Chrome Web Store
39Versions
1Code reviewed

Caution required

Suspicious in code review (v7.0.5)

Our reviewer found behaviour consistent with malware in version 7.0.5, but not enough to confirm it. Treat this extension as untrusted until it has been re-reviewed.

44 indicators in this extension

44 indicators
1 version analysed

Every finding is verified by a security analyst. Unlock the code evidence, indicators and version history.

Unlock this report — $4.99Start 7-day trial — all reports
One-time payment · Secure checkout by Stripe

What our analysis found

CrxMouse: Mouse Gestures, used by 700,000 people, is rated caution by Extension Auditor. Our code review reported 3 findings (2 critical, 1 high), led by network interception. Its permissions mean it can read and change data on all websites, can inject scripts into pages and can observe network requests.

Key findings

  • Critical

    Network Interception

    The code overrides native WebSocket, fetch, and XHR constructors to capture all response data from any webpage. It dispatches the data via custom events, which are then processed by the extension's rule engine. This allows the extension to intercept and exfiltrate network traffic without user consent.

  • Critical

    Data Exfiltration

    The WwI module loads rules from extension storage, checks if the current page matches a target URL, and if so, sets a localStorage hash to enable the network interception defined in. It then subscribes to the intercepted data and processes it using a rule engine, eventually sending the extracted information via a background message. This indicates the extension can be remotely configured to intercept and exfiltrate data from specific websites.

  • High

    Data Exfiltration

    The Zeh module scrapes web page content based on rules fetched from extension storage. It extracts data from the DOM using a custom rule engine and, if certain conditions are met, sends the extracted data to the background via chrome.runtime.sendMessage. This allows the extension to exfiltrate page contents without clear user disclosure.

Analyst notes

The extension contains code to intercept all fetch, XHR, and WebSocket responses on any website, dispatch captured data to internal listeners, and exfiltrate it via background service worker. It also scrapes page content based on locally stored rules. This behavior is not disclosed in the CWS description or the listed data collection categories (Web history, User activity), and is unnecessary for the stated mouse gesture functionality. The ML risk score of 0.00 is likely a false negative due to the extension's benign appearance and user base.

CrxMouse: Mouse Gestures

CrxMouse: Mouse Gestures Chrome extension security report

ID: jlgkpaicikihijadgifklkbpdajbkhjo

Supported Languages

🇨🇳Chinese (Simplified)
🇹🇼Chinese (Traditional)
🇩🇰Danish
🇳🇱Dutch
🇺🇸English
🇫🇮Finnish
🇫🇷French
🇩🇪German
🇮🇳Hindi
🇯🇵Japanese
🇰🇷Korean
🇳🇴Norwegian
🇸🇪Swedish

Extension Info & Metadata

Status
Active
Version
7.7.0
Size
7.73 MB
Rating
4.4/5
Reviews
11,570
Users
700,000
Type
Extension
Updated
Sep 25, 2026
Category
Workflow & planning
Price
Free
Featured
Yes
Visibility
Listed
Mature
No
By Google
No
Trusted
Yes
This publisherTrack record
1extension
All still listed

Publisher Contextual Analysis

Trusted
Author
https://crxmouse.com/
MX records exist
Yes
Domain exists
Yes
Is disposable
No
Is role-based
Yes
Mailbox exists
Yes
Website
Visit
Extensions
1
Active
1
Obsolete
0
Listed
1
Unlisted
0
Users
700,000

Screenshots & videos

Screenshot 2
Screenshot 3
Screenshot 4
Screenshot 5
Screenshot 6

Install growth

Item
Type
Severity
Description
webRequest
Permission
Critical
This permission enables the extension to monitor and analyze all web requests made by the browser. Rated Critical because it can observe all network traffic including sensitive data, track browsing behavior, and gather authentication tokens.
scripting
Permission
Critical
This permission allows injection and execution of JavaScript on any webpage. Rated Critical because it can modify page content, steal sensitive data, and inject malicious code into any site the extension has access to.
*://*/*
Host
Critical
Broad host access — the extension can read/modify content on every website.
<all_urls>
Host
Critical
Broad host access — the extension can read/modify content on every website.
Dangerous Permission Combination: scripting,<all_urls>,webRequest
Risk Factor
Critical
Enables sophisticated data theft through script injection and traffic monitoring
webNavigation
Permission
High
This permission enables monitoring of all browser navigation events and transitions. Rated High because it can track every page visit, navigation method, and browsing pattern, potentially exposing sensitive browsing behavior and user activities.
clipboardRead
Permission
High
This permission allows reading clipboard content. Rated High because it can steal copied passwords, sensitive data, and monitor all content copied to clipboard.
clipboardWrite
Permission
High
This permission allows modification of clipboard content. Rated High because it can inject malicious content into the clipboard, modify copied passwords, and manipulate copied data.
sessions
Permission
High
This permission accesses recently closed tabs and windows. Rated High because it can monitor user activity, recover closed sensitive pages, and track browsing patterns.
Contextual Risk Factors
Risk Factor
High
The following context increases the overall risk:• 10% increase: Early script execution enables pre-emptive content manipulation• 10% increase: About:blank access enables potential sandbox escape vectors
Broad Host Permissions
Risk Factor
High
This extension has broad host permissions allowing it to access many or all websites.
Broad Content Script Access
Risk Factor
High
This extension can inject scripts into any website.
tabs
Permission
Medium
This permission enables tab management and monitoring. Rated Medium because it can track open tabs, access tab metadata, and monitor user browsing patterns.
storage
Permission
Medium
This permission allows storing data locally in the browser. Rated Medium because it can persist sensitive user data, track user activities over time, and potentially store malicious payloads.
unlimitedStorage
Permission
Medium
This permission removes storage quota restrictions. Rated Medium because it can store large amounts of user data without limits, potentially impacting browser performance and storing extensive tracking data.
Early Content Script Execution
Risk Factor
Medium
This extension runs content scripts at document_start.
About:blank Access
Risk Factor
Medium
This extension can run content scripts in about:blank pages.
contextMenus
Permission
Low
This permission adds items to browser context menus. Rated Medium because it only modifies right-click menus without access to page content.
bookmarks
Permission
Low
This permission manages browser bookmarks and folders. Rated Low because it can only modify bookmark data, which is not sensitive and changes are visible to users.
alarms
Permission
Low
This permission schedules periodic tasks. Rated Low because it can only trigger events at specified times without access to sensitive data.

44 indicators in this extension

44 indicators
1 version analysed

Every finding is verified by a security analyst. Unlock the code evidence, indicators and version history.

Unlock this report — $4.99Start 7-day trial — all reports
One-time payment · Secure checkout by Stripe

About this extension

Boost browsing productivity with mouse gestures! Super Drag, Wheel & more for effortless navigation.

Read the publisher’s full description

Take control of your browsing with intuitive mouse gestures! CrxMouse supercharges your web experience with powerful mouse shortcuts. Effortlessly navigate, search, and open tabs with simple hand movements, saving you clicks and boosting your browsing efficiency. CrxMouse makes browsing: 🏎️ Faster: Navigate webpages and open links in a flash with customizable mouse gestures. 🖱️ Simpler: Ditch the keyboard shortcuts! Intuitive mouse movements take the effort out of browsing. 🕒 More Productive: Spend less time clicking and more time getting things done. CrxMouse offers: ⚙️ Easy-to-use mouse gestures: Get started quickly with pre-built options or create your own custom shortcuts. 🔎 Super drag: Drag links to open new tabs, copy text and URLs, and search in new tabs. 👆 Cursor Customization: Make browsing yours! Upload your own mouse cursor image for a unique and personalized touch. Take your browsing to the next level with CrxMouse! **Our service is free. No paid edition or account and no advertisements. Please note: Mouse gesture navigation doesn't work on Chrome's built-in pages because of Google's security restrictions. Mouse Gesture Built-in Actions: Press + Hold Right Button (anywhere on the screen) and Drag to perform the following: ↓→ : close current tab ↓→↑ : open a new window ← : back ←↑ : reopen closed tabs → : forward →↓ : scroll to bottom →↑ : scroll to top ↑ : scroll up one page ↑↓ : refresh ↑↓↑ : force a refresh ↑← : move to the left tab ↑→ : move to the right tab ↓→↓ : close current window -------------------------------- Super Drag Built-in Actions: Press + Hold Left Button and drag links to perform the following actions: → : open link in a new tab ← : open link in a new tab (background) ←↓→ : copy text →↓← : copy URL Press + Hold Left Button and drag text to perform the following actions: ← : search in new tab (background) → : search in a new tab -------------------------------- Wheel Gestures Built-in Actions: Press + Hold Right Button and scroll to perform the following actions: ↑: scroll to top Press + Hold Left Button and Scroll to perform the following actions: ↓: scroll to bottom Try these mouse gestures on our game - The Mouse Chase! 🐭 https://crxmouse.com/the-mouse-chase-1/ -------------------------------- We care greatly about your privacy. For more information, please read our privacy policy: https://crxmouse.com/privacy/

User reviews

Extension files

Browse and explore files within this extension package

Gain full insight into all external connections.

Upgrade for full visibility.

URLs
44

URLs

View the external URLs this extension communicates with to understand its network activity and data interactions.

No URLs found
No IP addresses found

44 indicators in this extension

44 indicators
1 version analysed

Every finding is verified by a security analyst. Unlock the code evidence, indicators and version history.

Unlock this report — $4.99Start 7-day trial — all reports
One-time payment · Secure checkout by Stripe
Version
Size
Verdict
Findings
Permhash
7.7.0
Latest
7.73 MBNot scanned—
0aac09c0232e034d10d7cb9a5169e52038813e99b9dafa78eb168598930589a1
7.6.4
7.66 MBNot scanned—
0aac09c0232e034d10d7cb9a5169e52038813e99b9dafa78eb168598930589a1
7.4.1
7.66 MBNot scanned—
0aac09c0232e034d10d7cb9a5169e52038813e99b9dafa78eb168598930589a1
7.4.0
7.66 MBNot scanned—
0aac09c0232e034d10d7cb9a5169e52038813e99b9dafa78eb168598930589a1
7.3.4
16.36 MBNot scanned—
0aac09c0232e034d10d7cb9a5169e52038813e99b9dafa78eb168598930589a1
7.3.3
16.35 MBNot scanned—
0aac09c0232e034d10d7cb9a5169e52038813e99b9dafa78eb168598930589a1
7.3.2
16.35 MBNot scanned—
0aac09c0232e034d10d7cb9a5169e52038813e99b9dafa78eb168598930589a1
7.2.1
16.18 MBNot scanned—
0aac09c0232e034d10d7cb9a5169e52038813e99b9dafa78eb168598930589a1
7.0.5
16.13 MBCaution0
0aac09c0232e034d10d7cb9a5169e52038813e99b9dafa78eb168598930589a1
6.4.2
1.24 MBNot scanned—
ff0ad971589a425a56965da25903374e90c4572ede3278b04136a57ce35ecdb3
Showing 1 to 10 of 40 rows
Rows per page:

Code Diff

Compare extension code between any two versions.

0 changed files detected

No comparable text files found between these versions.

Gain full insight into all external connections.

Upgrade for full visibility.

Popular in Workflow & Planning