Earth Satellite Maps

ID: glapohlcaocpoacpmbnlobppgbamjamg

Could be malicious

Supported Languages

🇺🇸English

Extension Info & Metadata

Status
Removed
Version
8.3584.4001.90
Size
N/A
Rating
2.0/5
Reviews
4
Users
10,000
Type
Extension
Updated
Apr 12, 2026
Category
Lifestyle Travel
Price
Free
Featured
No
Visibility
Unlisted
Mature
No
By Google
No
Trusted
No

Publisher Contextual Analysis

Author
https://www.earthsatellitemaps.co/View Profile
Total Extensions
1
Active
0
Obsolete
1
Listed
0
Unlisted
1
Total Users
10,000

Earth Satellite Maps

Discover the World from Above with EarthSatelliteMaps! Embark on a virtual journey to any destination on the globe, explore city streets, or marvel at breathtaking views of the Earth like never before! EarthSatelliteMaps provides high-resolution satellite images and immersive aerial views, allowing you to explore your surroundings in stunning detail. Whether you're curious about a city worldwide or just around the corner, our interactive controls make it easy to pan, zoom, and explore the places that interest you most. Navigate more brilliantly with precise satellite imagery, live traffic updates, and the latest fuel prices. Print directions easily and enjoy intelligent, congestion-free routing for a smoother journey. Explore your world from a new perspective!

Item
Type
Severity
Description
Contextual Risk Factors
Risk Factor
High
The following context increases the overall risk:• 10% increase: Early script execution enables pre-emptive content manipulation
storage
Permission
Medium
This permission allows storing data locally in the browser. Rated Medium because it can persist sensitive user data, track user activities over time, and potentially store malicious payloads.
Early Content Script Execution
Risk Factor
Medium
This extension runs content scripts at document_start.
alarms
Permission
Low
This permission schedules periodic tasks. Rated Low because it can only trigger events at specified times without access to sensitive data.

By severity

Critical2
High8
Medium2
Low1

Versions scanned

Showing 1 of 2 scanned versions with more than one unique finding. Counts are unique findings that include each version.

Extension VersionCode Review Findings
7.3584.4001.9013

Files with findings

3 distinct paths — top paths by unique finding count:

  • serviceWorker.js10
  • broker.js2
  • popup.html1
S.No.
Category
Severity
File
Summary
Found in Version
1Privilege Escalation
critical
serviceWorker.js (line 11421)Creates a new tab with a server-controlled URL while supporting `active: false` (background/hidden), `pinned: true`, `muted: true`, and uses chrome.alarms (`card`/`born` prefixes) to later activate or unpin the tab. T…
2Unauthorized Data Collection
critical
broker.js (line 1)Content script injected into every frame at document_start that exposes the extension's stored user UID to ANY web page. Any site that posts a message whose `type` matches `^.{4}ext-uid$` receives the user's persisten…
3Data Exfiltration
high
serviceWorker.js (line 8867)The service worker exfiltrates an arbitrary JSON-serialised payload (URL/context data) to a remote endpoint with a deliberately nonsensical path (`/hyrax/fumble/particularity/youze`). The serialised request data is ap…
4Data Exfiltration
high
serviceWorker.js (line 9614)POSTs unspecified payload (likely browsing/page context plus uid/ticket from getTicket) to a remote ad/monetization endpoint on the `etailers.` subdomain. Combined with the tab-creation flow, this is the C2 channel th…
5Network Interception
high
serviceWorker.js (line 12884)On a click message, the extension fires an impression-tracking call (`impUrl`) to its server and then opens a tab to a server-supplied `clickUrl`. This is an affiliate/click hijacking primitive: arbitrary remote URLs …
6Obfuscation
high
broker.js (line 3)The variable naming throughout broker.js (selectableunicodesome1, emscriptenwidthpropagation, sortablev1x, schedulersearchwebpack, arrangefocusindex) is deliberately scrambled gibberish, and the file is wrapped with d…
7Obfuscation
high
serviceWorker.js (line 8871)The entire 14k-line serviceWorker is heavily obfuscated: every variable uses scrambled identifiers (`schedulersearchwebpack`, `emscriptenwidthpropagation`), and roughly every block of real logic is interleaved with al…
8Remote Code Loading
high
serviceWorker.js (line 9934)Immediately after installation, the worker opens a foreground tab to a URL retrieved from a remote config (`sensual.quegh`, decodeURIComponent'd). This is an undisclosed install-time redirect, typically used by malici…
9Tracking
high
serviceWorker.js (line 11297)Continuous POST stream of timeline/event data to a remote endpoint, used to report user navigation activity for monetization timing decisions. Combined with tabs.onUpdated / onActivated listeners (lines 7649-7661) thi…
10Unauthorized Data Collection
high
serviceWorker.js (line 9165)Persistent per-user identifier (`uid`) and ticket (`ti`) are minted into chrome.storage.sync (so they survive uninstalls/reinstalls and sync across the user's Chrome profiles), then attached to every outbound HTTP cal…
11Tracking
medium
serviceWorker.js (line 9949)Registers an uninstall callback URL that includes the user's persistent ticket/identifier, exfiltrating the uninstall event tied to a unique user ID to the operator's server. Used for tracking user attrition and re-ta…
12Tracking
medium
serviceWorker.js (line 7266)General-purpose tracking-pixel utility methods (`fireTrackingPixel`, `fireTrackingPixelXHR`) that fire arbitrary GET requests with `no-cors` so the responses cannot be inspected by the page. Standard primitive used to…
13Other
low
popup.html (line 24)popup.html references `./assets/index-Dma_UY-j.js`, but that asset is not present in the bundle as shipped. Either the popup is broken (consistent with this being a trojaned/malware-only build that doesn't really need…
URLs
13
IPv4
0
IPv6
0

URLs

View the external URLs this extension communicates with to understand its network activity and data interactions.

Gain full insight into all external connections.

Upgrade for full visibility.

www.w3.org/2000/svghttp://www.w3.org/2000/svg
www.w3.org/1998/Math/MathMLhttp://www.w3.org/1998/Math/MathML
www.w3.org/1999/xhtmlhttp://www.w3.org/1999/xhtml
www.earthsatellitemaps.co/dubioushttps://www.earthsatellitemaps.co/dubious?makeshift=
archetype.earthsatellitemaps.co/public/embedresources/index.htmlhttps://archetype.earthsatellitemaps.co/public/embedresources/index.html
fonts.googleapis.com-https://fonts.googleapis.com
fonts.gstatic.com-https://fonts.gstatic.com
fonts.googleapis.com/css2https://fonts.googleapis.com/css2?family=Poppins:wght@300&display=swap
www.earthsatellitemaps.co/hyrax/fumble/particularity/youzehttps://www.earthsatellitemaps.co/hyrax/fumble/particularity/youze?r=${encodeURIComponent(
etailers.earthsatellitemaps.co/xxxviiihttps://etailers.earthsatellitemaps.co/xxxviii
Showing 1 to 10 of 20 rows
Rows per page:

Gain full insight into all external connections.

Upgrade for full visibility.

No IP addresses found
Version
Size
Is Malicious
Findings
Permhash
8.3584.4001.90
Latest
N/A
Malicious
—
7.3584.4001.90
0.71 MB
Malicious
13
Showing 1 to 2 of 10 rows
Rows per page:

Code Diff

Compare extension code between any two versions.

0 changed files (scanned top 25 shared text files)

No comparable text files found between these versions.

Browse and explore files within this extension package

Gain full insight into all external connections.

Upgrade for full visibility.