/ 100
MEDIUM risk
No change since v2026.1.1
Analyst verdict
Review before use

The AI review rates the findings as likely false positive, but the risk score (44/100) still counts them.

Analysis record

Analysed
2 days ago
Version
v2026.1.2
Artifact
SHA256 230…247
Source
Findings (non-IoC)

Is Spring Theme safe?

Spring Theme is a visual styling package for JetBrains IDEs published by Codigrate. It changes how your editor looks. The extension declares no special permissions and requests no host access. The only network endpoints it references are codigrate.com and the official JetBrains plugin marketplace. You do not need to worry about it reading your files or running background tasks.

The scanner flagged 290 items under the indicator of compromise category. Look closely at the actual findings, though. They are just links to color swatches. One specific finding, titled XIOC-URL-https://codigrate.com/util/color/DDBE6D.png?width=18&height=18, points to a small image file on the developer's website. The tool extracted every URL string it found in the package and marked them as network indicators. It treated every single image link as a potential threat, which is exactly what happens when a scanner lacks context.

These flags do not mean the extension is stealing data. A theme package naturally includes links to preview images and documentation. The high number of alerts comes from the developer including a large palette of color swatches in their files. The scanner tripped on repetitive asset links. There are no malware signatures, no secret access attempts, and no hidden scripts. It is just a theme.

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

7 detail rows

YARA Rule Matches

2 rules
SeverityRuleHitsFilesMetadata
LOWpostinstall file manipulation 1
theme/spring.xml
-
LOWpostinstall system command 1
theme/spring.xml
-

Publisher Evidence

Low

Codigrate

Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.

82
Noisy-finding weight
x1.00
Publisher domain
codigrate.com
Observed
Store verification signal
Verified publisher
Verified
Extension portfolio
52
Portfolio

12 evidence rows available.

Finding Categories

YARA Rules Matched

2 rules
postinstall file manipulation postinstall system command

AI Security Report

AI Security Review

Evidence context: threat category none; evidence quality strong.

The "Spring Theme" extension for JetBrains, published by Codigrate, is a visual theme package. The scan contains 290 indicators of compromise, but every single one of them is a URL pointing to codigrate.com/util/color/ followed by a hex color code and a .png extension, such as XIOC-URL-https://codigrate.com/util/color/DDBE6D.png?width=18&height=18. These are color swatch images hosted on the developer's own website. A theme extension naturally references external assets for documentation, previews, or color palettes. The remaining network endpoint, plugins.jetbrains.com, is simply the official JetBrains marketplace page for the extension itself, referenced in the package metadata.

Filesystem and process access are completely absent. The extension declares no permissions and no host permissions. This aligns perfectly with its stated purpose. A theme only needs to inject styling rules into the IDE interface. It does not need to read source code, spawn processes, or access the underlying operating system. The lack of any filesystem access means the risk of source code exfiltration or local credential theft is zero.

Credential-access findings are also entirely absent. There are zero secret detections and zero manifest-analysis findings. The extension does not attempt to read .env files, SSH keys, or cloud configuration files. It does not interact with the IDE's secret storage. The two low-severity code-smell findings are generic noise that trigger on any non-trivial codebase and do not represent actual credential theft or malicious execution.

The strongest counterargument to a clean verdict is the sheer volume of the 290 medium-severity findings. A quick glance at the raw count might alarm a reviewer. However, looking at the actual content of those findings reveals they are just repetitive URLs for color swatches. The scanner extracted every single URL string it found in the extension package and flagged it as an indicator of compromise. Because the developer included a large palette of color images in their documentation or preview files, the extractor generated hundreds of matches. The count is simply a byproduct of how the scanner processes repetitive asset links. There are no connections to unknown command-and-control servers, no data exfiltration endpoints, and no postinstall scripts. The extension is exactly what it claims to be: a simple visual theme.

Key Reasons

  • All 290 indicators of compromise are URLs to color swatch images on the publisher's own domain
  • Extension declares no permissions and requests no host access
  • Zero malware signatures, secrets, or obfuscation findings
  • Network endpoints are limited to the publisher's website and the official JetBrains marketplace

False Positive Considerations

  • IoC extractor flagging repetitive asset URLs as network indicators
  • High finding count driven by bundled color palette images

Reviewed 2026-10-01; recommended action: suppress false positive; model confidence 95%.

JetBrains version history

Risk trend by version

3 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.

Selected
44
Change since first
No change
Change from previous
No change
Versions:
First analyzed version
2026.1.0
Sep 16, 2026
Risk range
44 to 44
Across analyzed versions
Latest analyzed version
2026.1.2
Sep 29, 2026
Selected version
medium
Version
v2026.1.2
2 days ago
Risk score
44
Findings
297
Change vs previous
0

Pick any point on the chart to explore that version's code below.

About This Extension

Inspired by a spring garden in full bloom, from tulip beds and crocus to the first new grass under a clear sky, this theme pairs airy mint and soft green backgrounds...

Frequently Asked Questions