CRX aminer

Version 2.0.13 View in Chrome Web Store

Last scanned: about 4 hours ago

Extension Details

Context-Aware Verdict

CRITICAL
Overall Risk
Trust Factors:

The extension lacks fundamental identifying information including name, description, author details, user count, and ratings. This complete absence of metadata is highly suspicious and suggests either a malicious extension or one that has been deliberately obscured. The lack of transparency makes it impossible to verify the developer's legitimacy or assess user community feedback.

Concerns:

The extension exhibits an extremely dangerous permission profile with broad access capabilities that far exceed what most legitimate extensions require. The combination of tabs permission, all_urls host permissions, and universal content script injection creates a perfect storm for malicious activity. The extension can monitor all browsing activity, access sensitive data on any website, manipulate web pages, and potentially steal credentials or personal information. The storage permission allows it to persist stolen data locally.

Recommendations:

Do not install this extension under any circumstances. The combination of missing identification information and excessive permissions strongly suggests malicious intent. If already installed, remove it immediately and run a security scan. If you absolutely must test suspicious extensions, use a completely isolated Chrome profile with no access to personal accounts or sensitive data. Consider reporting this extension to Chrome Web Store security team for investigation.

Findings

HIGH
Broad Content Script Injection
This extension can inject scripts into any website. This means it could potentially read sensitive data, modify website content, or steal credentials.
HIGH
Broad Host Permissions
This extension has broad host permissions allowing it to access many or all websites. This could potentially be used to steal sensitive data or track browsing activity.
HIGH
High-Risk Permission: tabs
This extension has the tabs permission. Can access browser tab information and manipulate tabs. This could potentially be used maliciously to compromise security or privacy.
MEDIUM
Medium-Risk Permission: activeTab
This extension has the activeTab permission. Can access the active tab when clicking the extension icon.
MEDIUM
Medium-Risk Permission: storage
This extension has the storage permission. Can store data locally.