This extension shows concerning patterns that may indicate risky behavior. Proceed with caution.
Compromised in Cyberhaven supply chain attack
Extension was among 35+ extensions compromised in the December 2024 supply chain attack campaign that injected data-stealing code.
This extension shows significant risk signals. Review the findings below carefully before installing or continuing to use it.
Based on 19 permissions including high-risk ones, 202 code findings, 3 dangerous combinations.
Extension uses tab tracking APIs (onUpdated/query) and communicates with external servers — potential browsing surveillance.
Extension intercepts network traffic and sends data externally — potential man-in-the-middle behavior.
Extension has access to all sites and captures keyboard input — behavior consistent with a keylogger.
5 libraries detected, 5 with known vulnerabilities
object-src is not set to 'none'. Plugins like Flash can be embedded, which may allow code execution.
JavaScript files are exposed as web-accessible resources. Matched websites can load and interact with extension scripts.
50 indicators of compromise found