BackpackSecurity Analysis

Chromev0.10.190MV3February 18, 2026 at 09:27 AM
Potentially unsafe

This extension shows concerning patterns that may indicate risky behavior. Proceed with caution.

7.2HIGH
7.2 HIGHRaw: 8.0

This extension shows significant risk signals. Review the findings below carefully before installing or continuing to use it.

Based on 9 permissions including high-risk ones, 193 code findings, 1 dangerous combination.

Trust Signals(3.5/10)

Users
400K
Rating
4.3(367 reviews)

Dangerous Combinations(1)

CRITICALAll-sites access + keyboard capture

Extension has access to all sites and captures keyboard input — behavior consistent with a keylogger.

<all_urls>+keylogger_pattern
Permissions
7.0/10
Code
8.2/10
Combinations
10.0/10
Manifest/CSP
7.0/10

Permissions(9 analyzed)

Code Findings(31 patterns, 193 total)

Libraries(2 detected)

2 libraries detected

Content Security Policy

No CSP Defined(1 issue)
MEDIUM
N/ANo CSP defined

This extension does not define a Content Security Policy. A CSP helps prevent XSS and code injection attacks.

Manifest Analysis(4 findings)

HIGH
web_accessible_resourcesJS files exposed to web pages

JavaScript files are accessible to ALL websites. Any page can load and interact with these scripts, enabling web→extension attacks.

MEDIUM
web_accessible_resources.matchesOverly broad match patterns

Web-accessible resources use <all_urls> or wildcard patterns, exposing resources to every website.

MEDIUM
content_scriptsContent script injected on all URLs

Content script matches <all_urls>, executing on every website the user visits.

HIGH
content_scriptsAggressive content script injection

Content script runs at document_start in ALL frames on ALL URLs. This gives the extension deep access to every page load, including iframes.

External Domains(335)

${${e${f${t${{mainnet0x.xnfts.dev127.0.0.1aave-campaign.workers.madlads.comaccounts.google.comaddons.mozilla.orgaftermath.financeairtable-proxy.workers.madlads.comalfajores-forno.celo-testnet.orgalgorand.coin.ledger.comapi.apr.devapi.avax-test.networkapi.axelarscan.ioapi.covalenthq.comapi.devnet.aptoslabs.comapi.devnet.solana.comapi.helius.xyzapi.hyperliquid-testnet.xyzapi.mainnet-beta.solana.comapi.mainnet.aptoslabs.comapi.mainnet.hiro.soapi.moonpay.comapi.testnet.aptoslabs.comapi.testnet.hiro.soapi.testnet.solana.comapi.testnet.sonic.gameapi.testnet.wormholescan.ioapi.wormholescan.ioapp.hyperliquid.xyzaptos.devarb1.arbitrum.ioarbiscan.ioarweave.netassets.coingecko.comavalanche-c-chain-rpc.publicnode.comaxelarscan.iobackpack-api.xnfts.devbackpack-shared-assets.s3.us-east-1.amazonaws.combackpack.appbackpack.exchangebasescan.orgbepolia.rpc.berachain.comberatrail.ioberlin.net.solidwallet.iobit.lyblockaid.xnftdata.comblockchain.infobpsol.s3.us-west-1.amazonaws.combsc-rpc.publicnode.combscscan.combundles.jito.wtfbuy.api.live.ledger.comcardano.coin.ledger.comcasper.coin.ledger.comcdn.live.ledger-stg.comcdn.live.ledger.comcelestia-rpc.polkachu.comcelo.coin.ledger.comcloud-sync-backend.api.aws.stg.ldg-tech.comcloud-sync.api.live.ledger.comcloudflare-ipfs.comcoin-images.coingecko.comcommonmark.orgconnect.trezor.iocosmos-rpc.publicnode.comcountervalues.live.ledger.comcreditcoin-testnet.blockscout.comcreditcoin.blockscout.comcronos-pos.orgcrypto-assets-service.api.ledger.comcryptoorg-rpc-indexer.coin.ledger.comcryptoorg-rpc-node.coin.ledger.comdata-seed-prebsc-1-s3.binance.orgdelegations-elrond.coin.ledger.comdev.apollodata.comdev.suite.sldev.czdev.todevnet.aftermath.financedevnet.helius-rpc.comdevnet.sonic.gamedevnet.suivision.xyzdiscord.ggdocs.swmansion.comdymension-rpc.polkachu.comearn.api.live.ledger.comeclipsescan.xyzeips.ethereum.orgelrond.coin.ledger.comen.wikipedia.orgeth-devneteth-devnet2ethereum-rpc.publicnode.comethereum-sepolia.publicnode.cometherscan.ioethstats.neteu.backpack.exchangeeu.backpack.xn--exchange(-e65seu.backpack.xn--exchange(http-qo1u978by11ueu.support.backpack.exchangeevm-rpc-testnet.sei-apis.comevm-rpc.sei-apis.comevmos-rpc.polkachu.comevmos-testnet-rpc.polkachu.comexecutor-testnet.labsapis.comexecutor.labsapis.comexplorer-api.mayan.financeexplorer-sepolia.inkonchain.comexplorer.aptoslabs.comexplorer.celo.orgexplorer.hiro.soexplorer.inkonchain.comexplorer.jito.wtfexplorer.mayan.financeexplorer.mezo.orgexplorer.plume.orgexplorer.solana.comexplorer.sonic.gameexplorer.sui.ioexplorer.test.mezo.orgexplorer.testnet.xrplevm.orgexplorer.xrplevm.orgexplorers.api-01.live.ledger-stg.comexplorers.api.live.ledger.comfaucet.devnet.aptoslabs.comfb.mefeature-gates.workers.madlads.comfilecoin.coin.ledger.comfogoscan.comforno.celo.orgftmscan.comftxeurope.eufullnode.devnet.sui.iofullnode.mainnet.aptoslabs.comfullnode.mainnet.sui.iofullnode.testnet.aptoslabs.comfullnode.testnet.sui.iogasstation-testnet.polygon.technologygasstation.polygon.technologygateway.ipfs.iogateway.testnet.xlabs.xyzgfx.relayers.xlabs.xyzgithub.comgo.apollo.devgoerli.etherscan.iographql.mainnet.sui.iographql.testnet.sui.ioguardianhedera.coin.ledger.comhyperevmscan.ioicon.coin.ledger.comicp.coin.ledger.comimageresizer.xnftdata.comiris-api-sandbox.circle.comiris-api.circle.comjito.workers.madlads.comjsonrpc-mezo.boar.networkjupiter.xnfts.devkeyst.onekovan-testnet.github.ioledger.statuspage.iolifi.workers.madlads.comlinear-proxy.workers.madlads.comlinks.ethers.orglive-app-catalog.ledger.comlocalhostmadlads-merch.s3.us-east-2.amazonaws.commainnet-api.algonode.cloudmainnet.base.orgmainnet.block-engine.jito.wtfmainnet.fogo.iomainnet.helius-rpc.commainnet.optimism.iomainnet.unichain.orgmainnet3.creditcoin.networkmanager.api.live.ledger.commapping-service.api.ledger.commegaeth-testnet-v2.blockscout.commegaeth.blockscout.commempool.spacemonad-staking-proxy.backpack.workers.devmonad.socialscan.iomonadexplorer.commonadvision.commoonbase.moonscan.iomoonbeam-rpc.publicnode.commoonpay-signer.workers.madlads.commoonscan.iomulti-aged-mansion.btc.quiknode.promumbai.polygonscan.comneutron-rpc.polkachu.comnft.api.live.ledger.comnoble-rpc.polkachu.comnoble-testnet-rpc.polkachu.comopensea.iooptimistic.etherscan.ioorbmarkets.ioosmosis-rpc.polkachu.companora-proxy.workers.madlads.complasmascan.topolkadot-fullnodes.api.live.ledger.compolkadot-sidecar.coin.ledger.compolkadot.coin.ledger.compolygon-bor-rpc.publicnode.compolygonscan.comprice-api.mayan.financeprice-indexer.workers.madlads.comproxycg.api.live.ledger.compublic-en-kairos.node.kaia.iopublic-en.node.kaia.ioqr.xnfts.devreact.devreactnavigation.orgreactrouter.comredux-toolkit.js.orgredux.js.orgrelayer-api.mayan.financerpc-amoy.polygon.technologyrpc-converge-testnet-1.t.conduit.xyzrpc-qnd-sepolia.inkonchain.comrpc-qnd.inkonchain.comrpc-testnet-croeseid-4.crypto.orgrpc.ankr.comrpc.api.moonbase.moonbeam.networkrpc.berachain.comrpc.blaze.soniclabs.comrpc.cc3-testnet.creditcoin.networkrpc.hyperliquid.xyzrpc.linea.buildrpc.mainnet.sui.iorpc.mantle.xyzrpc.mocachain.orgrpc.monad.xyzrpc.plasma.torpc.plume.orgrpc.provenance.iorpc.sentry-02.theta-testnet.polypore.xyzrpc.sepolia.linea.buildrpc.soniclabs.comrpc.test.mezo.orgrpc.testnet.fantom.networkrpc.testnet.mantle.xyzrpc.testnet.osmosis.zonerpc.testnet.xrplevm.orgrpc.xrplevm.orgrpcapi.fantom.networkscan.li.fiscan.mocachain.orgscroll-rpc.publicnode.comscroll-sepolia-rpc.publicnode.comsei-rpc.polkachu.comsei-testnet-rpc.polkachu.comsei.explorers.guruseiscan.iosentry.tm.injective.networksepolia-rollup.arbitrum.iosepolia.base.orgsepolia.etherscan.iosepolia.optimism.iosepolia.unichain.orgshasta.tronscan.orgsimplehash.api.live.ledger.comsnowtrace.iosolana-api.projectserum.comsolana-devnetsolana.coin.ledger.comsolana.fmsolanabeach.iosolanapay.comsolscan.iostacks.coin.ledger.comstaging-connect.trezor.iostaging-rpc.dev2.eclipsenetwork.xyzstaking.${nstaking.xnfts.devstargaze-rpc.polkachu.comstellar.coin.ledger.comsui-mainnet.mystenlabs.comsuite.corp.sldev.czsuivision.xyzsupport.backpack.exchangeswap.ledger.comswr.xnftdata.comtestnet-api.algonode.cloudtestnet-explorer-api.mayan.financetestnet-explorer.plume.orgtestnet-ledger.cardanoscan.iotestnet-price-api.mayan.financetestnet-relayer-api.mayan.financetestnet-rpc.mocachain.orgtestnet-rpc.monad.xyztestnet-rpc.plasma.totestnet-rpc.plume.orgtestnet-scan.mocachain.orgtestnet.aftermath.financetestnet.api.axelarscan.iotestnet.axelarscan.iotestnet.bscscan.comtestnet.dev2.eclipsenetwork.xyztestnet.fogo.iotestnet.ftmscan.comtestnet.monadvision.comtestnet.plasmascan.totestnet.sentry.tm.injective.networktestnet.snowtrace.iotestnet.suivision.xyztestrpc.xlayer.techtezos-bakers.api.live.ledger.comtracker.berlin.icon.communitytrashscan.iotron.coin.ledger.comtronscan.orgtrustchain-backend.api.aws.stg.ldg-tech.comtrustchain.api.live.ledger.comvalidators-solana.coin.ledger.comvechain.coin.ledger.comworldchain-mainnet.g.alchemy.comworldchain-sepolia.g.alchemy.comwormchain-rpc.quickapi.comwormholescan.iowww.apollographql.comwww.ftx.comwww.hyperscan.comwww.rinkeby.iowww.tensor.tradex.comxlayerrpc.okx.comxnft.ggxray.helius.xyzxtz-explorer.api.live.ledger.comxtz-node.api.live.ledger.comxtz-tzkt-explorer.api.live.ledger.com

Indicators of Compromise

13850 indicators of compromise found

File Statistics

259
Total Files
83
JS Files
47.5 MB
Total Size

Other Scanned Extensions