Starting analysis...
The extension has concerning trust indicators with only 2,000 users and a modest 3.5-star rating. The lack of visible developer information and company details raises additional red flags. The name "Surf Security 5" suggests it's a security tool, but the extensive permissions far exceed what most legitimate security extensions require.
The extension requests an excessive number of high-risk permissions that create significant security vulnerabilities. The combination of proxy control, web request interception, cookie access, and broad host permissions (<all_urls>) essentially gives this extension complete control over your browsing experience. The management permission allowing control over other extensions is particularly concerning, as is the identity permission accessing personal information. The unsafe WebAssembly execution policy could hide malicious code. For a security extension with only 2,000 users, these permissions are disproportionately invasive and unnecessary.
Do not install this extension. If already installed, remove it immediately. The permission set suggests potential malware or a compromised extension rather than legitimate security software. If you need security functionality, choose well-established extensions from reputable companies with millions of users and transparent privacy policies. The combination of low user count, broad permissions, and security-focused branding is a common pattern in malicious extensions designed to steal data or compromise systems.
| https://github.com/hodgef/simple-keyboard | https://github.com/hodgef | |
| https://fonts.googleapis.com/css2?family=Open+Sans:wght@400 | https://fonts.googleapis.com/css2?family=Roboto:ital | |
| https://myaccount.google.com | https://backend-surf-1-tanitum.surf-admin.link | |
| https://surf-admin-1.surf-admin.link | https://onboarding.surf-admin.link | |
| https://www.surf.security | https://hooks.slack.com/services/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 | |
| https://data-transfer-1.surf-admin.link | https://6bbccwsqx4iu6irvgdnbwg7f5i0fpvvt.lambda-url.eu-west-2.on.aws/ | |
| https://c4wrrcyhalk73hpj23w6ski2l40qdrch.lambda-url.eu-west-2.on.aws/ | https://www.virustotal.com/ui/files | |
| https://drive.google.com/drive/my-drive | https://docs.google.com | |
| https://docs.google.com/spreadsheets | https://lucid.app | |
| https://onedrive.live.com/edit.aspx | https://excel.officeapps.live.com | |
| https://powerpoint.officeapps.live.com | https://web.whatsapp.com | |
| https://www.cloudflare.com/cdn-cgi/trace | https://ipv4.lafibre.info/ip.php | |
| https://dev-client-backend.portal-surf-security.link | https://surf-dev.portal-surf-security.link | |
| https://xdsmstklr7rgh3gwz2vezcqyoq0yrvkx.lambda-url.eu-west-2.on.aws/ | https://7xfpkp3wnzvtufeq52xyu2hr4i0jngra.lambda-url.eu-west-2.on.aws/ | |
| https://surf-dev.portal-surf-security.link/lp_login.html | https://surf-dev.portal-surf-security.link/file.html | |
| https://onboarding-dev.portal-surf-security.link | https://data-transfer-dev.portal-surf-security.link | |
| https://admin-us.portal-surf-security.link:3333 | https://test-us1.surf-admin.link | |
| https://test-us1.surf-admin.link/lp_login.html | https://test-us1.surf-admin.link/file.html | |
| https://admin-us.portal-surf-security.link:3335 | https://backend.portal-surf-security.link | |
| https://admin.portal-surf-security.link | https://k4hhwh5mrkgjx5f7r42efe4wwa0devrw.lambda-url.eu-west-2.on.aws/ | |
| https://r5pxpvohtigoiqaf5nunoj5g2m0zkriz.lambda-url.eu-west-2.on.aws/ | https://admin.portal-surf-security.link/lp_login.html | |
| https://backend.portal-surf-security.link/file.html | https://onboarding-staging.portal-surf-security.link | |
| https://data-transfer-staging.portal-surf-security.link | https://www.w3.org/TR/webauthn-2/#sctn-privacy-considerations-client. | |
| http://www.w3.org/2000/svg | http://purl.org/dc/elements/1.1/ | |
| http://purl.org/dc/terms/ | http://purl.org/dc/dcmitype/ | |
| http://schemas.microsoft.com/office/mac/excel/2008/main | http://schemas.openxmlformats.org/officeDocument/2006/relationships | |
| http://schemas.openxmlformats.org/package/2006/sheetjs/core-properties | http://schemas.openxmlformats.org/officeDocument/2006/docPropsVTypes | |
| http://www.w3.org/2001/XMLSchema-instance | http://www.w3.org/2001/XMLSchema | |
| http://schemas.openxmlformats.org/spreadsheetml/2006/main | http://purl.oclc.org/ooxml/spreadsheetml/main | |
| http://schemas.microsoft.com/office/excel/2006/main | http://schemas.microsoft.com/office/excel/2006/2 | |
| http://www.w3.org/TR/REC-html40 | http://schemas.openxmlformats.org/package/2006/content-types | |
| http://schemas.openxmlformats.org/officeDocument/2006/relationships/officeDocument | http://sheetjs.openxmlformats.org/officeDocument/2006/relationships/officeDocument | |
| http://schemas.openxmlformats.org/officeDocument/2006/relationships/hyperlink | http://schemas.openxmlformats.org/officeDocument/2006/relationships/vmlDrawing | |
| http://schemas.microsoft.com/office/2006/relationships/vbaProject | http://schemas.openxmlformats.org/package/2006/relationships | |
| http://docs.oasis-open.org/ns/office/1.2/meta/ | http://www.w3.org/1999/xlink | |
| http://schemas.openxmlformats.org/package/2006/metadata/core-properties | http://schemas.openxmlformats.org/package/2006/relationships/metadata/core-properties | |
| http://schemas.openxmlformats.org/officeDocument/2006/extended-properties | http://schemas.openxmlformats.org/officeDocument/2006/relationships/extended-properties | |
| http://schemas.openxmlformats.org/officeDocument/2006/custom-properties | http://schemas.openxmlformats.org/officeDocument/2006/relationships/custom-properties | |
| http://schemas.openxmlformats.org/officeDocument/2006/relationships/sharedStrings | http://schemas.openxmlformats.org/officeDocument/2006/relationships/styles | |
| http://schemas.openxmlformats.org/officeDocument/2006/relationships/theme | http://schemas.openxmlformats.org/drawingml/2006/main |
{ "name": "__MSG_extName__", "icons": { "16": "assets/icon_16.png", "48": "assets/icon_48.png", "128": "assets/icon_128.png" }, "action": { "default_icon": "assets/disconnected_128x128.png", "default_popup": "Popup.html", "default_title": "__MSG_extName__" }, "version": "1.4.256", "background": { "service_worker": "js/Background.bundle.js" }, "update_url": "https://clients2.google.com/service/update2/crx", "description": "__MSG_extDesc__", "permissions": [ "system.cpu", "scripting", "storage", "unlimitedStorage", "activeTab", "tabs", "alarms", "declarativeNetRequest", "webNavigation", "management", "downloads", "cookies", "idle", "proxy", "webRequestAuthProvider", "webRequest", "notifications", "identity", "identity.email", "nativeMessaging", "tabCapture", "offscreen" ], "devtools_page": "assets/devtools.html", "default_locale": "en", "host_permissions": [ "<all_urls>", "*://*/*" ], "manifest_version": 3, "externally_connectable": { "ids": [ "*" ], "matches": [ "*://*.portal-surf-security.link/*", "*://*.admin.surf-admin.link/*" ] }, "minimum_chrome_version": "120", "content_security_policy": { "sandbox": "sandbox allow-scripts allow-forms allow-popups allow-modals; script-src 'self' 'unsafe-inline' 'unsafe-eval' 'wasm-unsafe-eval'; child-src 'self';", "extension_pages": "script-src 'self' 'wasm-unsafe-eval'; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com; img-src * data:; object-src 'self'; frame-src 'none';" }, "declarative_net_request": { "rule_resources": [ { "id": "ruleset_1", "path": "assets/rules.json", "enabled": false } ] }, "web_accessible_resources": [ { "matches": [ "<all_urls>" ], "resources": [ "*.png", "*.js", "*.css", "*.scss", "*.html", "*.json", "*.svg" ], "extension_ids": [] } ] }
ⓘ CRXaminer has partnered with our friends at Secure Annex to provide additional findings unique to their platform.
Secure Annex also analyzes extensions from other browsers, IDEs, and can continuously monitor.
This extension may not yet be analyzed by Secure Annex.