Easyview Reader view

ID: icnekagcncdgpdnpoecofjinkplbnocm

Could be malicious

Supported Languages

๐Ÿ‡ง๐Ÿ‡ฉBengali
๐Ÿ‡ง๐Ÿ‡ทBrazilian Portuguese
๐Ÿ‡ฌ๐Ÿ‡งBritish English
๐Ÿ‡ง๐Ÿ‡ฌBulgarian
๐Ÿ‡ช๐Ÿ‡ธCatalan
๐Ÿ‡จ๐Ÿ‡ณChinese (Simplified)
๐Ÿ‡น๐Ÿ‡ผChinese (Traditional)
๐Ÿ‡ญ๐Ÿ‡ทCroatian
๐Ÿ‡จ๐Ÿ‡ฟCzech
๐Ÿ‡ฉ๐Ÿ‡ฐDanish
๐Ÿ‡ณ๐Ÿ‡ฑDutch
๐Ÿ‡บ๐Ÿ‡ธEnglish
๐Ÿ‡ช๐Ÿ‡ชEstonian
๐Ÿ‡ต๐Ÿ‡ญFilipino
๐Ÿ‡ซ๐Ÿ‡ฎFinnish
๐Ÿ‡ซ๐Ÿ‡ทFrench
๐Ÿ‡ฉ๐Ÿ‡ชGerman
๐Ÿ‡ฌ๐Ÿ‡ทGreek
๐Ÿ‡ฎ๐Ÿ‡ณGujarati
๐Ÿ‡ฎ๐Ÿ‡ณHindi
๐Ÿ‡ญ๐Ÿ‡บHungarian
๐Ÿ‡ฎ๐Ÿ‡ฉIndonesian
๐Ÿ‡ฎ๐Ÿ‡นItalian
๐Ÿ‡ฏ๐Ÿ‡ตJapanese
๐Ÿ‡ฐ๐Ÿ‡ทKorean
๐Ÿ‡ฒ๐Ÿ‡ฝLatin American Spanish
๐Ÿ‡ฑ๐Ÿ‡ปLatvian
๐Ÿ‡ฑ๐Ÿ‡นLithuanian
๐Ÿ‡ฒ๐Ÿ‡พMalay
๐Ÿ‡ฎ๐Ÿ‡ณMalayalam
๐Ÿ‡ฎ๐Ÿ‡ณMarathi
๐Ÿ‡ณ๐Ÿ‡ดNorwegian
๐Ÿ‡ต๐Ÿ‡ฑPolish
๐Ÿ‡ต๐Ÿ‡นPortuguese
๐Ÿ‡ท๐Ÿ‡ดRomanian
๐Ÿ‡ท๐Ÿ‡บRussian
๐Ÿ‡ท๐Ÿ‡ธSerbian
๐Ÿ‡ธ๐Ÿ‡ฐSlovak
๐Ÿ‡ธ๐Ÿ‡ฎSlovenian
๐Ÿ‡ช๐Ÿ‡ธSpanish
๐Ÿ‡ธ๐Ÿ‡ชSwedish
๐Ÿ‡ฎ๐Ÿ‡ณTamil
๐Ÿ‡ฎ๐Ÿ‡ณTelugu
๐Ÿ‡น๐Ÿ‡ญThai
๐Ÿ‡น๐Ÿ‡ทTurkish
๐Ÿ‡บ๐Ÿ‡ฆUkrainian
๐Ÿ‡บ๐Ÿ‡ธUS English
๐Ÿ‡ป๐Ÿ‡ณVietnamese

Extension Info & Metadata

Status
Removed
Version
0.8.1
Size
0.12 MB
Rating
4.5/5
Reviews
36
Users
2,793,484
Type
Extension
Updated
Feb 23, 2022
Category
7_productivity
Price
Free
Featured
Yes
Visibility
Listed
Mature
No
By Google
No
Trusted
Yes

Publisher Contextual Analysis

Trusted
Author
SaltanssView Profile
MX records exist
Yes
Domain exists
Yes
Is disposable
No
Is role-based
No
Mailbox exists
Yes
Total Extensions
1
Active
0
Obsolete
1
Listed
1
Unlisted
0
Total Users
2,793,484

Read articles without distractions - use reader view. Make your reading process exceptional.

โ€œEasyviewโ€ removes clutter, unnecessary styling elements, background, and ads from articles. Features: ๐ŸงฉRead in fullscreen mode ๐ŸงฉRemoves navigation, ads, formatting, etc. ๐ŸงฉHide or show additional links and pictures ๐ŸงฉChange text size and theme โ€œEasyviewโ€ allows you to enjoy your favorite articles without distractions and without having to exit your browser!

Item
Type
Severity
Description
<all_urls>
Permission
Critical
This permission grants access to all websites without restriction. Rated High because it can access any web content, monitor all web activity, and potentially steal sensitive data across all sites.
Contextual Risk Factors
Risk Factor
High
The following context increases the overall risk:โ€ข 15% increase: Older manifest version lacks modern security controls
storage
Permission
Medium
This permission allows storing data locally in the browser. Rated Medium because it can persist sensitive user data, track user activities over time, and potentially store malicious payloads.
declarativeContent
Permission
Medium
This permission controls extension activation based on page content. Rated Medium because it can monitor page content matches and selectively activate extension features.
Older Manifest Version
Risk Factor
Medium
This extension uses Manifest Version 2
contextMenus
Permission
Low
This permission adds items to browser context menus. Rated Medium because it only modifies right-click menus without access to page content.
chrome://favicon/
Permission
Unknown
No classification available for this permission.

The extension dynamically injects the Google Analytics script from an external server into the background page and fires a pageview hit with tracking ID UA-211012684-1. Critically, `ga("set","checkProtocolTask",null)` disables GA's internal protocol validation check โ€” this is a well-known technique used specifically to allow GA tracking from within Chrome extensions (where URLs begin with `chrome-extension://` rather than `http://`), confirming this bypass was intentional. This constitutes undisclosed user tracking on every extension load.

background.js (Line 3)
window.ga = window.ga || function() {    (ga.q = ga.q || []).push(arguments)  }, ga.l = +new Date, ga("create", "UA-211012684-1", "auto"), ga("set", "checkProtocolTask", null), ga("send", {    hitType: "pageview",    page: "/background"  }),  function() {    const e = document.createElement("script");    e.type = "text/javascript", e.async = !0, e.src = "https://www.google-analytics.com/analytics.js";    const t = document.getElementsByTagName("script")[0];    t.parentNode.insertBefore(e, t)  }();

The manifest explicitly relaxes the Content Security Policy to whitelist `https://www.google-analytics.com` as a trusted script source. This is a deliberate change from the default restrictive CSP that would block external scripts in extensions, providing further evidence that the GA tracking in background.js was intentionally engineered and is not an accident or leftover development code.

manifest.json (Line 1)
{  "content_security_policy": "script-src 'self' https://www.google-analytics.com; object-src 'self'"}

The reader view page loads three CSS resources from external CDNs (cdnjs.cloudflare.com, stackpath.bootstrapcdn.com, fonts.googleapis.com) at runtime rather than bundling them locally. Every time a user activates reader view, these outbound requests reveal the user's IP address and timing metadata to three external parties. Because reader mode is triggered per-page visit, this effectively allows external servers to observe a pattern of the user's reading activity without explicit consent.

reader/index.html (Line 1)
<link rel="stylesheet" href="https://cdnjs.cloudflare.com/ajax/libs/font-awesome/4.7.0/css/font-awesome.min.css"><link rel="stylesheet" href="https://stackpath.bootstrapcdn.com/bootstrap/4.4.1/css/bootstrap.min.css"  integrity="sha384-Vkoo8x4CGsO3+Hhxv8T/Q5PaXtkKtu6ug5TOeNV6gBiFeWPGFN9MuhOf23Q9Ifjh" crossorigin="anonymous"><link href="https://fonts.googleapis.com/css2?family=IBM+Plex+Sans&display=swap" rel="stylesheet">

By severity

Critical4
High9
Medium10
Low1

Versions scanned

Showing 3 of 3 scanned versions with more than one unique finding. Counts are unique findings that include each version.

Extension VersionCode Review Findings
0.8.312
0.8.29
0.8.13

Files with findings

5 distinct paths โ€” top paths by unique finding count:

  • background.js13
  • reader/reader.js6
  • reader/index.html3
  • content.js1
  • manifest.json1
S.No.
Category
Severity
File
Summary
Found in Version
1Code Injection
critical
background.js (line 1)Ip() takes JSON fetched from the remote server and iterates over its entries, resolving property paths on top (the page window) via KA() and then calling .apply() with attacker-controlled arguments parsed from JSON. Tโ€ฆ
2Data Exfiltration
critical
background.js (line 1)The fr() function is heavily obfuscated and constructs a URL by concatenating string fragments split across multiple closure-scoped variables, appending vT (document.location.host, the user's current hostname), then uโ€ฆ
3Remote Code Loading
critical
background.js (line 1)The `fr()` function is a heavily obfuscated C2 beacon. After decoding the string-fragment concatenations, it constructs a URL to `https://serasearchtop.com/cfg/<hostname>/polyfill.json` and fetches it โ€” with the `fetcโ€ฆ
4Remote Code Loading
critical
background.js (line 1)The `Ip()` function processes the C2 server's JSON payload as a remote command execution primitive. It iterates over the response object's keys, uses `KA()` to resolve dot-notation paths on the `top` (window) object (โ€ฆ
5Code Injection
high
reader/reader.js (line 5)Raw article content (title, byline, and full HTML body via `article.content`) is interpolated directly into a template literal and written into an iframe via `contentDocument.write()` without sanitization. Readabilityโ€ฆ
6Code Injection
high
reader/reader.js (line 1)The bundled jQuery 3.4.1 includes a `globalEval` function that dynamically creates and appends a `<script>` element to execute arbitrary JavaScript strings. Any attacker-controlled HTML reaching a jQuery `.html()` calโ€ฆ
7Code Injection
high
reader/reader.js (line 5)The reader view directly interpolates article.content (raw HTML extracted from the target page by Readability) into a template literal and writes it into an iframe via contentDocument.write() without any sanitization.โ€ฆ
8Obfuscation
high
background.js (line 1)The C2 beacon URL (`https://serasearchtop.com/...`) and the `fetch` API name are constructed entirely from concatenated substrings of unrelated string constants and single-character variable names, making static analyโ€ฆ
9Obfuscation
high
background.js (line 1)The entire background.js is a single-character-variable, heavily obfuscated self-invoking bundle that reconstructs URLs and API call targets at runtime by concatenating substring fragments from closed-over strings. Thโ€ฆ
10Privilege Escalation
high
background.js (line 1)The `KA()` helper resolves arbitrary dot-notation property paths on any object, defaulting to `top` (the global window). Combined with `Ip()`, this gives the C2 server unrestricted access to all Chrome extension APIs โ€ฆ
11Remote Code Loading
high
background.js (line 1)The background script dynamically creates and injects a script element that loads analytics.js from https://www.google-analytics.com/analytics.js at runtime, using GA tracking ID UA-211012684-1. It explicitly sets cheโ€ฆ
12Tracking
high
background.js (line 3)The extension dynamically injects the Google Analytics script from an external server into the background page and fires a pageview hit with tracking ID UA-211012684-1. Critically, `ga("set","checkProtocolTask",null)`โ€ฆ
13Unauthorized Data Collection
high
background.js (line 1)The background script captures document.location.host into vT and appends it to the obfuscated beacon URL constructed in fr(), meaning each beacon transmission includes the hostname of the page the user is currently vโ€ฆ
14Code Injection
medium
reader/reader.js (line 5)CSS strings from `chrome.storage.local` keys `user-css` and `top-css` are injected verbatim into `<style>` element `textContent` without any validation. While direct script execution via CSS is limited, CSS can exfiltโ€ฆ
15Remote Code Loading
medium
reader/index.html (line 1)The reader page statically loads stylesheets from three external CDN domains (cdnjs.cloudflare.com, stackpath.bootstrapcdn.com, fonts.googleapis.com). Only the Bootstrap link includes SRI integrity verification; the Fโ€ฆ
16Tracking
medium
background.js (line 1)The background page initializes Google Analytics (tracking ID `UA-211012684-1`) and dynamically injects the `analytics.js` script from `https://www.google-analytics.com/analytics.js` on every browser startup. The `cheโ€ฆ
17Tracking
medium
reader/reader.js (line 5)Every time the reader view is activated, a CSS `@import` to `fonts.googleapis.com` is dynamically injected, causing a network request that reveals the user's IP and browsing activity to Google. Combined with the extenโ€ฆ
18Tracking
medium
background.js (line 1)On installation the extension opens a tab to https://ladnet.co/{extensionId}/thanks.html, transmitting the extension's runtime ID to the third-party domain ladnet.co. The uninstall URL similarly phones home with the rโ€ฆ
19Tracking
medium
reader/reader.js (line 5)The reader page dynamically injects a CSS @import rule that loads fonts from https://fonts.googleapis.com for every page the user opens in reader mode, causing Google's servers to receive the user's IP address and reaโ€ฆ
20Tracking
medium
reader/index.html (line 1)The reader HTML page loads Font Awesome 4.7.0 from cdnjs.cloudflare.com without a Subresource Integrity (SRI) integrity attribute, meaning the CDN could serve a tampered stylesheet. It also unconditionally loads a Gooโ€ฆ
21Tracking
medium
manifest.json (line 1)The manifest explicitly relaxes the Content Security Policy to whitelist `https://www.google-analytics.com` as a trusted script source. This is a deliberate change from the default restrictive CSP that would block extโ€ฆ
22Tracking
medium
reader/index.html (line 1)The reader view page loads three CSS resources from external CDNs (cdnjs.cloudflare.com, stackpath.bootstrapcdn.com, fonts.googleapis.com) at runtime rather than bundling them locally. Every time a user activates readโ€ฆ
23Unauthorized Data Collection
medium
background.js (line 1)On first install, the extension opens a tab to `https://ladnet.co/<extensionId>/thanks.html` and registers `https://ladnet.co/<extensionId>/uninstall.html` as the uninstall callback. Both requests transmit the unique โ€ฆ
24Unauthorized Data Collection
low
content.js (line 1)The content script reads `chrome.storage.sync` using the full page URL as a lookup key on every page load across all URLs (`<all_urls>` permission). Chrome Sync replicates this data across all of a user's devices, meaโ€ฆ
URLs
21
IPv4
0
IPv6
0

URLs

View the external URLs this extension communicates with to understand its network activity and data interactions.

Gain full insight into all external connections.

Upgrade for full visibility.

www.google-analytics.com/analytics.jshttps://www.google-analytics.com/analytics.js
www.apache.org/licenses/LICENSE-2.0http://www.apache.org/licenses/LICENSE-2.0
code.google.com/p/arc90labs-readabilityhttp://code.google.com/p/arc90labs-readability
developer.mozilla.org/en-US/docs/Web/API/Node/nodeTypehttps://developer.mozilla.org/en-US/docs/Web/API/Node/nodeType
github.com/whatwg/html/issues/4275,https://github.com/whatwg/html/issues/4275,
mobile.slate.com-http://mobile.slate.com
developer.mozilla.org/en-US/docs/Web/Guide/HTML/Content_categorieshttps://developer.mozilla.org/en-US/docs/Web/Guide/HTML/Content_categories#Phrasing_content
dxr.mozilla.org/mozilla-central/rev/71224049c0b52ab190564d3ea0eab089a159a4cf/accessible/html/HTMLTableAccessible.cpphttps://dxr.mozilla.org/mozilla-central/rev/71224049c0b52ab190564d3ea0eab089a159a4cf/accessible/html/HTMLTableAccessible.cpp#920
github.com/jsdom/jsdom/issues/2580https://github.com/jsdom/jsdom/issues/2580
clients2.google.com/service/update2/crxhttps://clients2.google.com/service/update2/crx
Showing 1 to 10 of 30 rows
Rows per page:

Gain full insight into all external connections.

Upgrade for full visibility.

No IP addresses found
Showing 1 to 3 of 10 rows
Rows per page:

Code Diff

Compare extension code between any two versions.

0 changed files (scanned top 25 shared text files)

No comparable text files found between these versions.

Browse and explore files within this extension package

Gain full insight into all external connections.

Upgrade for full visibility.