This extension shows concerning patterns that may indicate risky behavior. Proceed with caution.
Compromised in Cyberhaven supply chain attack
Extension was among 35+ extensions compromised in the December 2024 supply chain attack campaign that injected data-stealing code.
This extension shows significant risk signals. Review the findings below carefully before installing or continuing to use it.
Based on 6 permissions including high-risk ones, 27 code findings, 2 dangerous combinations.
Extension has cookie access and sends data to external servers — potential session token theft.
Extension uses tab tracking APIs (onUpdated/query) and communicates with external servers — potential browsing surveillance.
3 libraries detected
object-src is not set to 'none'. Plugins like Flash can be embedded, which may allow code execution.
Resolved from __MSG_* i18n placeholders:
Name: TinaMind - The most powerful AI Assistant!
Description: Your AI Assistant powered by AI models. Chat, YouTube summary, search, write, TTS, OCR and more.
Web-accessible resources use <all_urls> or wildcard patterns, exposing resources to every website.
Web-accessible resources use <all_urls> or wildcard patterns, exposing resources to every website.
Web-accessible resources use <all_urls> or wildcard patterns, exposing resources to every website.
Extension accepts messages from 1 external pattern(s). Verify these are trusted origins.
Content script matches <all_urls>, executing on every website the user visits.
374 indicators of compromise found