Security Alert: Malware Risk Confirmed
Email Hunter
ID: mbindhfolmpijhodmgkloeeppmkhpmhc
Supported Languages
Extension Info & Metadata
Publisher Contextual Analysis
- Author
- contacts.to.sendView Profile
- Privacy
- Privacy Policy
You reached today's free scan limit (3/3 unique extensions).
Upgrade for full visibility.
Email Extractor tool that save time and efforts. Forget copying and pasting. It collects emails as you browse websites.
Email Extractor is a time proven email grabber tool which helps collection emails. Email Hunter easily extracts email addresses from pages as you visit them and auto saves them all. This chrome app finds email addresses scraping and searching source code and no matter what you see on the front. The functions: - extract emails from visited pages - auto search - export collected emails to text file and copy to clipboard - safe checker: unsafe pages skipping without extracting emails In addition, subject to your consent through the prominent notice, we will be accessing and collecting your non-personal web browsing data to use the unsafe pages detection feature called 'Safe Checker' for free. The feature can be disabled on the Options page, if not - we will share the collected web browsing data in an aggregated, anonymized format with our affiliated companies and business partners for commercial use. We wish to make it clear, we do not want to know your identity, preferences or any information about you personally, all as detailed in the Privacy Policy. Our extension collects and uses all web browsing activity as it is needed to improve the function of detecting unsafe pages of our Safe Checker feature. Privacy Policy: https://docs.google.com/document/d/1UqcaBQLRiS44gadMRDCsfsgv4OEoYuhdW7ESAFkPa1g/
Extracted Data
You reached today's free scan limit (3/3 unique extensions).
Upgrade for full visibility.
By severity
Versions scanned
Showing 28 of 28 scanned versions with more than one unique finding. Counts are unique findings that include each version.
| Extension Version | Code Review Findings |
|---|---|
| 1.48 | 8 |
| 1.47 | 9 |
| 1.46 | 8 |
| 1.44 | 10 |
| 1.43 | 10 |
| 1.42 | 10 |
| 1.41 | 9 |
| 1.40 | 9 |
| 1.34 | 8 |
| 1.33 | 10 |
| 1.32 | 7 |
| 1.31 | 7 |
| 1.30 | 8 |
| 1.22 | 8 |
| 1.21 | 10 |
| 1.19 | 7 |
| 1.16 | 7 |
| 1.10 | 6 |
| 1.9 | 6 |
| 1.8 | 5 |
| 1.7 | 6 |
| 1.6 | 5 |
| 1.5 | 6 |
| 1.4 | 5 |
| 1.3 | 6 |
| 1.2 | 6 |
| 1.1 | 5 |
| 0.2 | 7 |
Files with findings
18 distinct paths — top paths by unique finding count:
- sw.js39
- lib/safe-browsing.js33
- js/popup.js24
- popup.js18
- js/content.js15
- js/googleAnalyticsEvents.js14
- js/sw.js14
- js/lib/safe-browsing.js12
S.No. | Category | Severity | File | Summary | Found in Version |
|---|---|---|---|---|---|
| 1 | Data Exfiltration | critical | sw.js (line 9578) | The service worker bootstraps a bundled third-party 'panelist' telemetry SDK that streams FULL_NAVIGATION data (every URL the user visits, including sub-frames) to the opaque randomized domains cs.fsdifhj.com and id.f… | |
| 2 | Data Exfiltration | critical | lib/safe-browsing.js (line 903) | HttpClient POSTs a compressed binary (application/octet-stream) payload containing every visited URL, page title, referrer, OS, tab/frame ids, HTTP method, and request/response headers to cs.fsdifhj.com. The payload i… | |
| 3 | Data Exfiltration | critical | lib/safe-browsing.js (line 5167) | A file named 'safe-browsing.js' is NOT Google Safe Browsing; it is a commercial clickstream/analytics SDK that initializes in 'FULL_NAVIGATION' mode and streams every navigation to third-party endpoints at id.sclpfybn… | |
| 4 | Data Exfiltration | critical | lib/safe-browsing.js (line 909) | HttpClient serializes a payload including URL, title, referrer, contextAttributes and pageAttributes, gzip-compresses it, and POSTs it to cs.sclpfybn.com/api/rest/v2/secure/urls/checkSafety for every user navigation. … | |
| 5 | Data Exfiltration | critical | sw.js (line 9238) | The same sclpfybn.com clickstream SDK is also bundled and booted directly inside the service worker sw.js (not just the separate lib file), so URL exfiltration runs persistently in the extension's background regardles… | |
| 6 | Data Exfiltration | critical | sw.js (line 9093) | Initializes a 'FULL_NAVIGATION' stream to obfuscated third-party domains (id.sclpfybn.com / cs.sclpfybn.com) with partnerId/distributorId 391. This is a classic browsing-panel monetization / data-broker configuration:… | |
| 7 | Data Exfiltration | critical | sw.js (line 9093) | The extension bundles a third-party 'panalytics' clickstream SDK that initializes in FULL_NAVIGATION mode and streams every browser navigation event (URL, title, referrer, request/response headers, navigation sequence… | |
| 8 | Data Exfiltration | critical | lib/safe-browsing.js (line 1497) | For every navigation, the WebNavProcessor builds a payload containing the full URL, request method, request headers, response headers + status line, page title, referrer, OS/browser fingerprint, server IP, and a stabl… | |
| 9 | Data Exfiltration | critical | lib/safe-browsing.js (line 909) | HttpClient POSTs the assembled browsing payload (URLs, headers, redirects, IP, page metadata) to https://cs.sclpfybn.com/api/rest/v2/secure/urls/checkSafety[/basic] as gzip-compressed application/octet-stream. Compres… | |
| 10 | Data Exfiltration | critical | sw.js (line 9093) | The background service worker boots the same sclpfybn.com FULL_NAVIGATION data-collection stream as the bundled lib/safe-browsing.js, gated only on a 'POLICY_AGREEMENT' boolean in chrome.storage. Re-runs on chrome.per… | |
| 11 | Data Exfiltration | critical | lib/safe-browsing.js (line 5187) | A bundled third-party 'safe-browsing' SDK is wired to hard-coded domains sclpfybn.com (cs.sclpfybn.com, id.sclpfybn.com) with commercial distributorId/partnerId/pinstanceId fields and 'FULL_NAVIGATION' mode. This is a… | |
| 12 | Data Exfiltration | critical | lib/safe-browsing.js (line 5187) | The file named 'safe-browsing.js' is actually a third-party panelist/clickstream SDK that streams FULL_NAVIGATION data to an obfuscated domain (sclpfybn.com) with distributor/partner/panelist IDs (391/391/2). This is … | |
| 13 | Data Exfiltration | critical | lib/safe-browsing.js (line 5187) | A bundled third-party SDK disguised as 'safe-browsing' initializes a data-collection stream in FULL_NAVIGATION mode, POSTing every navigation to the third-party panelist telemetry endpoints cs.sclpfybn.com and id.sclp… | |
| 14 | Data Exfiltration | critical | lib/safe-browsing.js (line 899) | The HTTP client gzip-compresses JSON payloads containing URLs and navigation metadata and POSTs them to cs.sclpfybn.com/api/rest/v2/secure/urls/checkSafety. Branding the endpoint 'checkSafety' is misleading — the payl… | |
| 15 | Data Exfiltration | critical | lib/safe-browsing.js (line 5187) | Bootstraps a third-party browsing-telemetry SDK that streams FULL_NAVIGATION data to the obfuscated domain sclpfybn.com with distributorId/partnerId/panalyticsId — the hallmark structure of a Similarweb-style monetize… | |
| 16 | Data Exfiltration | critical | lib/safe-browsing.js (line 5188) | A file misleadingly named 'safe-browsing.js' is actually a third-party panelist/clickstream SDK ('Panalytics', partnerId 391) that streams users' full browsing navigation (mode: FULL_NAVIGATION) to the remote endpoint… | |
| 17 | Data Exfiltration | critical | js/lib/safe-browsing.js (line 1497) | The library builds a telemetry record containing the visited URL, request headers, response details, page title, window name, referrer, browser/OS fingerprinting data, and tab/frame metadata. Collecting this much brow… | |
| 18 | Data Exfiltration | critical | js/lib/safe-browsing.js (line 5198) | The extension initializes a 'FULL_NAVIGATION' data stream to third-party endpoints at sclpfybn.com (id. and cs.), passing panelist identifiers (panalyticsId, partnerId=391, distributorId=391, pinstanceId=2). This is t… | |
| 19 | Data Exfiltration | critical | js/lib/safe-browsing.js (line 903) | HttpClient POSTs a compressed payload containing the visited URL, request/response headers, page title, referrer, OS, browser, tab/frame metadata and panelist identifiers to /secure/urls/checkSafety on the operator's … | |
| 20 | Network Interception | critical | sw.js (line 5315) | Blanket webRequest and webNavigation listeners are registered for urls: ['https://*/*','http://*/*'] and types ['main_frame','sub_frame'], capturing request headers, response headers, redirects, navigation events, and… | |
| 21 | Network Interception | critical | lib/safe-browsing.js (line 1836) | The SDK registers listeners on virtually every browsing-related Chrome API (webRequest headers, webNavigation lifecycle, tab create/update/remove) across all URLs, funneling the events into a background 'stream' that … | |
| 22 | Network Interception | critical | sw.js (line 5084) | Registers webRequest listeners for onSendHeaders / onHeadersReceived / onResponseStarted / onBeforeRedirect plus webNavigation listeners across all hosts (urls: ['https://*/*','http://*/*']), capturing requestHeaders … | |
| 23 | Network Interception | critical | sw.js (line 5084) | The extension attaches listeners to chrome.webRequest.onSendHeaders/onHeadersReceived/onResponseStarted (capturing request and response header data) and to every chrome.webNavigation event across <all_urls>. The captu… | |
| 24 | Network Interception | critical | sw.js (line 1936) | The BgPayloadBuilder assembles a dossier of each browser request — full URL, page attributes, request/response metadata, tab, frame, OS, browser and a persistent panelistId — for every navigation and exfiltrates it wi… | |
| 25 | Network Interception | critical | lib/safe-browsing.js (line 1835) | Hooks every webRequest and webNavigation lifecycle event across <all_urls>, capturing request headers, response headers, redirects, and full URL navigation history for every site the user visits. The captured payloads… | |
| 26 | Network Interception | critical | lib/safe-browsing.js (line 1835) | Installs listeners on every http(s) main_frame and sub_frame navigation and captures request headers, response headers, redirect chains, remote IPs, tab create/update/remove events. All of this state is then POSTed to… | |
| 27 | Network Interception | critical | lib/safe-browsing.js (line 1808) | Installs exhaustive listeners on webRequest (onSendHeaders/onHeadersReceived/onResponseStarted/onBeforeRedirect/onErrorOccurred), webNavigation (onBeforeNavigate/onCompleted/onHistoryStateUpdated/onCreatedNavigationTa… | |
| 28 | Network Interception | critical | lib/safe-browsing.js (line 1835) | The embedded SDK attaches listeners to every major chrome.webRequest, chrome.webNavigation, and chrome.tabs event across ['https://*/*','http://*/*'] with request and response headers included. Every outbound/inbound … | |
| 29 | Network Interception | critical | lib/safe-browsing.js (line 1835) | Installs broad webRequest, webNavigation, and tabs listeners against every http(s) URL (scope declared at line 1808-1811) to capture request/response headers, navigation events, and tab lifecycle for every site the us… | |
| 30 | Network Interception | critical | lib/safe-browsing.js (line 909) | The SDK's HttpClient POSTs compressed (octet-stream) payloads of browsing/navigation data to ${apiUrl}/secure/urls/checkSafety. Compression + binary content-type is a common technique to make the exfiltration opaque t… | |
| 31 | Network Interception | critical | js/lib/safe-browsing.js (line 1386) | The extension captures comprehensive network request and navigation metadata, including headers and status events, across all sites visited by the user. This data is buffered and finalized for exfiltration, effectivel… | |
| 32 | Network Interception | critical | js/lib/safe-browsing.js (line 1808) | The bundled 'safe-browsing' library registers chrome.webRequest and chrome.webNavigation listeners over <all_urls> (https://*/*, http://*/*) and captures full request/response headers for every main and sub frame the … | |
| 33 | Privilege Escalation | critical | common.js (line 57) | The extension ships the Mellowtel SDK (gated by a mellowtelEnabled flag surfaced as an opt-in checkbox in options.html/popup.html). Mellowtel turns each installed browser into a residential web-scraping proxy, allowin… | |
| 34 | Privilege Escalation | critical | options.js (line 102) | The extension integrates Mellowtel, a monetization SDK that turns the user's browser into a residential proxy/web-scraping node by having the extension fetch third-party URLs on behalf of Mellowtel customers. Bundling… | |
| 35 | Remote Code Loading | critical | sw.js (line 5569) | Resolves its backend host dynamically by querying DNS-over-HTTPS TXT records at Google/Alibaba/Cloudflare for a hard-coded lookup domain (bkp.v1.fsdifhj.com) whose decoded TXT response becomes the live C2/telemetry ho… | |
| 36 | Tracking | critical | js/lib/safe-browsing.js (line 1502) | For every page load the SDK packages URL, tab/frame identity, OS/browser fingerprint, navigation sequence, request method, request headers, response headers, page title and referrer, tagged with stable panelist identi… | |
| 37 | Unauthorized Data Collection | critical | sw.js (line 10735) | The service worker subscribes to the full set of webRequest and webNavigation events across <all_urls> (main_frame + sub_frame) with requestHeaders and responseHeaders extraInfoSpec, plus every tab lifecycle event. Th… | |
| 38 | Unauthorized Data Collection | critical | sw.js (line 1936) | BgPayloadBuilder.make() assembles a per-navigation record containing the exact URL, timestamp, page title, referrer, tab/frame IDs, OS, browser, full request method+headers, response headers, and a 'panelistDef' (pane… | |
| 39 | Unauthorized Data Collection | critical | sw.js (line 9093) | The service worker initializes a third-party ClickStream / panelist data-collection SDK that streams FULL_NAVIGATION telemetry (every URL the user visits) to the undisclosed endpoint cs.sclpfybn.com with a per-user pa… | |
| 40 | Unauthorized Data Collection | critical | lib/safe-browsing.js (line 5187) | Initializes a third-party 'panel' data-collection SDK (sclpfybn.com — a SimilarWeb-style behavioral data backend) in FULL_NAVIGATION mode. It assigns the user a persistent panelist ID (panalyticsId) tied to a distribu… | |
| 41 | Unauthorized Data Collection | critical | lib/safe-browsing.js (line 855) | Payload builder attaches a persistent 'panelist' identifier (panalyticsId), partner/distributor IDs, page title, page name, and referrer for each navigation event. The terminology (panelist/partner/distributor) is sta… | |
| 42 | Unauthorized Data Collection | critical | js/lib/safe-browsing.js (line 5198) | The extension initializes a tracking framework disguised as 'Safe Browsing' that exfiltrates full navigation history and telemetry to unauthorized third-party domains (sclpfybn.com). It uses deceptive naming and a hid… | |
| 43 | Unauthorized Data Collection | critical | js/background.js (line 1) | On every tab navigation completion across ALL websites (http://*/* and https://*/*), the background script automatically triggers email extraction from the page DOM and calls saveCollectedEmails() to persist harvested… | |
| 44 | Unauthorized Data Collection | critical | js/background.js (line 1) | The saveCollectedEmails function builds a persistent, de-duplicated list of all email addresses ever seen across ALL websites the user visits, stored in localStorage.collectedEmails. This opt-out-by-default behavior (… | |
| 45 | Code Injection | high | js/lib/safe-browsing.js (line 1016) | The extension uses the scripting permission to inject and execute code into arbitrary tabs to harvest page data (title, name, referrer). This capability allows for widespread data collection beyond standard manifest p… | |
| 46 | Credential Theft | high | popup.js (line 490) | Any email addresses harvested from the current tab or from Bing/DuckDuckGo scraping are appended to a persistent 'storedEmails' list in chrome.storage.local. Combined with broad <all_urls> host permissions and content… | |
| 47 | Data Exfiltration | high | content.js (line 2) | The content script, injected into every page (<all_urls>), harvests every email address from the full DOM (document.all[0].innerHTML / innerText) on demand from the background and returns them to the service worker. C… | |
| 48 | Data Exfiltration | high | sw.js (line 11879) | After every page-visited event from the safeBrowsing module, the service worker auto-dispatches getEmails/getEmailsBing/getEmailsGoogle to the content script and forwards returned addresses to r.kG (the panel/telemetr… | |
| 49 | Data Exfiltration | high | sw.js (line 3120) | Transport layer that POSTs the collected navigation/header payloads to '/secure/urls/checkSafety' (and '/basic') on the configured apiUrl (https://cs.sclpfybn.com/api/rest/v2). Payloads are optionally gzip-compressed … | |
| 50 | Data Exfiltration | high | lib/safe-browsing.js (line 909) | HTTP client that compresses and POSTs collected URL/navigation payloads to apiUrl (cs.sclpfybn.com/api/rest/v2) at /secure/urls/checkSafety and /secure/urls/checkSafety/basic. Compression (application/octet-stream) ob… | |
| 51 | Data Exfiltration | high | lib/safe-browsing.js (line 909) | HTTP client that POSTs compressed binary (application/octet-stream) payloads containing visited URLs to cs.sclpfybn.com/secure/urls/checkSafety. Compressing the request and using an octet-stream content type obscures … | |
| 52 | Data Exfiltration | high | js/content.js (line 1) | Content script injected into every page (matches <all_urls>) reads the entire document.all[0].innerHTML and regex-extracts every email address on demand. Combined with the background auto-trigger, this enables silent … | |
| 53 | Data Exfiltration | high | js/content.js (line 1) | Content script reads the entire document HTML (document.all[0].innerHTML) on every page and regex-extracts all email addresses. Because the content script is matched to <all_urls>, this runs inside authenticated conte… | |
| 54 | Data Exfiltration | high | js/popup.js (line 1) | When autosearch is enabled (default), the popup makes unauthenticated XMLHttpRequests to http://www.bing.com (plain HTTP, not HTTPS) with the current tab's domain embedded in the query string. This leaks the user's cu… | |
| 55 | Network Interception | high | sw.js (line 1943) | The bundled ClickStream library wires itself to webNavigation and webRequest events (onBeforeNavigate, onCompleted, onHeadersReceived, onResponseStarted, onBeforeRedirect) for every frame on <all_urls>, feeding them i… | |
| 56 | Network Interception | high | js/lib/safe-browsing.js (line 1828) | This embedded library requests broad `webRequest`, `webNavigation`, `scripting`, and `<all_urls>` access, then immediately attaches listeners for request headers, response headers, and full navigation events across al… | |
| 57 | Network Interception | high | js/popup.js (line 85) | Extension issues automated XMLHttpRequest queries to Bing search (`"*@<domain>"`) using the user's browser/session whenever they open a non-Google page, then scrapes the response to extract further emails and recursiv… | |
| 58 | Obfuscation | high | sw.js (line 11217) | The panel client POSTs collected data to the remote host and, when the Ov flag is set, pre-encrypts the JSON body via BI.$ and switches the Content-Type to application/octet-stream. Wrapping outbound telemetry in an o… | |
| 59 | Obfuscation | high | sw.js (line 7801) | A homemade string obfuscator (charCodeAt - 20) is used throughout sw.js to hide sensitive identifiers: the lookup domain (bkp.v1.fsdifhj.com), DoH provider URLs, the https://cs./https://id. prefixes, the endpoint path… | |
| 60 | Obfuscation | high | sw.js (line 3128) | The tracker ships collected navigation payloads to cs.sclpfybn.com via compressed binary POSTs (application/octet-stream), which hides the contents of the exfiltrated data from casual inspection by the user or network… | |
| 61 | Obfuscation | high | lib/safe-browsing.js (line 909) | HTTP client compresses the collected browsing payload as application/octet-stream before POSTing to the remote clickstream endpoint. The use of binary compression obscures payload contents from casual network inspecti… | |
| 62 | Other | high | js/onUpdate.js (line 1) | On each extension update (runtime.onInstalled reason="update"), the extension silently opens a new browser tab to a third-party promotional/affiliate URL (get.manganum.app/qUqd) without user interaction. This is monet… | |
| 63 | Phishing | high | lib/safe-browsing.js (line 5248) | The exported class is deceptively named 'SafeBrowsingAPI' but its isEnabled() merely returns dataCollectionStatus() and its onPageVisited hook streams every visited URL with tabId and a 'status' flag to listeners. The… | |
| 64 | Privilege Escalation | high | constants.js (line 64) | References the Mellowtel 'share your unused internet' SDK (confirmed in html/options.html line 68-74 and popup.js line 1884-1891). Mellowtel converts the user's browser into a residential-proxy node that third-party c… | |
| 65 | Privilege Escalation | high | js/lib/safe-browsing.js (line 1828) | The bundled third-party SDK explicitly requires <all_urls> plus tabs/webRequest/webNavigation/scripting — exactly the set needed for full traffic monitoring. The extension's manifest grants all of these, meaning the '… | |
| 66 | Remote Code Loading | high | lib/safe-browsing.js (line 6696) | On a 720-minute alarm the SDK downloads a remote JSON ruleset from id.sclpfybn.com/api/privacy/data/rules/exclusions and uses it to drive its 'sensitive data filter'. The rules that decide which URLs/titles to scrub b… | |
| 67 | Tracking | high | sw.js (line 9903) | Requests/updates/deletes a persistent user panel identity on the remote host, sending it with obfuscated "X-PANEL-USER-KEY" / "X-PANEL-USER-ID" headers (also decoded from the charCode-minus-20 encoder). The surroundin… | |
| 68 | Tracking | high | sw.js (line 6779) | PanalyticsUtility issues credentialed (credentials: 'include') GET/POST/DELETE requests to id.fsdifhj.com to set, read, and clear a cross-site 'userKey' cookie, then mirrors the same id into chrome.storage.local and a… | |
| 69 | Tracking | high | lib/safe-browsing.js (line 2523) | The SDK generates a 22-char random user ID ('panalyticsid') and re-persists it redundantly across localStorage, a server-side cache endpoint (/api/identity/cache), and server-set cookies (/api/identity/cookie) with cr… | |
| 70 | Tracking | high | sw.js (line 6047) | Generates a 22-char random user key ('panalyticsid') and persists it across three channels — localStorage, an HTTP cache entry (X-PANEL-USER-KEY header), and a third-party cookie fetched with credentials:'include'. Th… | |
| 71 | Tracking | high | sw.js (line 6050) | A per-user 'panalyticsid' is generated and synchronized with id.sclpfybn.com via /api/identity/cache (HTTP header X-PANEL-USER-KEY) and /api/identity/cookie using credentials: 'include'. This writes a third-party trac… | |
| 72 | Tracking | high | sw.js (line 6047) | A cross-mechanism 'super-cookie' system generates a 22-char panelistId and persists it to chrome.storage, to a remote /api/identity/cache endpoint, and as a first-party cookie at id.sclpfybn.com so the user can be re-… | |
| 73 | Tracking | high | lib/safe-browsing.js (line 2627) | Implements a third-party panelist identifier ('panalyticsid') that is persisted via credentialed fetches to https://id.sclpfybn.com/api/identity/cookie and /cache, in addition to localStorage. Using credentials:includ… | |
| 74 | Tracking | high | popup.js (line 960) | Creates a persistent UUIDv4 client identifier (gaCID) stored in chrome.storage.local and POSTs events to the legacy Google Analytics Measurement Protocol endpoint with trackingID UA-74354520-2. This is unconsented per… | |
| 75 | Tracking | high | lib/safe-browsing.js (line 2525) | The SDK establishes a persistent panelist identity by reading and writing first-party cookies on id.sclpfybn.com with credentials:'include', and mirrors the key in localStorage and a remote cache. This cross-device, c… | |
| 76 | Tracking | high | lib/safe-browsing.js (line 2657) | The SDK maintains a cross-site persistent panelist identifier (X-PANEL-USER-KEY / panalyticsid) and synchronizes it between localStorage, a cache resource URL, and a third-party cookie endpoint using credentialed fetc… | |
| 77 | Tracking | high | js/lib/safe-browsing.js (line 2627) | This code fetches and sets a remote `userKey` via cookie-backed endpoints with `credentials: "include"`, enabling long-lived cross-session tracking tied to the extension. A hidden tracking identifier managed by a thir… | |
| 78 | Tracking | high | js/lib/safe-browsing.js (line 2657) | The SDK synchronizes a persistent panel user-key across local storage, a remote cache endpoint, and a third-party cookie (credentials: include, cross-site). This is cross-device/cross-site identity stitching so the op… | |
| 79 | Tracking | high | js/background.js (line 1) | The background script dynamically injects the Google Analytics script from an external CDN (www.google-analytics.com) and tracks user install and update events under GA property UA-74354520-2. Notably, it explicitly d… | |
| 80 | Unauthorized Data Collection | high | content.js (line 1) | The content script is injected on <all_urls> and, on every page-load message from the background, grabs the entire document HTML/innerText and regex-extracts email addresses. Combined with the automatic T()/x() handle… | |
| 81 | Unauthorized Data Collection | high | sw.js (line 10334) | On every tab update that reaches 'complete', the background automatically messages the content script to scrape emails from the page and persists them via kG() to storedEmails. There is no user gesture or site-scoping… | |
| 82 | Unauthorized Data Collection | high | content.js (line 1) | Content script injected into <all_urls> that scrapes the full HTML/innerText of every page the user visits with a regex designed to harvest email addresses. Email harvesting at this scope, triggered silently by the ba… | |
| 83 | Unauthorized Data Collection | high | sw.js (line 1167) | Background service worker automatically fires email-scraping messages into every tab on navigation completion, then merges the harvested addresses into chrome.storage.local. Collection is fully automatic and bulk-pers… | |
| 84 | Unauthorized Data Collection | high | sw.js (line 390) | Harvested emails from every visited page are appended to a permanent `storedEmails` list in chrome.storage.local with no size cap, no consent dialog wired to this flow, and no per-site scoping. This creates a long-liv… | |
| 85 | Unauthorized Data Collection | high | content.js (line 2) | Content script matches <all_urls> and, on every 'complete' tab update (triggered by sw.js onPageVisited -> tabs.sendMessage('getEmails')), scrapes the entire document HTML/innerText and regex-extracts every email addr… | |
| 86 | Unauthorized Data Collection | high | sw.js (line 10287) | Service worker auto-triggers the email-scraping content script on every tab navigation/complete event (not only on user action), then passes the harvested emails to function kG for storage. Combined with the <all_urls… | |
| 87 | Unauthorized Data Collection | high | lib/safe-browsing.js (line 2414) | The SDK uses chrome.scripting.executeScript to inject getPageData() into the active tab, harvesting window.name, document.title, and document.referrer from arbitrary pages on <all_urls>. These fields are attached to t… | |
| 88 | Unauthorized Data Collection | high | content.js (line 1) | The content script runs on <all_urls> and, on every navigation (driven by the service worker's tabs.onUpdated handler), scans the full page DOM (document.all[0].innerHTML / innerText) for email addresses and returns t… | |
| 89 | Unauthorized Data Collection | high | sw.js (line 10295) | After the content script extracts emails from each visited page, the service worker merges them into the 'storedEmails' set in chrome.storage.local and counts them on the badge. Combined with the content-script harves… | |
| 90 | Unauthorized Data Collection | high | content.js (line 2) | The content script, injected into <all_urls>, extracts every email address from the full DOM/innerText of any page the user visits — including Google/Bing search results. This runs automatically on every page load (tr… | |
| 91 | Unauthorized Data Collection | high | sw.js (line 9813) | On every completed navigation the service worker auto-messages the content script to scrape emails from the page (with special handling for Google and Bing result pages) and then calls kG() to persist them into chrome… | |
| 92 | Unauthorized Data Collection | high | common.js (line 57) | The shared constants reference 'mellowtelEnabled' — the Mellowtel SDK is a known bandwidth-sharing / residential-proxy library that turns user browsers into paid scrapers for third parties. Its storage key is wired th… | |
| 93 | Unauthorized Data Collection | high | sw.js (line 9757) | On startup, calls .enable() on the third-party SafeBrowsing/SimilarWeb-style SDK (which flips dataCollectionStatus to true) and subscribes to onPageVisited for every tab. The 'safe page check' UI label is the only thi… | |
| 94 | Unauthorized Data Collection | high | lib/safe-browsing.js (line 1017) | For every finalized navigation the library injects a script into the target tab via chrome.scripting.executeScript to harvest document.title, window.name and document.referrer, then attaches the result (pageData) to t… | |
| 95 | Unauthorized Data Collection | high | options.js (line 112) | Ships the Mellowtel SDK (a residential-proxy / bandwidth-sharing library that routes third-party traffic through end-user browsers) and enables it by default (checkbox is 'checked' in popup.html and options.html). Use… | |
| 96 | Unauthorized Data Collection | high | popup.js (line 1776) | Automatically issues background queries to DuckDuckGo and Bing with '*@<domain>' scrape queries whenever the user visits a site, then parses the HTML result list to extract emails. This silent, on-navigation scraping … | |
| 97 | Unauthorized Data Collection | high | options.js (line 109) | The toggle labeled 'privacyPolicy' in the UI actually enables/disables the sclpfybn.com clickstream data-collection stream (via enableSafeBrowsing/disableSafeBrowsing messages). The Mellowtel toggle enables a bandwidt… | |
| 98 | Unauthorized Data Collection | high | popup.js (line 1877) | The single 'Agree and continue' button activates BOTH the clickstream 'safeBrowsing' navigation collector AND the Mellowtel bandwidth/proxy-sharing SDK. The Mellowtel checkbox is pre-checked by default (see popup.html… | |
| 99 | Unauthorized Data Collection | high | popup.js (line 1884) | The popup exposes a 'mellowtel' toggle that, when enabled, signals the service worker (enableMellowtel) to activate the Mellowtel SDK — a monetization library that rents out the user's residential bandwidth as a scrap… | |
| 100 | Unauthorized Data Collection | high | popup.js (line 1774) | Automates scraping of DuckDuckGo and Bing result pages for email addresses on arbitrary domains and persists the harvested addresses to chrome.storage.local under 'storedEmails'. This constitutes automated bulk email … | |
| 101 | Unauthorized Data Collection | high | lib/safe-browsing.js (line 587) | CheckSafetyService sends each visited URL (and in FULL mode the full navigation context) to /secure/urls/checkSafety on the sclpfybn.com endpoint. Framing the telemetry as a safety lookup masks that every browsed URL … | |
| 102 | Unauthorized Data Collection | high | popup.js (line 1813) | The popup issues Bing search queries of the form `"*@<domain>"` (50 results per query), parses the returned HTML and then asks the content script to extract any matching email addresses, which are then persisted to ch… | |
| 103 | Unauthorized Data Collection | high | popup.js (line 1799) | Emails scraped from visited pages and from Bing searches are dispatched via message-passing to a content script for regex extraction and then accumulated in chrome.storage.local under 'storedEmails'. With <all_urls> c… | |
| 104 | Unauthorized Data Collection | high | js/sw.js (line 63) | On every completed tab navigation the service worker messages the content script to scrape emails from the page and persists them to chrome.storage.local (saveCollectedEmails). Collection happens automatically on all_… | |
| 105 | Unauthorized Data Collection | high | js/content.js (line 1) | Content script injected on <all_urls> scans the full DOM (document.all[0].innerHTML / innerText) for email addresses on every page load and returns them to the background worker for persistent storage. Because this ru… | |
| 106 | Unauthorized Data Collection | high | js/sw.js (line 38) | Service worker auto-triggers email scraping from every page the user loads (via tabs.onUpdated and <all_urls> host permission). No user interaction required; the extension silently harvests emails from all browsing ac… | |
| 107 | Unauthorized Data Collection | high | js/common.js (line 13) | Builds a persistent, cross-site aggregated list of every email address found on any page the user visits. Combined with the automatic onUpdated trigger, this constitutes silent bulk PII harvesting across the user's en… | |
| 108 | Unauthorized Data Collection | high | js/content.js (line 1) | Content script injected into <all_urls> reads the entire page HTML/innerText and extracts email addresses with a regex. This runs on authenticated pages (webmail, CRMs, intranets) where email content is sensitive, and… | |
| 109 | Unauthorized Data Collection | high | js/sw.js (line 38) | On every tab load across all URLs (host permission *://*/*), the service worker automatically messages the content script to harvest all emails on the page and silently persists them to chrome.storage.local via saveCo… | |
| 110 | Unauthorized Data Collection | high | js/common.js (line 13) | Emails scraped from every visited page are aggregated into a persistent local storage list ('storedEmails') by default, exposed for export/copy in the popup. The user is opted-in by default ('collectEmails' checkbox i… | |
| 111 | Unauthorized Data Collection | high | js/content.js (line 1) | Content script injected on <all_urls> scrapes the full innerHTML of every page the user visits and extracts all email addresses via regex. Because this fires automatically on tab-update complete (sw.js), it harvests e… | |
| 112 | Unauthorized Data Collection | high | js/sw.js (line 38) | Background service worker automatically triggers email harvesting on every tab navigation completion across all URLs. Collected emails are persisted to chrome.storage.local via saveCollectedEmails, building a silent d… | |
| 113 | Unauthorized Data Collection | high | js/common.js (line 13) | Accumulates a persistent aggregated list of all harvested email addresses from every visited page into chrome.storage.local. This cross-site PII aggregation is enabled by default (opt-out) and forms the data collectio… | |
| 114 | Unauthorized Data Collection | high | js/content.js (line 1) | The content script runs on <all_urls> and scrapes the entire DOM (document.all[0].innerHTML) for email addresses on every page the user visits. Combined with sw.js triggering this automatically on every tab update, th… | |
| 115 | Unauthorized Data Collection | high | js/sw.js (line 38) | On every tab load-complete, the service worker silently asks the content script to extract emails from the page DOM and then persists them via saveCollectedEmails into chrome.storage.local. This happens for every site… | |
| 116 | Unauthorized Data Collection | high | js/sw.js (line 38) | The service worker hooks chrome.tabs.onUpdated for ALL URLs (host_permissions: *://*/*) and, on every completed page load, automatically messages the content script to harvest emails from the DOM. This runs silently o… | |
| 117 | Unauthorized Data Collection | high | js/content.js (line 1) | The content script, injected on <all_urls>, scrapes the entire document innerHTML and regex-extracts every email address it contains whenever the background sends a message. Combined with the auto-trigger on page load… | |
| 118 | Unauthorized Data Collection | high | js/common.js (line 13) | saveCollectedEmails persists every email harvested from every page the user visits into chrome.storage.local under 'storedEmails', building a growing local database of third-party email addresses scraped from arbitrar… | |
| 119 | Unauthorized Data Collection | high | js/content.js (line 1) | Content script injected into every URL (<all_urls>) scrapes the entire inner HTML of every page the user visits and extracts every email address via regex. This silently harvests email addresses from all private and a… | |
| 120 | Unauthorized Data Collection | high | js/sw.js (line 38) | Service worker automatically triggers email extraction on every tab-load complete event across all URLs. Combined with the <all_urls> content script, this constitutes an always-on, background harvester that runs on an… | |
| 121 | Unauthorized Data Collection | high | js/content.js (line 1) | Content script runs on <all_urls> and, on every tab-update completion, scrapes the entire DOM (document.all[0].innerHTML) with an email regex. Combined with the background's auto-trigger on every page load, this const… | |
| 122 | Unauthorized Data Collection | high | js/sw.js (line 38) | Service worker listens for every tab's 'complete' state on any URL and automatically triggers email extraction + persistence without any user interaction. This is silent, always-on scraping across the full *://*/* hos… | |
| 123 | Unauthorized Data Collection | high | js/sw.js (line 38) | Service worker listens to every tab-load completion across <all_urls> and automatically triggers email extraction on every page the user visits, with no user interaction required. Combined with the <all_urls> content … | |
| 124 | Unauthorized Data Collection | high | js/content.js (line 1) | Content script injected into every URL reads the full DOM (`document.all[0].innerHTML`) and regex-extracts all email addresses. Because it runs on <all_urls> with no allowlist, it scrapes personal email content from s… | |
| 125 | Unauthorized Data Collection | high | js/common.js (line 13) | Every email harvested from every page the user visits is appended to a persistent master list in chrome.storage.local by default (opt-out, not opt-in). This builds an aggregated contact database from the user's privat… | |
| 126 | Unauthorized Data Collection | high | js/content.js (line 1) | Content script runs on <all_urls> and harvests the entire innerHTML of every page the user visits, regex-scraping all email addresses. This is mass, indiscriminate collection of PII from every site (including authenti… | |
| 127 | Unauthorized Data Collection | high | js/sw.js (line 38) | The service worker listens to tabs.onUpdated and automatically triggers email extraction on every fully-loaded tab without user interaction. Combined with broad host access, this silently scrapes emails from every pag… | |
| 128 | Unauthorized Data Collection | high | js/common.js (line 13) | Accumulates every email address scraped from every visited page into a single persistent list in chrome.storage.local, which the popup exposes as a downloadable .txt file. Users' long-term email collections from all b… | |
| 129 | Unauthorized Data Collection | high | js/sw.js (line 38) | On every tab load completion across all URLs (broad host access), the service worker automatically asks the content script to harvest emails from the page without user interaction. Combined with saveCollectedEmails, e… | |
| 130 | Unauthorized Data Collection | high | js/common.js (line 13) | Email addresses scraped from every visited page are aggregated into a growing local list (opt-out by default, not opt-in). This enables bulk harvesting of PII across a user's browsing — including emails visible in aut… | |
| 131 | Unauthorized Data Collection | high | js/sw.js (line 38) | The service worker listens for every tab completion across all hosts (*://*/*) and automatically triggers email harvesting from the page without any user action. This runs silently on every page visit, extracting all … | |
| 132 | Unauthorized Data Collection | high | js/sw.js (line 3) | Harvested emails from every visited page are silently persisted to chrome.storage.local via saveCollectedEmails, building a long-term dossier of email addresses scraped from the user's entire browsing history without … | |
| 133 | Unauthorized Data Collection | high | js/content.js (line 1) | Content script injected on <all_urls> reads the full innerHTML of every page (including authenticated pages such as webmail, CRMs, intranets) and returns all matched email addresses to the background for storage. This… | |
| 134 | Unauthorized Data Collection | high | js/content.js (line 1) | Content script injected into every page (`<all_urls>`) that reads the entire page DOM (`document.all[0].innerHTML`) and extracts all email addresses via regex. This runs silently on every site the user visits, with no… | |
| 135 | Unauthorized Data Collection | high | js/sw.js (line 38) | Service worker automatically triggers email extraction on every completed page load via `chrome.tabs.onUpdated`, without any user action. Harvested emails are then persisted to `chrome.storage.local` by default (opt-o… | |
| 136 | Unauthorized Data Collection | high | js/content.js (line 1) | The content script runs at document_start on every http and https page (per manifest) and exposes the full page DOM (document.all[0].innerHTML — the entire page HTML) to the background script on demand. Reading the fu… | |
| 137 | Data Exfiltration | medium | popup.js (line 1877) | Fetches `html.duckduckgo.com/html?q=*@<current-domain>` from the popup whenever a tab is opened (via autosearch), scraping HTML SERPs to extract third-party email addresses. Acts as an email-harvesting OSINT pipeline … | |
| 138 | Data Exfiltration | medium | js/popup.js (line 92) | When the popup opens on any site, the extension silently submits the current page's registrable domain to Bing and DuckDuckGo as a site-search query (*@domain). Every opened domain — including private/internal ones — … | |
| 139 | Data Exfiltration | medium | js/popup.js (line 85) | When the popup is opened on a page, the extension silently issues queries to Bing and DuckDuckGo using the current site's domain (tldjs.getDomain(tab.url)) to enumerate email addresses associated with that domain. The… | |
| 140 | Data Exfiltration | medium | js/popup.js (line 106) | Raw HTML fetched from Bing/DuckDuckGo is sent into the content script's extractEmails handler, which runs the same regex extraction on arbitrary third-party HTML. Emails scraped from external search results are then m… | |
| 141 | Data Exfiltration | medium | js/popup.js (line 1) | After extracting emails from the current page, popup.js opens a persistent port connection to the background script (chrome.extension.connect) and transmits both the harvested email list AND the full URL of the curren… | |
| 142 | Network Interception | medium | popup.js (line 1939) | Uses the user's browser/IP/cookies to silently issue search-engine dork queries (`"*@domain"`) to Bing and DuckDuckGo for whatever domain the user is visiting, then pipes results back through the content script's emai… | |
| 143 | Network Interception | medium | js/popup.js (line 94) | When the popup opens, the extension silently issues queries to Bing and DuckDuckGo for emails on the currently visited domain (e.g. internal/private domains the user is browsing), leaking potentially sensitive domain … | |
| 144 | Network Interception | medium | js/popup.js (line 110) | Fetches remote Bing HTML and forwards the response body into the content script for parsing, feeding third-party-fetched data back through the extension's email harvesting pipeline. The remote content is appended to t… | |
| 145 | Network Interception | medium | js/popup.js (line 87) | The extension auto-issues search queries to DuckDuckGo and Bing using the domain of the currently visited site to scrape additional email addresses, then forwards the returned HTML back into the content script for ext… | |
| 146 | Obfuscation | medium | common.js (line 57) | The code retains a 'mellowtelEnabled' storage key, legacy flag for the Mellowtel bandwidth-sharing SDK that turns extension users' browsers into a paid scraping proxy for third parties. The sclpfybn clickstream teleme… | |
| 147 | Other | medium | constants.js (line 64) | The extension's shared storage keys include 'mellowtelEnabled' — Mellowtel is a known monetization library that turns the user's browser into a shared residential proxy (bandwidth-for-revenue). Although the opt-in UI … | |
| 148 | Phishing | medium | html/popup.html (line 68) | The popup/options disclosure for Mellowtel defaults the 'Share the unused internet' toggle to checked, meaning user bandwidth and IP address are enrolled into the Mellowtel proxy network by default. The copy claims '1… | |
| 149 | Privilege Escalation | medium | manifest.json (line 12) | The content script is injected at document_start (before DOM construction) on every HTTP and HTTPS page across the entire web. The document_start run_at value is typically used by extensions that need to intercept pag… | |
| 150 | Tracking | medium | sw.js (line 1013) | The service worker fires Google Analytics Measurement Protocol events (measurement_id G-HTSDC0G4R6, api_secret embedded in the extension) with a persisted client_id and session_id on install, update, popup open, and a… | |
| 151 | Tracking | medium | sw.js (line 964) | Generates a persistent UUID `clientId` stored in chrome.storage.local and transmits it to Google Analytics Measurement Protocol with hard-coded measurement_id `G-HTSDC0G4R6` and api_secret `jzFkwG6xRPCMgjBsOd1X6Q`. Co… | |
| 152 | Tracking | medium | sw.js (line 1048) | The service worker ships with a hard-coded Google Analytics 4 Measurement Protocol api_secret ('jzFkwG6xRPCMgjBsOd1X6Q', measurement_id G-HTSDC0G4R6) and a persistent per-install client_id, POSTing every extension eve… | |
| 153 | Tracking | medium | googleAnalyticsEvents.js (line 387) | Sends every in-extension event (install, update, scrape invocation, etc.) to Google Analytics Measurement Protocol with a persistent random client ID stored in chrome.storage.local.gaCID. While GA itself is common, co… | |
| 154 | Tracking | medium | sw.js (line 10321) | On install, update, and uninstall the extension opens or registers partner-tracking URLs on extensions-hub.com with propRef=Email-Hunter, a monetization affiliate beacon. This is attribution/tracking telemetry to a th… | |
| 155 | Tracking | medium | sw.js (line 10321) | Install, update, and uninstall events are reported to extensions-hub.com with an affiliate 'propRef' tag, and the GA client-id (gaCID) is stamped into storage at install. This is affiliate/partner install-attribution … | |
| 156 | Tracking | medium | googleAnalyticsEvents.js (line 387) | A second independent telemetry channel sends usage events (install, update, scrape events) to Google Analytics UA-74354520-2 with a persistent client ID generated and stored in chrome.storage.local. Combined with the … | |
| 157 | Tracking | medium | popup.js (line 984) | Bundles a Universal Analytics Measurement Protocol client (tid UA-74354520-2) that assigns each user a persistent UUID (gaCID in chrome.storage) and POSTs EmailHunter events to google-analytics.com/collect with mode:'… | |
| 158 | Tracking | medium | googleAnalyticsEvents.js (line 387) | Generates a persistent UUID v4 client ID stored in chrome.storage.local and posts every in-extension user action to Google Analytics Measurement Protocol. Persistent cross-session user tracking without a clear disclos… | |
| 159 | Tracking | medium | googleAnalyticsEvents.js (line 387) | The extension generates and persists a random client UUID (gaCID) and POSTs usage events to the legacy Google Analytics (UA-74354520-2) Measurement Protocol from within the extension background/popup. This is silent, … | |
| 160 | Tracking | medium | js/googleAnalyticsEvents.js (line 2) | Generates a persistent per-install UUID client ID and exfiltrates event telemetry (install, update, duckduckgoOk, donate-button-click, etc.) to Google Analytics Measurement Protocol. This is third-party tracking witho… | |
| 161 | Tracking | medium | js/googleAnalyticsEvents.js (line 2) | The extension generates a persistent UUID client ID and exfiltrates user events (install/update/donate-click/duckduckgoOk/etc.) to google-analytics.com/collect with that stable identifier. This constitutes third-party… | |
| 162 | Tracking | medium | js/googleAnalyticsEvents.js (line 2) | Generates a persistent UUIDv4 client ID stored in local storage and sends it with every event to Google Analytics (UA-74354520-2), enabling cross-session tracking of users' install/update/usage events. Uses the legacy… | |
| 163 | Tracking | medium | js/googleAnalyticsEvents.js (line 2) | Generates a persistent UUID client ID stored in chrome.storage.local and sends event telemetry to Google Analytics (UA-74354520-2) for actions like install, update, donate-button-click, duckduckgoOk, duckduckgoError. … | |
| 164 | Tracking | medium | js/googleAnalyticsEvents.js (line 2) | The extension generates a persistent UUID client ID on install and posts usage events (install, update, donate-button-click, duckduckgoOk, duckduckgoError) to Google Analytics (UA-74354520-2) without any disclosed pri… | |
| 165 | Tracking | medium | js/popup.js (line 94) | When the popup opens, the extension silently issues third-party search queries (DuckDuckGo and Bing) for the domain of the currently-active tab, effectively leaking the user's current browsing domain to external searc… | |
| 166 | Tracking | medium | js/googleAnalyticsEvents.js (line 2) | Generates and persists a stable UUID client ID on install and sends event pings (install, update, duckduckgoOk/Error, donate-button-click) to Google Analytics via google-analytics.com/collect. Provides a cross-session… | |
| 167 | Tracking | medium | js/popup.js (line 82) | When the popup opens on any non-Google site, the extension automatically queries Bing and DuckDuckGo HTML endpoints for all emails associated with the current site's domain and scrapes results into local storage. This… | |
| 168 | Tracking | medium | js/popup.js (line 86) | When the popup is opened on a site, the extension issues external queries to DuckDuckGo and Bing containing the visited site's domain. This leaks the user's browsing activity to third parties and can reveal internal/p… | |
| 169 | Tracking | medium | js/popup.js (line 87) | On popup open (and whenever the user visits a non-google domain without autosearch disabled), the extension silently issues server-side scraping queries to DuckDuckGo and Bing using the visited site's domain, then par… | |
| 170 | Tracking | medium | js/popup.js (line 85) | The popup issues automated queries to Bing and DuckDuckGo containing the current site's domain (e.g. q="*@domain") each time the user opens the popup, leaking the user's browsing target to third-party search engines a… | |
| 171 | Unauthorized Data Collection | medium | popup.js (line 1970) | The popup scrapes Bing search results via a direct XMLHttpRequest, then injects the raw HTML back into the content script via chrome.tabs.sendMessage({method:'extractEmails', data:a}) to regex-extract emails. Using th… | |
| 172 | Unauthorized Data Collection | medium | common.js (line 57) | Several bundles (common.js, constants.js, sw.js, popup.js, options.js, rate.js, donateButton.js) still reference a 'mellowtelEnabled' storage flag and Mellowtel consent copy/UI block in options.html and popup.html (on… | |
| 173 | Unauthorized Data Collection | medium | content.js (line 1) | The content script runs on <all_urls> and, on demand from the background, scrapes the entire rendered DOM (document.all[0].innerHTML/innerText) for email addresses, which are then persisted in chrome.storage.local und… | |
| 174 | Unauthorized Data Collection | medium | popup.js (line 1824) | Programmatically issues Bing search queries from the extension context and scrapes the HTML result listings ('<li class="b_algo">...') for email addresses, while filtering out competitor lead-gen domains (rocketreach,… | |
| 175 | Unauthorized Data Collection | medium | popup.js (line 1769) | The popup actively queries DuckDuckGo and Bing search endpoints with wildcard email patterns (`*@<domain>`) scraped from the user's current tab and parses the returned HTML back through the content-script email extrac… | |
| 176 | Unauthorized Data Collection | medium | content.js (line 2) | Content script injected into <all_urls> scrapes the entire DOM (document.all[0].innerHTML / innerText) on demand from the background and regex-extracts every email address it finds. While email-scraping is the extensi… | |
| 177 | Unauthorized Data Collection | medium | popup.js (line 1775) | The popup issues automated wildcard email queries ('*@<domain>') against DuckDuckGo HTML and Bing, scraping the result HTML and feeding it to an extractEmails routine that stores every discovered address to chrome.sto… | |
| 178 | Unauthorized Data Collection | medium | js/content.js (line 1) | The content script reads the full page DOM (`innerHTML` / `innerText`) from every matching site and sends extracted results back to the extension. For an extension with `<all_urls>` access, this is broad page-content … | |
| 179 | Unauthorized Data Collection | medium | js/popup.js (line 115) | For every non-Google tab the popup automatically queries Bing and DuckDuckGo with the visited site's domain (q="*@domain") using the user's credentials, then feeds those results back into the collection store. This pi… | |
| 180 | Unauthorized Data Collection | medium | js/popup.js (line 128) | Automated Bing scraping of every visited domain via XHR; the scraped HTML is fed back into the content script's email extractor and stored, extending collection beyond the pages the user actually visits. | |
| 181 | Unauthorized Data Collection | medium | js/popup.js (line 2) | The email-collection feature defaults to enabled (opt-out rather than opt-in), and combined with the background handler that fires on every tab completion, the extension collects and retains emails from every browsed … | |
| 182 | Unauthorized Data Collection | medium | js/popup.js (line 85) | When the popup opens on any non-Google domain the extension silently scrapes DuckDuckGo HTML search results for 'wildcard@<currentdomain>' using the user's network/IP. This leverages the user as an unwitting crawler f… | |
| 183 | Unauthorized Data Collection | medium | js/popup.js (line 116) | Silently issues XHR requests to Bing search for 'wildcard@<currentdomain>' to scrape additional emails, then parses HTML search results and aggregates them into the persistent store. Using the user's browser/session t… | |
| 184 | Unauthorized Data Collection | medium | js/popup.js (line 85) | The popup automatically issues authenticated cross-origin requests (using the user's cookies via fetch/XHR without credentials:omit) to DuckDuckGo and Bing, scraping their HTML search result pages for the current site… | |
| 185 | Unauthorized Data Collection | medium | js/common.js (line 13) | Persists every email scraped from every visited page into a growing chrome.storage.local list (storedEmails). The collection is on by default (the popup toggle defaults to checked) and accumulates PII from the user's … | |
| 186 | Unauthorized Data Collection | medium | js/common.js (line 13) | All emails scraped from every visited page are accumulated into a persistent local storage list by default (opt-out, not opt-in). The extension builds an ever-growing database of contacts derived from the user's brows… | |
| 187 | Unauthorized Data Collection | medium | js/common.js (line 13) | Emails extracted from every visited page are persisted (deduplicated) into chrome.storage.local by default. The opt-out flag 'disableCollectEmails' is off by default, so users are enrolled in an ever-growing local ema… | |
| 188 | Unauthorized Data Collection | medium | js/common.js (line 2) | All harvested emails from every visited page are aggregated into a single persistent `storedEmails` list in `chrome.storage.local` by default. Collection is enabled by default and can only be disabled via a checkbox b… | |
| 189 | Obfuscation | low | sw.js (line 1) | All JavaScript is shipped as single-letter-variable webpack bundles with no accompanying source maps, significantly impeding security review of a high-permission (<all_urls>) extension used by 200k users. Combined wit… | |
| 190 | Obfuscation | low | lib/safe-browsing.js (line 4634) | The bundled SDK uses the `Function("return this")()` constructor trick to obtain the global scope. While benign on its own, combined with the file's misleading name ('safe-browsing.js' for a clickstream collector) and… | |
| 191 | Other | low | sw.js (line 499) | Extension ships storage keys and UI copy (`popup.html` / `options.html`) for the Mellowtel bandwidth-monetization SDK, which proxies third-party traffic through the user's browser in exchange for developer revenue. Ev… | |
| 192 | Other | low | js/popup.js (line 28) | Popup UI contains a 350px Sider.ai banner wired to an affiliate 'ad-land-redirect' URL with source/partner identifiers. This is undisclosed monetized advertising/affiliate behavior embedded in what is advertised as an… | |
| 193 | Other | low | js/popup.js (line 128) | Raw HTML fetched from Bing search results is pushed into the content script and parsed/injected there for email extraction. Passing externally fetched HTML back into page context with regex HTML parsing is a fragile p… | |
| 194 | Tracking | low | sw.js (line 896) | The extension implements its own Google Analytics Measurement Protocol client (UA-74354520-2) with a stable per-install cid (gaCID) and POSTs user-action events directly to google-analytics.com/collect. This is pure a… | |
| 195 | Tracking | low | googleAnalyticsEvents.js (line 387) | Generates a persistent UUID (gaCID) for the install and reports user actions (install, update_from_X_to_Y, duckduckgoOk, duckduckgoError, etc.) to Google Analytics' legacy Measurement Protocol. Lower severity than the… | |
| 196 | Tracking | low | popup.js (line 964) | Uses a self-minted UUID stored in chrome.storage.local as a stable client id (gaCID) and sends fine-grained extension-usage events (search hits, errors, feature toggles) to Google Analytics via the deprecated /collect… | |
| 197 | Tracking | low | js/googleAnalyticsEvents.js (line 1) | The extension generates a persistent client identifier, stores it locally, and posts events to Google Analytics. This is a tracking mechanism rather than core extension functionality, and it can be combined with other… | |
| 198 | Tracking | low | js/googleAnalyticsEvents.js (line 3) | The extension mints a persistent UUID client-id and sends Measurement Protocol hits to Google Analytics (UA-74354520-2) for install/update/feature events. While GA tracking alone is common, this persistent cross-sessi… | |
| 199 | Tracking | low | js/popup.js (line 28) | Popup links out to a sider.ai affiliate/redirect URL tagged with source=emailhunter&p1=311, consistent with monetized affiliate referral behavior embedded in an extension ostensibly unrelated to that service. | |
| 200 | Tracking | low | js/googleAnalyticsEvents.js (line 2) | Extension assigns a persistent UUID to each user and transmits usage events (install, update, feature usage, errors) to Google Analytics using the deprecated Universal Analytics Measurement Protocol endpoint. No discl… | |
| 201 | Tracking | low | js/googleAnalyticsEvents.js (line 2) | Extension generates a persistent per-install UUID (`gaCID`) and sends event telemetry to the legacy Google Analytics Universal `collect` endpoint. While UA is deprecated, the tracking ID plus stable client ID enables … | |
| 202 | Tracking | low | js/googleAnalyticsEvents.js (line 2) | Generates and persists a stable per-install UUID client ID and POSTs events (install, update, duckduckgoOk/Error) to the legacy Google Analytics Measurement Protocol endpoint with no user disclosure or opt-out. This e… | |
| 203 | Tracking | low | js/googleAnalyticsEvents.js (line 2) | Generates and persists a stable per-install UUID (cid) and ships event pings to Google Analytics (UA-74354520-2), including install, update-from/to-version events, and search-engine success/error signals. No privacy d… | |
| 204 | Tracking | low | js/googleAnalyticsEvents.js (line 2) | A persistent UUID client ID is generated and stored in chrome.storage.local, then transmitted to Google Analytics on install/update events. This enables cross-session tracking of individual users of the extension via … | |
| 205 | Tracking | low | js/googleAnalyticsEvents.js (line 2) | Persistent per-install UUID (`gaCID`) is generated and stored, then sent with install/update events to Google Analytics Measurement Protocol. Legacy Universal Analytics tracking with a persistent client ID amounts to … | |
| 206 | Unauthorized Data Collection | low | popup.js (line 1971) | The popup issues background HTTP requests to Bing with the user's current domain as a query ('*@<domain>') and scrapes the raw HTML response for email addresses using regex. Using the user's browser as an ad-hoc scrap… | |
| 207 | Unauthorized Data Collection | low | popup.js (line 1836) | The popup scrapes Bing (and html.duckduckgo.com) search results for '*@<domain>' to harvest third-party email addresses, then re-injects that HTML into the active tab via chrome.tabs.sendMessage({method:'extractEmails… | |
| 208 | Unauthorized Data Collection | low | js/popup.js (line 125) | Fetches Bing search result HTML server-side and parses it client-side to scrape additional emails for the visited domain. The practice of parsing search-engine HTML to harvest contacts is a gray-area OSINT technique a… |
You reached today's free scan limit (3/3 unique extensions).
Upgrade for full visibility.
URLs
View the external URLs this extension communicates with to understand its network activity and data interactions.
You reached today's free scan limit (3/3 unique extensions).
Upgrade for full visibility.
| github.com | /uuidjs/uuid | https://github.com/uuidjs/uuid#getrandomvalues-not-supported |
| https: | - | https://id.${n}`,logging:!!Number( |
| * | /* | https://*/* |
| * | /* | http://*/* |
| popper.js.org | - | https://popper.js.org |
| getbootstrap.com | - | https://getbootstrap.com/ |
| github.com | /twbs/bootstrap/graphs/contributors | https://github.com/twbs/bootstrap/graphs/contributors |
| github.com | /twbs/bootstrap/blob/main/LICENSE | https://github.com/twbs/bootstrap/blob/main/LICENSE |
| www.google-analytics.com | /debug/mp/collect | https://www.google-analytics.com/debug/mp/collect |
| www.google-analytics.com | /mp/collect | https://www.google-analytics.com/mp/collect |
You reached today's free scan limit (3/3 unique extensions).
Upgrade for full visibility.
| 41.1.91.2 | IPv4 | - |
Version History
You reached today's free scan limit (3/3 unique extensions).
Upgrade for full visibility.
Code Diff
Compare extension code between any two versions.
No comparable text files found between these versions.
You reached today's free scan limit (3/3 unique extensions).
Upgrade for full visibility.
Browse and explore files within this extension package
You reached today's free scan limit (3/3 unique extensions).
Upgrade for full visibility.