This extension shows concerning patterns that may indicate risky behavior. Proceed with caution.
Compromised in Cyberhaven supply chain attack
Extension was among 35+ extensions compromised in the December 2024 supply chain attack campaign that injected data-stealing code.
This extension shows significant risk signals. Review the findings below carefully before installing or continuing to use it.
Based on 24 permissions including high-risk ones, 64 code findings, 2 dangerous combinations.
Extension uses chrome.cookies.getAll for bulk cookie access and sends data to external servers — high risk of session token theft.
Extension has access to all sites and captures keyboard input — behavior consistent with a keylogger.
2 libraries detected
object-src is not set to 'none'. Plugins like Flash can be embedded, which may allow code execution.
Resolved from __MSG_* i18n placeholders:
Name: Vidnoz Flex - Video recorder & Video share
Description: Easily record your screen and webcam, share your video with a link anytime, and track video performance timely.
Extension accepts messages from 2 external pattern(s). Verify these are trusted origins.
9 indicators of compromise found