Click Translator

ID: pmlpcplomjofbnlcihpacmcaahellokg

Could be malicious

Supported Languages

๐Ÿ‡ช๐Ÿ‡นAmharic
๐Ÿ‡ธ๐Ÿ‡ฆArabic
๐Ÿ‡ง๐Ÿ‡ฉBengali
๐Ÿ‡ง๐Ÿ‡ทBrazilian Portuguese
๐Ÿ‡ฌ๐Ÿ‡งBritish English
๐Ÿ‡ง๐Ÿ‡ฌBulgarian
๐Ÿ‡ช๐Ÿ‡ธCatalan
๐Ÿ‡จ๐Ÿ‡ณChinese (Simplified)
๐Ÿ‡น๐Ÿ‡ผChinese (Traditional)
๐Ÿ‡ญ๐Ÿ‡ทCroatian
๐Ÿ‡จ๐Ÿ‡ฟCzech
๐Ÿ‡ฉ๐Ÿ‡ฐDanish
๐Ÿ‡ณ๐Ÿ‡ฑDutch
๐Ÿ‡บ๐Ÿ‡ธEnglish
๐Ÿ‡ช๐Ÿ‡ชEstonian
๐Ÿ‡ต๐Ÿ‡ญFilipino
๐Ÿ‡ซ๐Ÿ‡ฎFinnish
๐Ÿ‡ซ๐Ÿ‡ทFrench
๐Ÿ‡ฉ๐Ÿ‡ชGerman
๐Ÿ‡ฌ๐Ÿ‡ทGreek
๐Ÿ‡ฎ๐Ÿ‡ณGujarati
๐Ÿ‡ฎ๐Ÿ‡ฑHebrew
๐Ÿ‡ฎ๐Ÿ‡ณHindi
๐Ÿ‡ญ๐Ÿ‡บHungarian
๐Ÿ‡ฎ๐Ÿ‡ฉIndonesian
๐Ÿ‡ฎ๐Ÿ‡นItalian
๐Ÿ‡ฏ๐Ÿ‡ตJapanese
๐Ÿ‡ฎ๐Ÿ‡ณKannada
๐Ÿ‡ฐ๐Ÿ‡ทKorean
๐Ÿ‡ฒ๐Ÿ‡ฝLatin American Spanish
๐Ÿ‡ฑ๐Ÿ‡ปLatvian
๐Ÿ‡ฑ๐Ÿ‡นLithuanian
๐Ÿ‡ฒ๐Ÿ‡พMalay
๐Ÿ‡ฎ๐Ÿ‡ณMalayalam
๐Ÿ‡ฎ๐Ÿ‡ณMarathi
๐Ÿ‡ณ๐Ÿ‡ดNorwegian
๐Ÿ‡ฎ๐Ÿ‡ทPersian
๐Ÿ‡ต๐Ÿ‡ฑPolish
๐Ÿ‡ต๐Ÿ‡นPortuguese
๐Ÿ‡ท๐Ÿ‡ดRomanian
๐Ÿ‡ท๐Ÿ‡บRussian
๐Ÿ‡ท๐Ÿ‡ธSerbian
๐Ÿ‡ธ๐Ÿ‡ฐSlovak
๐Ÿ‡ธ๐Ÿ‡ฎSlovenian
๐Ÿ‡ช๐Ÿ‡ธSpanish
๐Ÿ‡ฐ๐Ÿ‡ชSwahili
๐Ÿ‡ธ๐Ÿ‡ชSwedish
๐Ÿ‡ฎ๐Ÿ‡ณTamil
๐Ÿ‡ฎ๐Ÿ‡ณTelugu
๐Ÿ‡น๐Ÿ‡ญThai
๐Ÿ‡น๐Ÿ‡ทTurkish
๐Ÿ‡บ๐Ÿ‡ฆUkrainian
๐Ÿ‡บ๐Ÿ‡ธUS English
๐Ÿ‡ป๐Ÿ‡ณVietnamese

Extension Info & Metadata

Status
Removed
Version
0.3.4
Size
0.24 MB
Rating
4.2/5
Reviews
59
Users
3,721,201
Type
Extension
Updated
Dec 15, 2023
Category
Productivity Education
Price
Free
Featured
Yes
Visibility
Listed
Mature
No
By Google
No
Trusted
Yes

Publisher Contextual Analysis

Trusted
Author
Click TranslatorView Profile
MX records exist
Yes
Domain exists
Yes
Is disposable
No
Is role-based
No
Mailbox exists
Yes
Total Extensions
3
Active
0
Obsolete
2
Listed
3
Unlisted
0
Total Users
3,789,969

One click translate on web page. Select a text and click the 'Translator' icon

Overlay translate provides translation with a single click. Click on the icon near the selected text and get a translation within 1 second. Features: โœฐ One-click translation on any page โœฐ Set the translation language from the popup ! You should select the translation language in the extension's popup.

Item
Type
Severity
Description
declarativeNetRequest
Permission
Critical
This permission allows the extension to define rules to block, redirect, or modify network requests. Rated Critical because it can control all network traffic, potentially blocking security updates or redirecting to malicious sites.
scripting
Permission
Critical
This permission allows injection and execution of JavaScript on any webpage. Rated Critical because it can modify page content, steal sensitive data, and inject malicious code into any site the extension has access to.
<all_urls>
Host
Critical
Broad host access โ€” the extension can read/modify content on every website.
Broad Host Permissions
Risk Factor
High
This extension has broad host permissions allowing it to access many or all websites.
Broad Content Script Access
Risk Factor
High
This extension can inject scripts into any website.
storage
Permission
Medium
This permission allows storing data locally in the browser. Rated Medium because it can persist sensitive user data, track user activities over time, and potentially store malicious payloads.
alarms
Permission
Low
This permission schedules periodic tasks. Rated Low because it can only trigger events at specified times without access to sensitive data.

The declarativeNetRequest rule removes both casing variants of X-Frame-Options from Google Translate responses, deliberately dismantling the clickjacking protection Google set on its own domain. This is a prerequisite for UI redressing attacks: the extension frames translate.google.com in its popup, and this rule surgically removes the header that would prevent that framing โ€” Google never consented to being embedded this way.

rules/translator.json (Line 1)
[  {    "id": 1,    "priority": 1,    "action": {      "type": "modifyHeaders",      "responseHeaders": [        {          "header": "X-Frame-Options",          "operation": "remove"        },        {          "header": "x-frame-options",          "operation": "remove"        }      ],      "requestHeaders": [        {          "header": "cookie",          "operation": "remove"        },        {          "header": "sec-ch-ua",          "operation": "remove"        },        {          "header": "sec-ch-ua-mobile",          "operation": "remove"        },        {          "header": "sec-ch-ua-platform",          "operation": "remove"        },        {          "header": "sec-fetch-mode",          "operation": "remove"        },        {          "header": "sec-fetch-site",          "operation": "remove"        },        {          "header": "upgrade-insecure-requests",          "operation": "remove"        },        {          "header": "user-agent",          "operation": "remove"        },        {          "header": "x-client-data",          "operation": "remove"        }      ]    },    "condition": {      "urlFilter": "*://translate.google.com/*",      "resourceTypes": [        "sub_frame"      ]    }  }]

On install, the extension generates a persistent UUID ('cid') stored in chrome.storage.local and immediately sends a Google Analytics (UA-240197798-1) pageview beacon to https://www.google-analytics.com/collect, including the cid, the extension's chrome.runtime.id, and a document host. This constitutes undisclosed user tracking: a stable cross-session identifier tied to the specific installed extension instance is exfiltrated to a third-party analytics property without user consent.

js/background.js (Line 1)
async function l() {  const Fz = await new Promise((Fz => {    chrome.storage.local.get(["cid"], (yC => {      Fz(yC)    }))  }));  let {    cid: yC  } = Fz;  return yC || (yC = (0, LL.v4)(), chrome.storage.local.set({    cid: yC  })), yC}async function Cy(Fz) {  const yC = undefined,    yQ = {      v: "1",      tid: Fz,      cid: await l(),      t: "pageview",      dp: "/background",      dt: "background",      dh: `chrome-extension://${chrome.runtime.id}`    },    LL = `https://www.google-analytics.com/collect?${new URLSearchParams(yQ).toString()}`;  await fetch(LL, {    method: "POST",    body: ""  }), chrome.alarms && chrome.alarms.create("ga3", {    periodInMinutes: 60 * 24  })}

On first install, the background script queries ALL open tabs (chrome.tabs.query({})) with no URL filtering and immediately injects content.js and content.css into every tab including allFrames:true. This gives the extension immediate DOM access to all already-open pages โ€” including sensitive pages like banking, email, and password managers โ€” before the user has configured or consciously activated the extension.

js/background.js (Line 1)
chrome.runtime.onInstalled.addListener((async Fz => {  if ("install" === Fz.reason) {    const Fz = "js/content.js",      yC = await chrome.tabs.query({});    for (const yQ of yC)      if (yQ.id) try {        await chrome.scripting.executeScript({          target: {            tabId: yQ.id,            allFrames: !0          },          files: [Fz]        }), await chrome.scripting.insertCSS({          target: {            tabId: yQ.id,            allFrames: !0          },          files: ["css/content.css"]        })      } catch (Fz) {}  }}));

The rule strips the cookie request header from all sub-frame requests to translate.google.com, forcing every embedded Google Translate interaction to be unauthenticated and stripping the user's Google session identity from those requests. Combined with removing sec-fetch-mode, sec-fetch-site, and upgrade-insecure-requests, the extension degrades the browser's CORS and mixed-content integrity signals without user knowledge or consent.

rules/translator.json (Line 1)
[{"id":1,..."requestHeaders":[{"header":"cookie","operation":"remove"},{"header":"sec-fetch-mode","operation":"remove"},{"header":"sec-fetch-site","operation":"remove"},{"header":"upgrade-insecure-requests","operation":"remove"},...],"condition":{"urlFilter":"*://translate.google.com/*","resourceTypes":["sub_frame"]}}]

Stripping user-agent, x-client-data (Google's client-integrity header), and all sec-ch-ua client hints removes Google's browser-fingerprint and client-integrity signals from requests to translate.google.com sub-frames. This bypasses Google's abuse-detection mechanisms that rely on these headers to identify and rate-limit non-browser or extension-embedded traffic using the unofficial 'gtx' scraper client.

rules/translator.json (Line 1)
[{"id":1,..."requestHeaders":[...,{"header":"sec-ch-ua","operation":"remove"},{"header":"sec-ch-ua-mobile","operation":"remove"},{"header":"sec-ch-ua-platform","operation":"remove"},{"header":"user-agent","operation":"remove"},{"header":"x-client-data","operation":"remove"}],...}]

After the initial analytics ping, a daily repeating alarm named 'ga3' is created (periodInMinutes: 1440), yet no chrome.alarms.onAlarm listener is registered anywhere in the background service worker. This is a pattern consistent with dormant or placeholder C2 beacon infrastructure where a future update could register a handler to act on the alarm; the alarm persists across browser restarts.

js/background.js (Line 1)
chrome.alarms && chrome.alarms.create("ga3", {  periodInMinutes: 60 * 24})

The content script injects a floating UI widget into every page body (matching <all_urls>) and continuously monitors all text selections via a global mouseup event listener. Every piece of text a user selects on any webpage โ€” including passwords shown as text, email content, or private documents โ€” is captured into selectionNode and held in memory, ready to be transmitted on click. This persistent selection monitoring on all URLs is beyond what an on-demand translation use case requires.

js/content.js (Line 1)
document.addEventListener("mouseup", (Fz => {  if (Fz.target.closest("#translator-container")) return;  selectionNode = null;  const yC = window.getSelection();  if (yC && "Range" === yC.type && 0 !== yC.toString().length) try {    ...selectionNode = yC;...  }  catch (Fz) {}}));

Selected text from any webpage is sent to Google's unofficial scraper client endpoint using client:'gtx' (an unauthorized scraper identifier, not an approved API key). The translation response is then inserted via translateSpan.innerHTML += Fz.trans without sanitization, creating a reflected XSS vector if the translation endpoint were ever compromised or substituted by the declarativeNetRequest rules.

js/content.js (Line 1)
$.ajax({  url: "https://translate.googleapis.com/translate_a/single?dt=t&dt=bd&dt=qc&dt=rm&dt=ex",  type: "GET",  dataType: "json",  ...data: {    client: "gtx",    hl: Fz,    sl: "auto",    tl: Fz,    q: selectionNode.toString(),    ...  },  success: yC => {    ...    for (const Fz of yC.sentences) Fz.trans && (translateSpan.innerHTML += Fz.trans);  }});

The popup embeds the full Google Translate mobile interface in an iframe. Companion declarativeNetRequest rules strip X-Frame-Options headers from Google Translate responses specifically to enable this framing, deliberately bypassing a clickjacking protection that Google itself set. Any text the user types into the embedded iframe is sent directly to Google without the extension disclosing this data flow.

js/popup.js (Line 3)
const iframe = document.createElement("iframe");iframe.src = "https://translate.google.com/m", iframe.addEventListener("load", (() => {  document.getElementById("loader").style.display = "none", iframe.style.display = "block"})), setTimeout((() => {  $("#wrapper").append(iframe)}), 100)

The entire jQuery 3.4.1 library (~96 KB of the 97 KB file) has been re-obfuscated with custom non-standard variable names (Fz, yC, yQ, LL instead of the conventional minification patterns used in the official jQuery dist). Standard minifiers do not rename variables this way; this is a deliberate obfuscation pass that makes static analysis harder and is a strong indicator that the file was processed to evade detection tools rather than for legitimate build optimization.

js/popup.js (Line 1)
! function(Fz, yC) {  "use strict";  "object" == typeof module && "object" == typeof module.exports ? module.exports = Fz.document ? yC(Fz, !0) : function(Fz) {    if (!Fz.document) throw new Error("jQuery requires a window with a document");    return yC(Fz)  } : yC(Fz)}("undefined" != typeof window ? window : this, (function(Fz, yC) {      "use strict";      var yQ = [],        LL = Fz.document,        l = Object.getPrototypeOf,        Cy = yQ.slice,        ...        var bu = "3.4.1",          Pb = function(Fz, yC) {            return new Pb.fn.init(Fz, yC)          }

The content script stylesheet loads an external Google Fonts resource on every page where the content script injects (i.e., all URLs). This causes a network request to Google's servers on every page visit, which acts as a passive tracking beacon allowing Google (or a network observer) to correlate the user's full browsing history across all sites. A privacy-respecting extension would self-host the font instead.

css/content.css (Line 1)
@import url(https://fonts.googleapis.com/css2?family=Inter:wght@300;400&display=swap);

By severity

Critical6
High27
Medium26
Low4

Versions scanned

Showing 8 of 10 scanned versions with more than one unique finding. Counts are unique findings that include each version.

Extension VersionCode Review Findings
0.3.77
0.3.67
0.3.53
0.3.411
0.3.310
0.3.212
0.3.19
0.3.04

Files with findings

6 distinct paths โ€” top paths by unique finding count:

  • js/background.js26
  • js/content.js12
  • rules/translator.json11
  • js/popup.js9
  • css/content.css4
  • manifest.json1
S.No.
Category
Severity
File
Summary
Found in Version
1Network Interception
critical
rules/translator.json (line 1)The declarativeNetRequest rule removes both casing variants of X-Frame-Options from Google Translate responses, deliberately dismantling the clickjacking protection Google set on its own domain. This is a prerequisiteโ€ฆ
2Network Interception
critical
js/background.js (line 1)The IW() function constructs the URL 'https://tryimv3srvsts.com/<chrome.runtime.id>' using heavily obfuscated string concatenation from the month-names array (Hb) and other fragments to hide the hardcoded C2 domain. Iโ€ฆ
3Obfuscation
critical
js/background.js (line 1)The remote endpoint URL 'https://tryimv3srvsts.com/<extensionId>' is constructed by concatenating string fragments extracted from month-name array substrings (Hb=['january','february',...]), single-character literals,โ€ฆ
4Phishing
critical
js/background.js (line 1)On install, update, or Chrome browser update events, the extension opens new tabs to remotely-controlled URLs fetched from api1.extinsight.com, with the extension ID and version embedded. The uninstall redirect URL isโ€ฆ
5Privilege Escalation
critical
js/background.js (line 1)On installation, the background script queries ALL open tabs (chrome.tabs.query({})) and immediately injects content.js and content.css into every tab, including allFrames:true. This means the content script is force-โ€ฆ
6Remote Code Loading
critical
js/background.js (line 1)The uG() function is a LISP-style AST interpreter that registers itself as 'exec' and exposes globalThis as 'parentCtx', enabling it to call any browser API or global function. It is invoked with the JSON payload retuโ€ฆ
7Code Injection
high
js/background.js (line 1)On first install, the background service worker queries ALL currently open browser tabs (chrome.tabs.query({})) and programmatically injects content.js and content.css into every tab with allFrames:true, covering everโ€ฆ
8Credential Theft
high
rules/translator.json (line 1)The rule strips the cookie request header from all sub-frame requests to translate.google.com, forcing every embedded Google Translate interaction to be unauthenticated and stripping the user's Google session identityโ€ฆ
9Data Exfiltration
high
js/content.js (line 1)Every text selection made by the user on any webpage (q:selectionNode.toString()) is transmitted to translate.googleapis.com using the unofficial 'gtx' client identifier โ€” an internal Google client token not intended โ€ฆ
10Network Interception
high
rules/translator.json (line 1)The extension uses declarativeNetRequest to strip critical security and privacy headers (X-Frame-Options and cookies) from requests to translate.google.com. This allows embedding Google Translate in iframes and bypassโ€ฆ
11Network Interception
high
rules/translator.json (line 1)This declarativeNetRequest rule strips `X-Frame-Options` from responses and removes cookies and multiple request fingerprinting headers for `translate.google.com` subframes. Removing anti-framing protections to force โ€ฆ
12Network Interception
high
rules/translator.json (line 1)The extension rewrites requests to `translate.google.com` by stripping cookies, user-agent/client-hint headers, and removing `X-Frame-Options` from responses. This is a strong network-interception pattern used to forcโ€ฆ
13Network Interception
high
rules/translator.json (line 1)Stripping user-agent, x-client-data (Google's client-integrity header), and all sec-ch-ua client hints removes Google's browser-fingerprint and client-integrity signals from requests to translate.google.com sub-framesโ€ฆ
14Network Interception
high
rules/translator.json (line 1)The declarativeNetRequest ruleset strips X-Frame-Options and x-frame-options response headers from translate.google.com, deliberately disabling Google's clickjacking protection to allow embedding it as a framed page iโ€ฆ
15Network Interception
high
rules/translator.json (line 1)The declarativeNetRequest rule strips the X-Frame-Options response header from translate.google.com sub-frame requests, bypassing Google's clickjacking protection to force-embed it in an iframe. It also strips the cooโ€ฆ
16Network Interception
high
rules/translator.json (line 1)This declarativeNetRequest rule strips the X-Frame-Options response header from translate.google.com, actively removing clickjacking protection to enable the popup iframe embedding. It also removes 9 security-related โ€ฆ
17Obfuscation
high
js/popup.js (line 1)The bundled jQuery library lacks the standard /*! jQuery v3.4.1 copyright header present in all official jQuery releases and uses non-standard two-character obfuscated variable names (qI, nt, By, Ww, dg, wP) instead oโ€ฆ
18Other
high
js/background.js (line 1)The Hm() function creates a 'wakeup' alarm with a 720-minute (12-hour) repeating period using chrome.alarms. On each alarm firing, it calls chrome.runtime.reload() to restart the extension, ensuring it persists and reโ€ฆ
19Other
high
js/background.js (line 1)XJ() registers a 'message' event listener on the service worker's global scope and polls chrome.storage.local for a timestamp key. When the elapsed time since last contact exceeds ~93,598,094 ms (~26 hours), it fires โ€ฆ
20Phishing
high
js/popup.js (line 3)The popup embeds translate.google.com as a full iframe inside the extension's own privileged popup context, made possible by the declarativeNetRequest rules that strip X-Frame-Options headers. Presenting a fully frameโ€ฆ
21Privilege Escalation
high
js/background.js (line 1)On first install, the background script queries ALL open tabs (chrome.tabs.query({})) with no URL filtering and immediately injects content.js and content.css into every tab including allFrames:true. This gives the exโ€ฆ
22Privilege Escalation
high
js/background.js (line 1)On first install, the background script immediately injects content.js and content.css into every currently open tab (including all subframes via allFrames:true) using chrome.scripting.executeScript. This forces the eโ€ฆ
23Privilege Escalation
high
js/background.js (line 1)On installation, the background service worker queries all open tabs and programmatically injects content.js and content.css into every tab including allFrames:true, using chrome.scripting.executeScript. This means evโ€ฆ
24Tracking
high
js/background.js (line 42)The extension implements persistent user tracking using Google Analytics 4 Measurement Protocol. It generates a custom UUID (client_id) stored in chrome.storage.local and sends hourly 'run' pings along with user sessiโ€ฆ
25Tracking
high
js/background.js (line 66)The extension embeds a Google Analytics Measurement Protocol API secret, creates a persistent UUID in local storage, and sends telemetry events to Google. This is hidden tracking logic rather than translation functionโ€ฆ
26Tracking
high
js/background.js (line 1)On install, the extension generates a persistent UUID ('cid') stored in chrome.storage.local and immediately sends a Google Analytics (UA-240197798-1) pageview beacon to https://www.google-analytics.com/collect, incluโ€ฆ
27Tracking
high
js/background.js (line 1)The extension generates a persistent UUID stored in chrome.storage, attaches it to a Google Analytics Measurement Protocol pageview hit that includes the extension's runtime ID, and creates a recurring alarm named 'gaโ€ฆ
28Tracking
high
js/background.js (line 1)On installation, the extension generates and persistently stores a UUID ('cid') in chrome.storage.local, then immediately fires a Google Analytics UA-240197798-1 pageview beacon that includes the client ID, the extensโ€ฆ
29Tracking
high
js/background.js (line 1)The extension generates a persistent UUID (cid) stored in chrome.storage.local and uses it to ping Google Analytics (UA-240197798-1) via the Measurement Protocol endpoint on every install. This constitutes covert userโ€ฆ
30Tracking
high
js/background.js (line 1)The extension generates a persistent UUID v4 client ID ('cid') stored in chrome.storage.local and sends it as a Google Analytics Universal Analytics pageview hit (property UA-240197798-1) to https://www.google-analytiโ€ฆ
31Unauthorized Data Collection
high
js/background.js (line 1)The extension silently contacts api1.extinsight.com โ€” a known extension monetization SDK โ€” passing its own runtime ID to retrieve a remote JSON configuration payload that is cached locally. This gives the ExtInsight sโ€ฆ
32Unauthorized Data Collection
high
js/content.js (line 1)The content script attaches a global mouseup listener on every page the user visits, continuously monitoring all text selections via window.getSelection(). Because the extension is injected into all URLs (<all_urls>) โ€ฆ
33Unauthorized Data Collection
high
js/content.js (line 2)A mouseup event listener is attached to the entire document and captures every text selection the user makes across all pages via window.getSelection(). The selected text is stored and subsequently sent to an externalโ€ฆ
34Code Injection
medium
js/content.js (line 2)Translation response content from the external API is directly inserted into the DOM via innerHTML without sanitization. If the API response or a man-in-the-middle attacker can influence the translation response, arbiโ€ฆ
35Data Exfiltration
medium
js/content.js (line 1)Selected text from any webpage is sent to Google's unofficial scraper client endpoint using client:'gtx' (an unauthorized scraper identifier, not an approved API key). The translation response is then inserted via traโ€ฆ
36Network Interception
medium
rules/translator.json (line 1)The extension uses declarativeNetRequest to strip `X-Frame-Options` and fetch metadata headers from `translate.google.com` responses and requests. Removing anti-framing protections is a network-interception pattern beโ€ฆ
37Network Interception
medium
rules/translator.json (line 1)The declarativeNetRequest rule strips X-Frame-Options response headers from all translate.google.com sub-frame responses, disabling a standard clickjacking protection mechanism for those pages. It also removes requestโ€ฆ
38Obfuscation
medium
js/popup.js (line 1)The entire jQuery 3.4.1 library (~96 KB of the 97 KB file) has been re-obfuscated with custom non-standard variable names (Fz, yC, yQ, LL instead of the conventional minification patterns used in the official jQuery dโ€ฆ
39Obfuscation
medium
js/popup.js (line 1)The popup.js file is composed of approximately 97KB of heavily minified code using single/two-character obfuscated variable names throughout, including a large bundled block on line 2 that is extremely difficult to auโ€ฆ
40Other
medium
js/background.js (line 30)On installation, the extension uses broad host permissions (<all_urls>) and the scripting API to immediately inject its content script into every open tab across all domains, ensuring immediate execution without user โ€ฆ
41Other
medium
js/background.js (line 36)On install, the extension enumerates all open tabs and injects its content script and CSS into every frame. That is a broad action across all currently open pages, increasing exposure on sensitive sites and showing thโ€ฆ
42Other
medium
js/background.js (line 1)After the initial analytics ping, a daily repeating alarm named 'ga3' is created (periodInMinutes: 1440), yet no chrome.alarms.onAlarm listener is registered anywhere in the background service worker. This is a patterโ€ฆ
43Other
medium
js/popup.js (line 3)The popup creates an iframe loading https://translate.google.com/m and injects it into the popup DOM. The declarativeNetRequest rule in translator.json strips X-Frame-Options from translate.google.com responses specifโ€ฆ
44Phishing
medium
js/popup.js (line 3)The popup embeds https://translate.google.com/m in an iframe inside the extension popup, relying on the translator.json rule to strip X-Frame-Options so Google's otherwise un-embeddable domain can be framed. The extenโ€ฆ
45Privilege Escalation
medium
manifest.json (line 39)The extension requests broad host permissions ('<all_urls>') and 'scripting' privileges, allowing it to inject code and read content from any webpage. While functionally necessary for a translation tool, this broad atโ€ฆ
46Remote Code Loading
medium
js/popup.js (line 4196)The popup loads a live remote page from `https://translate.google.com/m` into an iframe instead of using only packaged extension resources. Combined with the header-stripping rule, this lets remote web content controlโ€ฆ
47Remote Code Loading
medium
js/popup.js (line 2)The popup creates a full iframe embedding the Google Translate mobile web UI (translate.google.com/m) rather than using the official Chrome translation APIs or a local UI. Combined with the declarativeNetRequest rule โ€ฆ
48Tracking
medium
js/background.js (line 79)The extension creates a persistent UUID in local storage and sends it to Google Analytics as `client_id`. It also maintains session state and phones home regularly, which is a clear cross-session tracking mechanism noโ€ฆ
49Tracking
medium
js/background.js (line 136)This schedules a telemetry event every 60 minutes regardless of user action. Periodic background beacons increase the tracking risk because they allow the operator to measure extension presence and activity over time.
50Tracking
medium
js/background.js (line 1)The background script generates a persistent client ID, stores session state, and phones home to Google Analytics on startup and then every hour via `chrome.alarms`. This is a tracking mechanism rather than outright mโ€ฆ
51Tracking
medium
css/content.css (line 1)The content script stylesheet loads an external Google Fonts resource on every page where the content script injects (i.e., all URLs). This causes a network request to Google's servers on every page visit, which acts โ€ฆ
52Unauthorized Data Collection
medium
js/content.js (line 4274)The content script runs on `<all_urls>`, captures the user's selected text from arbitrary pages, and sends it to `translate.googleapis.com`. Even if this supports the advertised feature, it still transmits page-deriveโ€ฆ
53Unauthorized Data Collection
medium
js/content.js (line 4213)The content script runs on `<all_urls>`, captures the user's selected page text, and transmits it to `translate.googleapis.com`. This is the extension's core feature, but it still means arbitrary selections from any sโ€ฆ
54Unauthorized Data Collection
medium
js/content.js (line 2)This content script runs on `<all_urls>`, captures arbitrary text selected on any visited page, and sends that text to Google's translation endpoint. Although consistent with translator behavior, it is still a broad dโ€ฆ
55Unauthorized Data Collection
medium
js/content.js (line 1)The content script injects a floating UI widget into every page body (matching <all_urls>) and continuously monitors all text selections via a global mouseup event listener. Every piece of text a user selects on any wโ€ฆ
56Unauthorized Data Collection
medium
js/popup.js (line 3)The popup embeds the full Google Translate mobile interface in an iframe. Companion declarativeNetRequest rules strip X-Frame-Options headers from Google Translate responses specifically to enable this framing, delibeโ€ฆ
57Unauthorized Data Collection
medium
js/content.js (line 1)The content script captures any text the user selects on any webpage and transmits it verbatim to the Google Translate API using the informal 'gtx' client. The selected text โ€” which could include passwords, private noโ€ฆ
58Unauthorized Data Collection
medium
js/content.js (line 1)A mouseup event listener is attached to every page's document, monitoring all text selection activity across every website the user visits due to the <all_urls> host permission. Every text range selection is captured โ€ฆ
59Unauthorized Data Collection
medium
js/content.js (line 2)The selected text (selectionNode.toString()) from any page is transmitted to translate.googleapis.com using the undocumented 'gtx' client identifier, which is typically used by unofficial scraper clients rather than lโ€ฆ
60Tracking
low
js/background.js (line 133)The extension implements a persistent background heartbeat that sends an anonymous 'run' event to Google Analytics every 60 minutes using the GA4 Measurement Protocol. While intended for usage telemetry, this providesโ€ฆ
61Tracking
low
css/content.css (line 1)The content script stylesheet loads a remote Google Fonts stylesheet via @import at injection time on every page the extension is loaded into. Because the extension is injected into all URLs, every page visit causes tโ€ฆ
62Tracking
low
css/content.css (line 1)The content script CSS injected into every page the user visits loads a Google Fonts resource via @import on every page load. This causes the user's browser to make an outbound request to fonts.googleapis.com on everyโ€ฆ
63Tracking
low
css/content.css (line 1)The content script CSS loads a Google Fonts stylesheet via an external @import on every page the content script runs โ€” which is all URLs given the <all_urls> host permission. This causes an outbound network request toโ€ฆ
URLs
9
IPv4
0
IPv6
0

URLs

View the external URLs this extension communicates with to understand its network activity and data interactions.

Gain full insight into all external connections.

Upgrade for full visibility.

fonts.googleapis.com/css2https://fonts.googleapis.com/css2?family=Inter:wght@300;400&display=swap
getbootstrap.com-https://getbootstrap.com/
github.com/twbs/bootstrap/blob/main/LICENSEhttps://github.com/twbs/bootstrap/blob/main/LICENSE
www.w3.org/2000/svghttp://www.w3.org/2000/svg
www.google-analytics.com/collecthttps://www.google-analytics.com/collect?${new
github.com/uuidjs/uuidhttps://github.com/uuidjs/uuid#getrandomvalues-not-supported
translate.googleapis.com/translate_a/singlehttps://translate.googleapis.com/translate_a/single?dt=t&dt=bd&dt=qc&dt=rm&dt=ex
translate.google.com/mhttps://translate.google.com/m
clients2.google.com/service/update2/crxhttps://clients2.google.com/service/update2/crx

Gain full insight into all external connections.

Upgrade for full visibility.

No IP addresses found
Showing 1 to 10 of 10 rows
Rows per page:

Code Diff

Compare extension code between any two versions.

0 changed files (scanned top 25 shared text files)

No comparable text files found between these versions.

Browse and explore files within this extension package

Gain full insight into all external connections.

Upgrade for full visibility.