This extension requests significant permissions. It has 1M+ users, a 3.3 star rating, but review the findings below.
Compromised in Cyberhaven supply chain attack
Extension was among 35+ extensions compromised in the December 2024 supply chain attack campaign that injected data-stealing code.
This extension shows some risk signals that are common in legitimate extensions but worth reviewing. Check the details below.
Based on 2 permissions including high-risk ones, 37 code findings.
This extension does not define a Content Security Policy. A CSP helps prevent XSS and code injection attacks.
JavaScript files are accessible to ALL websites. Any page can load and interact with these scripts, enabling web→extension attacks.
Web-accessible resources use <all_urls> or wildcard patterns, exposing resources to every website.
17 indicators of compromise found