CRX aminer

Starting analysis...

Extension icon

XHunt – Your Crypto Co-pilot on X

Version 0.2.03 View in Chrome Web Store

Last scanned: 1 day ago | force re-scan

Extension Details

Rating: 4.6 ★ (28 ratings)
Users: 10,000

Context-Aware Verdict

MEDIUM
Overall Risk
Trust Factors:

The extension has a decent user base of 10,000 users and maintains a strong 4.6-star rating from 28 reviews, indicating positive user experiences. However, the lack of visible developer information and company details reduces transparency and accountability. The extension targets cryptocurrency users on X (formerly Twitter), which is a legitimate use case but also attracts malicious actors due to the financial nature of crypto activities.

Concerns:

The primary concern is the combination of scripting permissions with content script access to X.com, which allows the extension to read and modify all content on the platform. This creates potential for data harvesting of sensitive information like crypto wallet addresses, trading discussions, or personal financial data. The storage permission, while common, enables the extension to retain collected data locally. The crypto-focused nature makes it an attractive target for malicious updates or supply chain attacks, as crypto users are high-value targets for scammers.

Recommendations:

Given the medium risk level, consider running this extension in a separate Chrome profile dedicated to crypto activities. Regularly review the extension's permissions and behavior for any suspicious changes. Be cautious about sharing sensitive crypto information while the extension is active. Monitor your accounts for unusual activity and consider using hardware wallets for significant crypto holdings. Keep the extension updated but watch for permission changes in future versions.

Findings

MEDIUM
Medium-Risk Permission: storage
This extension has the storage permission. Can store data locally.