CRX aminer

Starting analysis...

Version 1.1.15 View in Chrome Web Store

Last scanned: 4 months ago | force re-scan

Extension Details

Context-Aware Verdict

HIGH
Overall Risk
Trust Factors: This extension appears to be designed for Caixa Econômica Federal (Brazilian government bank) systems, as evidenced by the specific domain permissions for caixa.gov.br and related subdomains. However, several red flags significantly impact trustworthiness: missing basic metadata (name, description, author, user count, ratings), which suggests either an incomplete analysis or a potentially problematic extension. The localhost permission combined with native messaging capabilities raises additional concerns about local system access.
Concerns:
- Missing critical identifying information makes verification impossible
- Native messaging permission allows communication with local applications, creating potential attack vectors
- Unlimited storage permission combined with storage access could enable data hoarding
- Manifest V2 usage indicates outdated security standards
- Localhost access permission is unusual and potentially dangerous
- Content script injection across multiple banking domains creates significant security exposure
- The combination of native messaging with banking site access presents elevated risks for financial data compromise
Recommendations:
- Do not install this extension without proper verification of its source and legitimacy
- If this is a legitimate banking tool, contact Caixa directly to verify authenticity
- If you must use it, run it in a completely separate Chrome profile isolated from other activities
- Monitor system and network activity closely when the extension is active
- Consider alternative solutions that don't require such extensive permissions

Findings

MEDIUM
Medium-Risk Permission: storage
This extension has the storage permission. Can store data locally.
MEDIUM
Medium-Risk Permission: unlimitedStorage
This extension has the unlimitedStorage permission. Can store unlimited data locally.
MEDIUM
Older Manifest Version
This extension uses Manifest Version 2, which has fewer security restrictions than Manifest V3. Consider using extensions that have upgraded to V3.