Caution required
Suspicious in code review (v7.7)
Our reviewer found behaviour consistent with malware in version 7.7, but not enough to confirm it. Treat this extension as untrusted until it has been re-reviewed.
What our analysis found
eRail.in, used by 300,000 people, is rated caution by Extension Auditor. Our code review reported 4 findings (2 critical, 2 medium), led by credential theft. It comes from a trusted publisher and was last updated in August 2024.
Key findings
- critical· credential theft —The content script is injected into all pages and listens to window postMessage events without origin validation, forwarding any action (including GETCOOKIE) to the background. Combined with the background's ability to fetch cookies for Railways domains and the content script's onMessage handler that passes data back to the page, any malicious website can steal sensitive session cookies.
- critical· credential theft —The background script processes a GETCOOKIE message from any tab (including content scripts injected into attacker pages) and retrieves all cookies for the specified domain (e.g.,.) using chrome.cookies.getAll. The cookies are then sent back to the requesting tab, enabling theft of authentication tokens.
- medium· other —The bundled manifest uses manifest_version 2 and includes permissions webRequest, webRequestBlocking, while the published summary on CWS indicates manifest_version 3 with only tabs, cookies permissions. Host permissions in the bundled manifest omit domains present in the published summary. This discrepancy may indicate an outdated or unreviewed code version.
- medium· code injection —The extension uses eval() on data fetched from (response text) and on OCR-rendered captcha text. Executing external data with eval can lead to arbitrary code execution if the source is compromised, posing a code injection risk.
The extension is a legitimate Indian Railways tool but contains a critical vulnerability: it injects content scripts into all websites and exposes cookie retrieval APIs to any webpage via postMessage, potentially allowing any site to steal Railways session cookies. Combined with eval of external data and manifest discrepancies, the extension is suspicious.
eRail.in Chrome extension security report
ID: aopfgjfeiimeioiajeknfidlljpoebgc
Extension Info & Metadata
Publisher Contextual Analysis
- Author
- https://erail.in/
- Privacy
- Privacy Policy
- MX records exist
- Yes
- Domain exists
- Yes
- Is disposable
- No
- Is role-based
- No
- Mailbox exists
- Yes
- Website
- Visit
Screenshots & videos
Install growth
Gain full insight into all external connections.
Upgrade for full visibility.
About this extension
This app provides enhanced user experience for eRail.in
Read the publisher’s full description
Extension helps to access availability, PNR and Running Status of trains from Indian Railways.
User reviews
Extension files
Browse and explore files within this extension package
Gain full insight into all external connections.
Upgrade for full visibility.
URLs
View the external URLs this extension communicates with to understand its network activity and data interactions.
Gain full insight into all external connections.
Upgrade for full visibility.
Code Diff
Compare extension code between any two versions.
0 changed files detected
No comparable text files found between these versions.
Gain full insight into all external connections.
Upgrade for full visibility.
Related extensions
Popular in Workflow & Planning
- Application Launcher For Drive (by Google)98,000,000 users
- Chrome Remote Desktop41,000,000 users
- Microsoft Single Sign On37,000,000 users
- PrinterLogic Extension v1.0.6.113,000,000 users
- MetaMask12,000,000 users