Chrome Web Store
16Versions
1Code reviewed

Caution required

Suspicious in code review (v7.7)

Our reviewer found behaviour consistent with malware in version 7.7, but not enough to confirm it. Treat this extension as untrusted until it has been re-reviewed.

What our analysis found

eRail.in, used by 300,000 people, is rated caution by Extension Auditor. Our code review reported 4 findings (2 critical, 2 medium), led by credential theft. It comes from a trusted publisher and was last updated in August 2024.

Key findings

  • critical· credential theft —The content script is injected into all pages and listens to window postMessage events without origin validation, forwarding any action (including GETCOOKIE) to the background. Combined with the background's ability to fetch cookies for Railways domains and the content script's onMessage handler that passes data back to the page, any malicious website can steal sensitive session cookies.
  • critical· credential theft —The background script processes a GETCOOKIE message from any tab (including content scripts injected into attacker pages) and retrieves all cookies for the specified domain (e.g.,.) using chrome.cookies.getAll. The cookies are then sent back to the requesting tab, enabling theft of authentication tokens.
  • medium· other —The bundled manifest uses manifest_version 2 and includes permissions webRequest, webRequestBlocking, while the published summary on CWS indicates manifest_version 3 with only tabs, cookies permissions. Host permissions in the bundled manifest omit domains present in the published summary. This discrepancy may indicate an outdated or unreviewed code version.
  • medium· code injection —The extension uses eval() on data fetched from (response text) and on OCR-rendered captcha text. Executing external data with eval can lead to arbitrary code execution if the source is compromised, posing a code injection risk.

The extension is a legitimate Indian Railways tool but contains a critical vulnerability: it injects content scripts into all websites and exposes cookie retrieval APIs to any webpage via postMessage, potentially allowing any site to steal Railways session cookies. Combined with eval of external data and manifest discrepancies, the extension is suspicious.

eRail.in

eRail.in Chrome extension security report

ID: aopfgjfeiimeioiajeknfidlljpoebgc

Extension Info & Metadata

Status
Active
Version
9.10
Size
0.04 MB
Rating
4.2/5
Reviews
3,100
Users
300,000
Type
Extension
Updated
Aug 1, 2024
Category
Workflow & planning
Price
Free
Featured
No
Visibility
Listed
Mature
No
By Google
No
Trusted
Yes
This publisherTrack record
1extension
All still listed

Publisher Contextual Analysis

Trusted
Author
https://erail.in/
MX records exist
Yes
Domain exists
Yes
Is disposable
No
Is role-based
No
Mailbox exists
Yes
Website
Visit
Extensions
1
Active
1
Obsolete
0
Listed
1
Unlisted
0
Users
300,000

Screenshots & videos

Screenshot 1

Install growth

Item
Type
Severity
Description
cookies
Permission
High
This permission provides full access to read and modify browser cookies. Rated High because it can steal session tokens, modify authentication cookies, and compromise accounts across websites.
tabs
Permission
Medium
This permission enables tab management and monitoring. Rated Medium because it can track open tabs, access tab metadata, and monitor user browsing patterns.
https://erail.in/*
Host
Medium
Host permission — access limited to this URL pattern.
https://*.erail.in/*
Host
Medium
Host permission — access limited to this URL pattern.
https://tripmgt.in/*
Host
Medium
Host permission — access limited to this URL pattern.
https://*.irctc.co.in/*
Host
Medium
Host permission — access limited to this URL pattern.
https://*.indianrail.gov.in/*
Host
Medium
Host permission — access limited to this URL pattern.

Gain full insight into all external connections.

Upgrade for full visibility.

About this extension

This app provides enhanced user experience for eRail.in

Read the publisher’s full description

Extension helps to access availability, PNR and Running Status of trains from Indian Railways.

User reviews

Extension files

Browse and explore files within this extension package

Gain full insight into all external connections.

Upgrade for full visibility.

URLs
8

URLs

View the external URLs this extension communicates with to understand its network activity and data interactions.

No URLs found
No IP addresses found

Gain full insight into all external connections.

Upgrade for full visibility.

Version
Size
Verdict
Findings
Permhash
8.40
Latest
0.36 MBNot scanned—
a93772181b1b63a500e203e932420191171db5035c19f802749b90ce35f5253f
8.20
0.36 MBNot scanned—
29aed923a502358a63b87b63fbad3a8b88ae9f0182bbdf211a8b020baac52e32
8.10
0.36 MBNot scanned—
29aed923a502358a63b87b63fbad3a8b88ae9f0182bbdf211a8b020baac52e32
8.00
0.36 MBNot scanned—
29aed923a502358a63b87b63fbad3a8b88ae9f0182bbdf211a8b020baac52e32
7.70
0.36 MBNot scanned—
29aed923a502358a63b87b63fbad3a8b88ae9f0182bbdf211a8b020baac52e32
7.50
0.36 MBNot scanned—
29aed923a502358a63b87b63fbad3a8b88ae9f0182bbdf211a8b020baac52e32
7.40
0.36 MBNot scanned—
29aed923a502358a63b87b63fbad3a8b88ae9f0182bbdf211a8b020baac52e32
7.20
0.36 MBNot scanned—
29aed923a502358a63b87b63fbad3a8b88ae9f0182bbdf211a8b020baac52e32
7.10
0.36 MBNot scanned—
29aed923a502358a63b87b63fbad3a8b88ae9f0182bbdf211a8b020baac52e32
7.9
0.36 MBNot scanned—
29aed923a502358a63b87b63fbad3a8b88ae9f0182bbdf211a8b020baac52e32
Showing 1 to 10 of 20 rows
Rows per page:

Code Diff

Compare extension code between any two versions.

0 changed files detected

No comparable text files found between these versions.

Gain full insight into all external connections.

Upgrade for full visibility.

Popular in Workflow & Planning