Among Us Game Cursor

ID: nmmdefhefkhcbcmnnobjbcffigeiglln

Could be malicious

Supported Languages

🇺🇸English

Extension Info & Metadata

Status
Removed
Version
1.20.26.8
Size
0.51 MB
Rating
4.7/5
Reviews
23
Users
67,135
Type
Extension
Updated
Jan 25, 2021
Category
14_fun
Price
Free
Featured
No
Visibility
Listed
Mature
No
By Google
No
Trusted
Yes

Publisher Contextual Analysis

Trusted
Author
https://nicecursor.comView Profile
MX records exist
Yes
Domain exists
Yes
Is disposable
No
Is role-based
Yes
Mailbox exists
Yes
Website
Visit
Total Extensions
22
Active
0
Obsolete
22
Listed
22
Unlisted
0
Total Users
1,065,286

Among Us cursor for chrome browser. Choose your favorite Among Us custom cursor with this extension. Created for Among Us fans.

Customize your browser experience by using this Among Us custom cursor chrome extension. Extension Features: 1. Give you different Among Us cursor design for you to replace default cursor. 2. Click on the task bar extension icon located at right hand top corner to open up Among Us cursor setting box. ------------------- ! After installing this extension, refresh the previously opened tab if you want to use it on this page. ! According to the rules of the Chrome Web Store extension can not work on the store pages and home page. Please open any other website (for example, google.com) after installing this extension and check how the extension will work on it. ------------------- By installing this extension, you agree to the End User License Agreement (https://nicecursor.com/eula/) and Privacy Policy (https://nicecursor.com/privacy-policy/) Homepage: https://nicecursor.com/among-us-game-cursor-chrome If you have any questions about our among us game cursor extension or just want to give us some feedback, feel free to send us a message or write a review! We'd love to hear from you.

Item
Type
Severity
Description
*://*/*
Permission
Critical
This permission grants access to all websites without restriction. Rated High because it can access any web content, monitor all web activity, and potentially steal sensitive data across all sites.
Contextual Risk Factors
Risk Factor
High
The following context increases the overall risk:• 10% increase: Early script execution enables pre-emptive content manipulation• 15% increase: Older manifest version lacks modern security controls
storage
Permission
Medium
This permission allows storing data locally in the browser. Rated Medium because it can persist sensitive user data, track user activities over time, and potentially store malicious payloads.
Early Content Script Execution
Risk Factor
Medium
This extension runs content scripts at document_start.
Older Manifest Version
Risk Factor
Medium
This extension uses Manifest Version 2

The popup creates and appends a script tag dynamically. In this version it only loads the local 'content.js', but this pattern is a common vector for later substitution with a remote URL. Given the publisher's 100% malicious rate across other extensions, the presence of a dynamic script-loader warrants noting even if currently benign.

popup.js (Line 2)
includeFile = function(e) {  let t = document.createElement("script");  t.src = e, document.head.appendChild(t)},

The popup contains a hardcoded affiliate/cross-promotion link to coolthemestores.com. While this is just an anchor tag and not code execution, it is a form of undisclosed advertising injection through an extension UI that may have contributed to the policy_violation removal and is consistent with adware-adjacent behavior seen across this publisher family.

popup.html (Line 422)
<a href="https://coolthemestores.com?utm_campaign=referral&utm_medium=cursorbox&utm_source=amonguscursor"  style="background-color:#27ae60; font-size:14px; color:#ffffff; border-radius:7px; margin-left:60px; width:250px; padding:10px 20px 10px 20px; text-decoration:none; font-family:arial"  target="_blank">More Themes</a>

By severity

Critical0
High0
Medium0
Low2

Versions scanned

Showing 1 of 3 scanned versions with more than one unique finding. Counts are unique findings that include each version.

Extension VersionCode Review Findings
1.20.26.82

Files with findings

2 distinct paths — top paths by unique finding count:

  • popup.html1
  • popup.js1
S.No.
Category
Severity
File
Summary
Found in Version
1Remote Code Loading
low
popup.js (line 2)The popup creates and appends a script tag dynamically. In this version it only loads the local 'content.js', but this pattern is a common vector for later substitution with a remote URL. Given the publisher's 100% ma…
2Tracking
low
popup.html (line 422)The popup contains a hardcoded affiliate/cross-promotion link to coolthemestores.com. While this is just an anchor tag and not code execution, it is a form of undisclosed advertising injection through an extension UI …
URLs
5
IPv4
1
IPv6
0

URLs

View the external URLs this extension communicates with to understand its network activity and data interactions.

Gain full insight into all external connections.

Upgrade for full visibility.

nicecursor.com/uninstallhttps://nicecursor.com/uninstall?utm_campaign=Extensions&utm_medium=uninstall&utm_source=amongus
nicecursor.com/among-us-game-custom-cursorhttps://nicecursor.com/among-us-game-custom-cursor?utm_campaign=Extensions&utm_medium=newinstall&utm_source=
clients2.google.com/service/update2/crxhttps://clients2.google.com/service/update2/crx
fonts.googleapis.com/css2https://fonts.googleapis.com/css2?family=Poppins:wght@500&display=swap
coolthemestores.com-https://coolthemestores.com?utm_campaign=referral&utm_medium=cursorbox&utm_source=amonguscursor

Gain full insight into all external connections.

Upgrade for full visibility.

1.20.26.8
IPv4
-
Showing 1 to 3 of 10 rows
Rows per page:

Code Diff

Compare extension code between any two versions.

0 changed files (scanned top 25 shared text files)

No comparable text files found between these versions.

Browse and explore files within this extension package

Gain full insight into all external connections.

Upgrade for full visibility.