CRX aminer
Extension icon

IMTLazarusv3

Version 24.0 View in Chrome Web Store

Last scanned: about 2 months ago | force re-scan

Extension Details

Rating: 1.2 ★ (381 ratings)
Users: 100,000

Context-Aware Verdict

CRITICAL
Overall Risk
Trust Factors:

The extension has a concerning trust profile with a very low rating of 1.2 out of 5 stars from 381 reviews, indicating widespread user dissatisfaction. Despite having 100,000 users, the poor rating suggests significant issues. The lack of clear author and developer information raises transparency concerns, making it difficult to assess the legitimacy of the extension's creators.

Concerns:

This extension exhibits extremely concerning behavior with excessive permissions that far exceed what would be reasonable for most legitimate purposes. The combination of webRequest and webRequestBlocking permissions allows complete interception and modification of all web traffic. The broad host permissions covering all websites, combined with content script injection capabilities, creates a perfect surveillance and data theft mechanism. The identity and management permissions could allow access to personal information and control over other extensions. The unsafe WebAssembly execution policy could hide malicious code. The extensive list of content scripts targeting major platforms like YouTube, Gmail, Teams, and various educational sites suggests potential data harvesting across critical services.

Recommendations:

Do not install this extension under any circumstances. The risk profile is too severe for safe use even in an isolated browser profile. If already installed, remove it immediately and consider changing passwords for any accounts accessed while the extension was active. Run a security scan on your system and monitor for any suspicious account activity. The combination of poor ratings, excessive permissions, and broad access capabilities strongly suggests malicious intent.

Findings

HIGH
Broad Content Script Injection
This extension can inject scripts into any website. This means it could potentially read sensitive data, modify website content, or steal credentials.
HIGH
Broad Host Permissions
This extension has broad host permissions allowing it to access many or all websites. This could potentially be used to steal sensitive data or track browsing activity.
HIGH
Dangerous Permission Combination: webRequest + webRequestBlocking
This extension can intercept, modify, and block web requests in real-time. This combination could be used to modify sensitive web traffic or steal data.
HIGH
High-Risk Permission: bookmarks
This extension has the bookmarks permission. Can access and modify bookmarks. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: identity
This extension has the identity permission. Can access your identity information. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: management
This extension has the management permission. Can manage other extensions. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: tabs
This extension has the tabs permission. Can access browser tab information and manipulate tabs. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: webNavigation
This extension has the webNavigation permission. Can track your web navigation. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: webRequest
This extension has the webRequest permission. Can intercept and modify web requests. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: webRequestBlocking
This extension has the webRequestBlocking permission. Can block and modify web requests in real-time. This could potentially be used maliciously to compromise security or privacy.
HIGH
Unsafe WebAssembly Execution
This extension's Content Security Policy allows 'wasm-unsafe-eval', which permits potentially dangerous WebAssembly code execution. This could be used to hide malicious code or perform CPU-intensive operations.
MEDIUM
Medium-Risk Permission: geolocation
This extension has the geolocation permission. Can access your location.
MEDIUM
Medium-Risk Permission: storage
This extension has the storage permission. Can store data locally.
MEDIUM
Medium-Risk Permission: unlimitedStorage
This extension has the unlimitedStorage permission. Can store unlimited data locally.