This extension shows concerning patterns that may indicate risky behavior. Proceed with caution.
Compromised in Cyberhaven supply chain attack
Extension was among 35+ extensions compromised in the December 2024 supply chain attack campaign that injected data-stealing code.
This extension shows significant risk signals. Review the findings below carefully before installing or continuing to use it.
Based on 6 permissions including high-risk ones, 48 code findings, 1 dangerous combination.
Extension has access to all sites and captures keyboard input — behavior consistent with a keylogger.
2 libraries detected
This extension does not define a Content Security Policy. A CSP helps prevent XSS and code injection attacks.
Resolved from __MSG_* i18n placeholders:
Name: YesCaptcha assistant
Description: captcha assistant
JavaScript files are exposed as web-accessible resources. Matched websites can load and interact with extension scripts.
25 indicators of compromise found