CRX aminer
Extension icon

IntelligenceBank Assets Connector

Version 1.7.62 View in Chrome Web Store

Last scanned: about 11 hours ago

Extension Details

Developer: IntelligenceBank Pty Ltd
Rating: 5.0 ★ (2 ratings)
Users: 307

Context-Aware Verdict

HIGH
Overall Risk
Trust Factors:

The extension is developed by IntelligenceBank Pty Ltd, which appears to be a legitimate company offering digital asset management services. However, the extremely low user base of only 307 users and minimal rating data (only 2 reviews) provide limited validation of the extension's trustworthiness. The 5.0 rating is positive but based on insufficient feedback to be meaningful.

Concerns:

The extension requests downloads permissions that allow it to manage files and access download history, which could be exploited for malicious purposes. The broad host permissions extending beyond just IntelligenceBank domains raise red flags, as the CSP allows connections to any HTTPS site. While the host permissions are technically scoped to IntelligenceBank domains, the combination of download capabilities and storage permissions creates potential attack vectors for data exfiltration or unauthorized file manipulation.

Recommendations:

Given the high-risk classification, consider running this extension in a separate Chrome profile to isolate it from your primary browsing activities. Only install if you specifically need IntelligenceBank asset management functionality and trust the company with your download activities. Monitor the extension's behavior closely and review what files it accesses. Consider whether the business benefits justify the security risks, and explore alternative solutions if available.

Findings

HIGH
Broad Host Permissions
This extension has broad host permissions allowing it to access many or all websites. This could potentially be used to steal sensitive data or track browsing activity.
HIGH
High-Risk Permission: downloads
This extension has the downloads permission. Can download files and access download history. This could potentially be used maliciously to compromise security or privacy.
MEDIUM
Access to Sensitive Domains
This extension requests access to sensitive domains: *://*.intelligencebank.com/*, https://cdn.intelligencebank.com/*. Ensure you trust this extension with access to these sites.
MEDIUM
Medium-Risk Permission: storage
This extension has the storage permission. Can store data locally.