CRX aminer
Extension icon

LeadhuntAI - Chrome Extension

Version 0.7.0.4 View in Chrome Web Store

Last scanned: about 3 hours ago

Extension Details

Rating: 4.4 ★ (13 ratings)
Users: 336

Context-Aware Verdict

CRITICAL
Overall Risk
Trust Factors: The extension has very limited trust indicators with only 336 users and 13 ratings, suggesting minimal market validation. The 4.4 rating is positive but based on an extremely small sample size. No clear developer information is provided, which raises transparency concerns. The extension appears to be a lead generation tool for LinkedIn, which is a legitimate business use case.
Concerns: The permission set is extremely excessive for a LinkedIn lead generation tool. The management permission is particularly alarming as it allows control over other extensions, which is rarely necessary for legitimate functionality. The combination of cookies, tabs, webNavigation, and broad host permissions creates a powerful surveillance capability that extends far beyond LinkedIn. The unlimitedStorage permission combined with extensive data access could enable large-scale data harvesting. The localhost permission suggests potential communication with local applications, adding another attack vector.
Recommendations: Do not install this extension in your primary browser profile due to the critical risk level. If you must use it, create a dedicated Chrome profile with minimal sensitive data and no other extensions installed. Consider alternative LinkedIn lead generation tools with more restrictive permissions. Before installation, verify the developer's identity and reputation through independent sources. Monitor your LinkedIn account closely for any unauthorized activity if you proceed with installation.

Findings

HIGH
Broad Host Permissions
This extension has broad host permissions allowing it to access many or all websites. This could potentially be used to steal sensitive data or track browsing activity.
HIGH
High-Risk Permission: cookies
This extension has the cookies permission. Can access and modify browser cookies. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: management
This extension has the management permission. Can manage other extensions. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: tabs
This extension has the tabs permission. Can access browser tab information and manipulate tabs. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: webNavigation
This extension has the webNavigation permission. Can track your web navigation. This could potentially be used maliciously to compromise security or privacy.
MEDIUM
Access to Sensitive Domains
This extension requests access to sensitive domains: *://*.linkedin.com/*. Ensure you trust this extension with access to these sites.
MEDIUM
Medium-Risk Permission: activeTab
This extension has the activeTab permission. Can access the active tab when clicking the extension icon.
MEDIUM
Medium-Risk Permission: contextMenus
This extension has the contextMenus permission. Can add items to the context menu.
MEDIUM
Medium-Risk Permission: notifications
This extension has the notifications permission. Can show notifications.
MEDIUM
Medium-Risk Permission: storage
This extension has the storage permission. Can store data locally.
MEDIUM
Medium-Risk Permission: unlimitedStorage
This extension has the unlimitedStorage permission. Can store unlimited data locally.