Starting analysis...
Version 1.4.213 View in Chrome Web Store
The extension has concerning trust indicators with only 2,000 users and a modest 3.5-star rating. The lack of visible developer information and company details raises additional red flags. The name "Surf Security 5" suggests it's a security tool, but the extensive permissions far exceed what most legitimate security extensions require.
The permission set is extremely invasive and includes dangerous capabilities like proxy control, web request interception, extension management, and identity access. The combination of broad host permissions with webRequest and proxy permissions creates a perfect storm for man-in-the-middle attacks. The management permission allows it to disable other security extensions. The unsafe WebAssembly execution policy could hide malicious code. For a security extension, having access to downloads, cookies, and complete browsing history seems excessive and potentially contradictory to its stated purpose.
Do not install this extension. If already installed, remove it immediately. The risk profile suggests potential malware or a compromised legitimate extension. If you absolutely need similar functionality, research well-established security extensions from reputable companies with transparent privacy policies and significantly higher user bases. Consider using built-in browser security features or dedicated security software instead. If you must test suspicious extensions, use a completely isolated browser profile or virtual machine.
| https://github.com/hodgef/simple-keyboard | https://github.com/hodgef | |
| https://fonts.googleapis.com/css2?family=Open+Sans:wght@400 | https://fonts.googleapis.com/css2?family=Roboto:ital | |
| https://mui.com/production-error/?code= | http://fb.me/use-check-prop-types | |
| https://reactjs.org/docs/error-decoder.html?invariant= | http://www.w3.org/1999/xlink | |
| http://www.w3.org/XML/1998/namespace | http://www.w3.org/1999/xhtml | |
| http://www.w3.org/1998/Math/MathML | http://www.w3.org/2000/svg | |
| http://purl.org/dc/elements/1.1/ | http://purl.org/dc/terms/ | |
| http://purl.org/dc/dcmitype/ | http://schemas.microsoft.com/office/mac/excel/2008/main | |
| http://schemas.openxmlformats.org/officeDocument/2006/relationships | http://schemas.openxmlformats.org/package/2006/sheetjs/core-properties | |
| http://schemas.openxmlformats.org/officeDocument/2006/docPropsVTypes | http://www.w3.org/2001/XMLSchema-instance | |
| http://www.w3.org/2001/XMLSchema | http://schemas.openxmlformats.org/spreadsheetml/2006/main | |
| http://purl.oclc.org/ooxml/spreadsheetml/main | http://schemas.microsoft.com/office/excel/2006/main | |
| http://schemas.microsoft.com/office/excel/2006/2 | http://www.w3.org/TR/REC-html40 | |
| http://schemas.openxmlformats.org/package/2006/content-types | http://schemas.openxmlformats.org/officeDocument/2006/relationships/officeDocument | |
| http://sheetjs.openxmlformats.org/officeDocument/2006/relationships/officeDocument | http://schemas.openxmlformats.org/officeDocument/2006/relationships/hyperlink | |
| http://schemas.openxmlformats.org/officeDocument/2006/relationships/vmlDrawing | http://schemas.microsoft.com/office/2006/relationships/vbaProject | |
| http://schemas.openxmlformats.org/package/2006/relationships | http://docs.oasis-open.org/ns/office/1.2/meta/ | |
| http://schemas.openxmlformats.org/package/2006/metadata/core-properties | http://schemas.openxmlformats.org/package/2006/relationships/metadata/core-properties | |
| http://schemas.openxmlformats.org/officeDocument/2006/extended-properties | http://schemas.openxmlformats.org/officeDocument/2006/relationships/extended-properties | |
| http://schemas.openxmlformats.org/officeDocument/2006/custom-properties | http://schemas.openxmlformats.org/officeDocument/2006/relationships/custom-properties | |
| http://schemas.openxmlformats.org/officeDocument/2006/relationships/sharedStrings | http://schemas.openxmlformats.org/officeDocument/2006/relationships/styles | |
| http://schemas.openxmlformats.org/officeDocument/2006/relationships/theme | http://schemas.openxmlformats.org/drawingml/2006/main | |
| http://schemas.openxmlformats.org/officeDocument/2006/relationships/image | http://schemas.openxmlformats.org/officeDocument/2006/relationships/drawing | |
| http://schemas.openxmlformats.org/officeDocument/2006/relationships/comments | http://schemas.openxmlformats.org/officeDocument/2006/relationships/dialogsheet | |
| http://schemas.microsoft.com/office/2006/relationships/xlMacrosheet | http://schemas.openxmlformats.org/officeDocument/2006/relationships/worksheet | |
| http://purl.oclc.org/ooxml/officeDocument/relationships/worksheet | http://schemas.openxmlformats.org/officeDocument/2006/relationships/chartsheet | |
| http://openoffice.org/2004/office | http://openoffice.org/2004/writer | |
| http://openoffice.org/2004/calc | http://www.w3.org/2001/xml-events | |
| http://www.w3.org/2002/xforms | http://openoffice.org/2005/report | |
| http://www.w3.org/2003/g/data-view# | http://openoffice.org/2009/table | |
| http://openoffice.org/2010/draw | http://www.w3.org/TR/css3-text/ | |
| http://www.w3.org/1999/02/22-rdf-syntax-ns# | http://docs.oasis-open.org/ns/office/1.2/meta/pkg# | |
| https://redux.js.org/Errors?code= | https://reactjs.org/link/react-polyfills | |
| https://tinyurl.com/y2uuvskb | http://bit.ly/2kdckMn | |
| https://bit.ly/3cXEKWf | https://socket.io/docs/v3/migrating-from-2-x-to-3-0/ | |
| https://myaccount.google.com | https://backend-surf-1.surf-admin.link | |
| https://safebrowsing.googleapis.com/v4/threatMatches:find | https://surf-admin-1.surf-admin.link | |
| https://onboarding.surf-admin.link | https://www.surf.security | |
| http://surf-assets.s3-website.eu-west-2.amazonaws.com | https://lcjlelbjbachjjkpjjlcikldffninona.chromiumapp.org | |
| https://hooks.slack.com/services/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 | https://data-transfer-1.surf-admin.link |
{ "name": "__MSG_extName__", "icons": { "16": "assets/icon_16.png", "48": "assets/icon_48.png", "128": "assets/icon_128.png" }, "action": { "default_icon": "assets/disconnected_128x128.png", "default_popup": "Popup.html", "default_title": "__MSG_extName__" }, "version": "1.4.213", "background": { "service_worker": "js/Background.bundle.js" }, "update_url": "https://clients2.google.com/service/update2/crx", "description": "__MSG_extDesc__", "permissions": [ "system.cpu", "scripting", "storage", "activeTab", "tabs", "alarms", "declarativeNetRequest", "webNavigation", "management", "downloads", "cookies", "idle", "proxy", "webRequestAuthProvider", "webRequest", "notifications", "identity", "identity.email", "nativeMessaging", "tabCapture", "offscreen" ], "default_locale": "en", "host_permissions": [ "<all_urls>", "*://*/*" ], "manifest_version": 3, "externally_connectable": { "ids": [ "*" ], "matches": [ "*://*.portal-surf-security.link/*", "*://*.admin.surf-admin.link/*" ] }, "minimum_chrome_version": "120", "content_security_policy": { "sandbox": "sandbox allow-scripts allow-forms allow-popups allow-modals; script-src 'self' 'unsafe-inline' 'unsafe-eval' 'wasm-unsafe-eval'; child-src 'self';", "extension_pages": "script-src 'self' 'wasm-unsafe-eval'; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com; img-src * data:; object-src 'self'; frame-src 'none';" }, "declarative_net_request": { "rule_resources": [ { "id": "ruleset_1", "path": "assets/rules.json", "enabled": false } ] }, "web_accessible_resources": [ { "matches": [ "<all_urls>" ], "resources": [ "*.png", "*.js", "*.css", "*.scss", "*.html", "*.json", "*.svg" ], "extension_ids": [] } ] }
ⓘ CRXaminer has partnered with our friends at Secure Annex to provide additional findings unique to their platform.
Secure Annex also analyzes extensions from other browsers, IDEs, and can continuously monitor.
This extension may not yet be analyzed by Secure Annex.