This extension shows concerning patterns that may indicate risky behavior. Proceed with caution.
Compromised in Cyberhaven supply chain attack
Extension was among 35+ extensions compromised in the December 2024 supply chain attack campaign that injected data-stealing code.
This extension shows some risk signals that are common in legitimate extensions but worth reviewing. Check the details below.
Based on 5 permissions including high-risk ones, 36 code findings, 1 dangerous combination.
Extension has access to all sites and captures keyboard input — behavior consistent with a keylogger.
This extension does not define a Content Security Policy. A CSP helps prevent XSS and code injection attacks.
Resolved from __MSG_* i18n placeholders:
Name: Reader Mode - Natural Reader and dark mode
Description: Distraction-free chrome reader view extension and dark mode for Chrome.
Web-accessible resources use <all_urls> or wildcard patterns, exposing resources to every website.
Content script matches <all_urls>, executing on every website the user visits.
3 indicators of compromise found