CRX aminer
Extension icon

HLS Downloader

Version 0.1.4 View in Chrome Web Store

Last scanned: about 4 hours ago

Extension Details

Rating: 3.6 ★ (200 ratings)
Users: 100,000

Context-Aware Verdict

CRITICAL
Overall Risk
Trust Factors: The extension has a moderate user base of 100,000 downloads and a below-average rating of 3.6/5 stars from 200 reviews, which suggests user dissatisfaction or potential issues. The lack of developer information raises transparency concerns, making it difficult to assess the publisher's credibility or contact them for support.
Concerns: The extension's permission set is extremely broad and powerful for its stated purpose of downloading HLS streams. The webRequest permission allows complete interception and modification of all web traffic, while webNavigation enables comprehensive browsing tracking across all websites. The universal host permissions (*://*/*.m3u8) grant access to any website containing M3U8 files, but the scope extends far beyond what's necessary. The downloads permission, while functionally required, combined with these other permissions creates a potent surveillance and data exfiltration toolkit. The storage permission adds persistence capabilities for collected data.
Recommendations: Given the critical risk level, avoid installing this extension on your primary browser profile. If you must use it, create a dedicated Chrome profile with no saved passwords, personal data, or sensitive browsing activity. Consider using established, well-reviewed alternatives for HLS downloading. Monitor your network traffic when the extension is active, and regularly review your download history for unauthorized files. The combination of broad permissions with limited developer transparency makes this extension unsuitable for users handling sensitive information.

Findings

HIGH
Broad Host Permissions
This extension has broad host permissions allowing it to access many or all websites. This could potentially be used to steal sensitive data or track browsing activity.
HIGH
High-Risk Permission: downloads
This extension has the downloads permission. Can download files and access download history. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: webNavigation
This extension has the webNavigation permission. Can track your web navigation. This could potentially be used maliciously to compromise security or privacy.
HIGH
High-Risk Permission: webRequest
This extension has the webRequest permission. Can intercept and modify web requests. This could potentially be used maliciously to compromise security or privacy.
MEDIUM
Medium-Risk Permission: contextMenus
This extension has the contextMenus permission. Can add items to the context menu.
MEDIUM
Medium-Risk Permission: storage
This extension has the storage permission. Can store data locally.