CRX aminer
Extension icon

CFCA CryptoKit.YZZG Extension

Version 3.4.0.1 View in Chrome Web Store

Last scanned: about 2 hours ago

Extension Details

Rating: 0.0 ★

Context-Aware Verdict

HIGH
Overall Risk
Trust Factors:

The extension lacks critical transparency indicators - no visible download count, user ratings, or developer information. The cryptographic nature suggested by "CryptoKit" combined with minimal public information raises significant trust concerns. The 0.0 rating with no reviews indicates either a very new extension or one with limited adoption, making it difficult to assess real-world safety.

Concerns:

The combination of nativeMessaging permission with host permissions to yzzg.tech domains creates a concerning attack vector. Native messaging allows direct communication with local applications, which could potentially be exploited for system-level access. The broad host permissions, while limited to specific domains, still grant extensive access to all content on those sites. The cryptographic focus combined with these powerful permissions could enable sophisticated data interception or manipulation attacks.

Recommendations:

Given the high-risk profile, install this extension only in a separate Chrome profile isolated from your primary browsing activities. Verify the legitimacy of the yzzg.tech domain and ensure you trust the organization behind it before installation. Monitor system activity after installation for any unexpected native application communications. Consider whether the cryptographic functionality is essential enough to justify the security risks, and explore alternative solutions with better transparency and user feedback.

Findings

HIGH
Broad Host Permissions
This extension has broad host permissions allowing it to access many or all websites. This could potentially be used to steal sensitive data or track browsing activity.