Kubernetes by Red Hat
The AI review rates the findings as likely false positive, but the risk score (48/100) still counts them.
No individual score drivers were recorded for this analysis.
Analysis record
- Analysed
- 3 days ago
- Version
- v1.7.0.11
- Artifact
- SHA256 46C…47E
- Source
- Findings (non-IoC)
Is Kubernetes by Red Hat safe?
Kubernetes by Red Hat is a JetBrains plugin from Red Hat, used by around 104,000 people, that connects your IDE to Kubernetes clusters so you can browse workloads, edit manifests and apply changes without leaving the editor. This extension declares no special permissions. The strings flagged as network endpoints, things like 1kb5.pub and 8ugfx.wf, are not addresses the plugin contacts.
Nothing in the scan looks like malware. There are no malicious payload signatures, no obfuscated code and no stolen secrets. What the scan produced instead was hundreds of domain-shaped strings, including one recorded as XIOC-DOMAIN-φ.pk. If a plugin really reached out to a changing list of throwaway domains, that would be a serious sign of command-and-control traffic. The giveaway is the shape of the strings. Real command-and-control domains appear next to code that builds web requests. These come from the file listing extracted_from_files, with no code attached, and several contain characters that cannot exist in a real hostname.
A plugin that talks to Kubernetes does hold real power. It reads kubeconfig files, which can contain cluster credentials, and it can change running infrastructure. That is the normal scope of this kind of tool, and the scan found no sign it does anything outside it. The scanner tripped on substrings inside bundled library code, where ordinary variable names and byte sequences look like domains to a pattern matcher. That is a scanner problem, not plugin behaviour.
Evidence ledger
Ranked by severity · findings with a source location link to the code viewer
Publisher Evidence
LowRed-Hat
Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.
11 evidence rows available.
Finding Categories
AI Security Report
AI Security Review
Evidence context: threat category none; evidence quality moderate.
Kubernetes by Red Hat version 1.7.0.11 is a JetBrains Marketplace plugin published by Red Hat with roughly 104,000 installs. Its stated job is to talk to Kubernetes clusters from inside the IDE: browsing workloads, editing manifests, applying them. A tool like that needs to read workspace files and drive cluster tooling. Nothing in the scan contradicts that picture.
Every one of the 499 domain findings carries the file path extracted_from_files, meaning the extractor could not tie a single one to a line of code. Look at what it captured: XIOC-DOMAIN-1kb5.pub, XIOC-DOMAIN-e2i.mw, XIOC-DOMAIN-x7.ie, XIOC-DOMAIN-φ.pk, XIOC-DOMAIN-ߵ.mt. These are two-label fragments, several containing characters (φ, ϭ, ߵ, ߒ) that cannot appear in a registered hostname. The same strings appear in the network endpoint list as 0s.bv, 2k.bz, 9ϒ0.tw. They are substrings lifted out of minified JavaScript, where ordinary property chains and byte sequences look domain-shaped to a regex. A plugin that genuinely phoned home to a rotating roster of throwaway two-letter TLDs would need request-building logic somewhere. The scan shows zero network findings, zero malware signatures and zero obfuscation findings.
On filesystem and process access: this bundle carries no declared permission strings and no manifest-analysis findings, so nothing shows scope beyond the plugin's purpose. A Kubernetes client legitimately reads YAML manifests in the open workspace and reads ~/.kube/config, and it shells out to cluster tooling. Reading and writing workspace files is what the plugin is for.
On credentials: there are no credential-access findings at all. Nothing targets .env, .ssh, .git/config, cloud credential files or IDE secret storage. The 170 low-severity items are code-smell rule matches, the class of YARA rule that fires on any non-trivial JavaScript because it greps for fetch, exec, fs and process.env as bare strings. Nothing pairs a credential read with a network write.
The strongest argument against this verdict is volume: 758 findings, 499 of them medium, inside a plugin with cluster-level reach. The number of hits reflects how the scanner works, not what the plugin does. Every medium finding is a scanner-extracted domain string with no source location and no accompanying code, and the name, publisher, install base and version string match a first-party Red Hat product rather than a lookalike listing.
Key Reasons
- All 499 medium-severity domain hits are labelled extracted_from_files, with no source location and no accompanying request-building code
- The flagged domains include impossible hostnames such as XIOC-DOMAIN-φ.pk and XIOC-DOMAIN-ߵ.mt, which match on minified JavaScript fragments rather than real endpoints
- Zero malware-signature, network, obfuscation, secret and tool-poisoning findings across 758 total items
- No credential-access findings targeting .env, .ssh, .git/config or IDE secret storage
- Publisher Red Hat, 103,951 installs and version 1.7.0.11 match a first-party JetBrains Marketplace listing, not a typosquat
False Positive Considerations
- XIOC domain extraction matching short non-ASCII substrings inside bundled/minified JavaScript
- Code-smell YARA rules (170 low-severity matches) firing on generic Node.js patterns like fetch, exec, fs and process.env
- Finding-count inflation from bundled dependencies, where hundreds of library files each yield extractor hits
- Security scanners' default weighting of IoC volume over IoC plausibility
Reviewed 2026-09-30; recommended action: suppress false positive; model confidence 90%.
About This Extension
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace
Migration Toolkit for Runtimes (MTR) by Red Hat
Red-Hat
Migration Toolkit for Applications (MTA) by Red Hat
Red-Hat
OpenShift Dev Spaces
Red-Hat
Red Hat OpenShift Dev Spaces
Red-Hat
LSP4IJ
Red-Hat
Red Hat Dependency Analytics
Red-Hat