JetBrains Marketplace Verified

Kubernetes by Red Hat

by Red-Hat · 104.0K users · 2.7 rating
fc04d298-29a4-59f4-b924-e294b6f68b93 | v1.7.0.11
48/ 100
MEDIUM risk
Analyst verdict
Review before use

The AI review rates the findings as likely false positive, but the risk score (48/100) still counts them.

No individual score drivers were recorded for this analysis.

Analysis record

Analysed
3 days ago
Version
v1.7.0.11
Artifact
SHA256 46C…47E
Source
Findings (non-IoC)

Is Kubernetes by Red Hat safe?

Kubernetes by Red Hat is a JetBrains plugin from Red Hat, used by around 104,000 people, that connects your IDE to Kubernetes clusters so you can browse workloads, edit manifests and apply changes without leaving the editor. This extension declares no special permissions. The strings flagged as network endpoints, things like 1kb5.pub and 8ugfx.wf, are not addresses the plugin contacts.

Nothing in the scan looks like malware. There are no malicious payload signatures, no obfuscated code and no stolen secrets. What the scan produced instead was hundreds of domain-shaped strings, including one recorded as XIOC-DOMAIN-φ.pk. If a plugin really reached out to a changing list of throwaway domains, that would be a serious sign of command-and-control traffic. The giveaway is the shape of the strings. Real command-and-control domains appear next to code that builds web requests. These come from the file listing extracted_from_files, with no code attached, and several contain characters that cannot exist in a real hostname.

A plugin that talks to Kubernetes does hold real power. It reads kubeconfig files, which can contain cluster credentials, and it can change running infrastructure. That is the normal scope of this kind of tool, and the scan found no sign it does anything outside it. The scanner tripped on substrings inside bundled library code, where ordinary variable names and byte sequences look like domains to a pattern matcher. That is a scanner problem, not plugin behaviour.

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

89 detail rows
Showing 25 of 89 · highest severity first

Publisher Evidence

Low

Red-Hat

Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.

97
Noisy-finding weight
x1.00
Publisher domain
redhat.com
Observed
Store verification signal
Verified publisher
Verified
Extension portfolio
64
Portfolio

11 evidence rows available.

Finding Categories

AI Security Report

AI Security Review

Evidence context: threat category none; evidence quality moderate.

Kubernetes by Red Hat version 1.7.0.11 is a JetBrains Marketplace plugin published by Red Hat with roughly 104,000 installs. Its stated job is to talk to Kubernetes clusters from inside the IDE: browsing workloads, editing manifests, applying them. A tool like that needs to read workspace files and drive cluster tooling. Nothing in the scan contradicts that picture.

Every one of the 499 domain findings carries the file path extracted_from_files, meaning the extractor could not tie a single one to a line of code. Look at what it captured: XIOC-DOMAIN-1kb5.pub, XIOC-DOMAIN-e2i.mw, XIOC-DOMAIN-x7.ie, XIOC-DOMAIN-φ.pk, XIOC-DOMAIN-ߵ.mt. These are two-label fragments, several containing characters (φ, ϭ, ߵ, ߒ) that cannot appear in a registered hostname. The same strings appear in the network endpoint list as 0s.bv, 2k.bz, 9ϒ0.tw. They are substrings lifted out of minified JavaScript, where ordinary property chains and byte sequences look domain-shaped to a regex. A plugin that genuinely phoned home to a rotating roster of throwaway two-letter TLDs would need request-building logic somewhere. The scan shows zero network findings, zero malware signatures and zero obfuscation findings.

On filesystem and process access: this bundle carries no declared permission strings and no manifest-analysis findings, so nothing shows scope beyond the plugin's purpose. A Kubernetes client legitimately reads YAML manifests in the open workspace and reads ~/.kube/config, and it shells out to cluster tooling. Reading and writing workspace files is what the plugin is for.

On credentials: there are no credential-access findings at all. Nothing targets .env, .ssh, .git/config, cloud credential files or IDE secret storage. The 170 low-severity items are code-smell rule matches, the class of YARA rule that fires on any non-trivial JavaScript because it greps for fetch, exec, fs and process.env as bare strings. Nothing pairs a credential read with a network write.

The strongest argument against this verdict is volume: 758 findings, 499 of them medium, inside a plugin with cluster-level reach. The number of hits reflects how the scanner works, not what the plugin does. Every medium finding is a scanner-extracted domain string with no source location and no accompanying code, and the name, publisher, install base and version string match a first-party Red Hat product rather than a lookalike listing.

Key Reasons

  • All 499 medium-severity domain hits are labelled extracted_from_files, with no source location and no accompanying request-building code
  • The flagged domains include impossible hostnames such as XIOC-DOMAIN-φ.pk and XIOC-DOMAIN-ߵ.mt, which match on minified JavaScript fragments rather than real endpoints
  • Zero malware-signature, network, obfuscation, secret and tool-poisoning findings across 758 total items
  • No credential-access findings targeting .env, .ssh, .git/config or IDE secret storage
  • Publisher Red Hat, 103,951 installs and version 1.7.0.11 match a first-party JetBrains Marketplace listing, not a typosquat

False Positive Considerations

  • XIOC domain extraction matching short non-ASCII substrings inside bundled/minified JavaScript
  • Code-smell YARA rules (170 low-severity matches) firing on generic Node.js patterns like fetch, exec, fs and process.env
  • Finding-count inflation from bundled dependencies, where hundreds of library files each yield extractor hits
  • Security scanners' default weighting of IoC volume over IoC plausibility

Reviewed 2026-09-30; recommended action: suppress false positive; model confidence 90%.

About This Extension

A plugin for interacting with Kubernetes and OpenShift clusters. The plugin provides functionalities and user experiences that are very close to the Kubernetes...

Frequently Asked Questions