Security Alert: Confirmed Malware
Among Us Game Cursor
ID: nmmdefhefkhcbcmnnobjbcffigeiglln
Supported Languages
Extension Info & Metadata
Publisher Contextual Analysis
- Author
- https://nicecursor.comView Profile
- Privacy
- Privacy Policy
- MX records exist
- Yes
- Domain exists
- Yes
- Is disposable
- No
- Is role-based
- Yes
- Mailbox exists
- Yes
- Website
- Visit
Among Us cursor for chrome browser. Choose your favorite Among Us custom cursor with this extension. Created for Among Us fans.
Customize your browser experience by using this Among Us custom cursor chrome extension. Extension Features: 1. Give you different Among Us cursor design for you to replace default cursor. 2. Click on the task bar extension icon located at right hand top corner to open up Among Us cursor setting box. ------------------- ! After installing this extension, refresh the previously opened tab if you want to use it on this page. ! According to the rules of the Chrome Web Store extension can not work on the store pages and home page. Please open any other website (for example, google.com) after installing this extension and check how the extension will work on it. ------------------- By installing this extension, you agree to the End User License Agreement (https://nicecursor.com/eula/) and Privacy Policy (https://nicecursor.com/privacy-policy/) Homepage: https://nicecursor.com/among-us-game-cursor-chrome If you have any questions about our among us game cursor extension or just want to give us some feedback, feel free to send us a message or write a review! We'd love to hear from you.
The popup creates and appends a script tag dynamically. In this version it only loads the local 'content.js', but this pattern is a common vector for later substitution with a remote URL. Given the publisher's 100% malicious rate across other extensions, the presence of a dynamic script-loader warrants noting even if currently benign.
includeFile = function(e) { let t = document.createElement("script"); t.src = e, document.head.appendChild(t)},The popup contains a hardcoded affiliate/cross-promotion link to coolthemestores.com. While this is just an anchor tag and not code execution, it is a form of undisclosed advertising injection through an extension UI that may have contributed to the policy_violation removal and is consistent with adware-adjacent behavior seen across this publisher family.
<a href="https://coolthemestores.com?utm_campaign=referral&utm_medium=cursorbox&utm_source=amonguscursor" style="background-color:#27ae60; font-size:14px; color:#ffffff; border-radius:7px; margin-left:60px; width:250px; padding:10px 20px 10px 20px; text-decoration:none; font-family:arial" target="_blank">More Themes</a>By severity
Versions scanned
Showing 1 of 3 scanned versions with more than one unique finding. Counts are unique findings that include each version.
| Extension Version | Code Review Findings |
|---|---|
| 1.20.26.8 | 2 |
Files with findings
2 distinct paths — top paths by unique finding count:
- popup.html1
- popup.js1
Code Diff
Compare extension code between any two versions.
No comparable text files found between these versions.
Browse and explore files within this extension package
Gain full insight into all external connections.
Upgrade for full visibility.