GitHub加速

ID: mfnkflidjnladnkldfonnaicljppahpg

Could be malicious

Supported Languages

🇨🇳Chinese (Simplified)

Extension Info & Metadata

Status
Removed
Version
1.0.9
Size
0.24 MB
Rating
4.8/5
Reviews
132
Users
100,000
Type
Extension
Updated
Jan 7, 2022
Category
7_productivity
Price
Free
Featured
No
Visibility
Listed
Mature
No
By Google
No
Trusted
No

Publisher Contextual Analysis

Author
fhefh2016View Profile
MX records exist
Yes
Domain exists
Yes
Is disposable
No
Is role-based
No
Mailbox exists
Yes
Total Extensions
15
Active
0
Obsolete
15
Listed
15
Unlisted
0
Total Users
130,539

国内Github下载很慢,用上了这个插件后,下载速度嗖嗖嗖的~!’

用途:能提高中国开发者访问GitHub的速度,提升克隆Git仓库的速度,提升下载release包的下载速度。 用户为何安装:提高中国软件开发者的工作效率,使他们能跟专注的开发软件。

Item
Type
Severity
Description
clipboardWrite
Permission
High
This permission allows modification of clipboard content. Rated High because it can inject malicious content into the clipboard, modify copied passwords, and manipulate copied data.
Contextual Risk Factors
Risk Factor
High
The following context increases the overall risk:• 15% increase: Older manifest version lacks modern security controls
activeTab
Permission
Medium
This permission grants temporary access to the current tab. Rated Medium because it can access current page content when invoked, though limited to user-initiated actions.
storage
Permission
Medium
This permission allows storing data locally in the browser. Rated Medium because it can persist sensitive user data, track user activities over time, and potentially store malicious payloads.
Older Manifest Version
Risk Factor
Medium
This extension uses Manifest Version 2

Every download and clone action is silently redirected through third-party mirror servers the user may not be aware of or trust. While these are known Chinese GitHub mirrors, a compromised or malicious mirror could serve modified source archives or binaries — the behavior Google flagged as 'potentially_uws'. This is an architectural supply-chain concern, not active malicious code in the extension itself.

js/background.js (Line 5)
let cf_url = "https://github.91chifun.workers.dev/";let fastgithub_url = "https://hub.fastgit.org";let cnpmjs_url = "https://github.com.cnpmjs.org";let ssh_url = "[email protected]:";...<a class = "flex-1 btn btn-outline get-repo-btn"rel = "nofollow"href = "${use_url}/https://github.com/${github_auth_name}/${git_name}/archive/master.zip" >

The bundled manifest declares 'activeTab' and 'clipboardWrite' permissions, but the published CWS manifest summary shows only 'storage'. While activeTab and clipboardWrite are low-severity on their own, the discrepancy suggests the store listing may not accurately reflect the shipped package, which is a transparency issue.

manifest.json (Line 41)
{  "permissions": [    "activeTab",    "clipboardWrite",    "storage"  ]}

By severity

Critical0
High0
Medium1
Low1

Versions scanned

Showing 1 of 11 scanned versions with more than one unique finding. Counts are unique findings that include each version.

Extension VersionCode Review Findings
1.0.92

Files with findings

2 distinct paths — top paths by unique finding count:

  • js/background.js1
  • manifest.json1
S.No.
Category
Severity
File
Summary
Found in Version
1Other
medium
js/background.js (line 5)Every download and clone action is silently redirected through third-party mirror servers the user may not be aware of or trust. While these are known Chinese GitHub mirrors, a compromised or malicious mirror could se…
2Other
low
manifest.json (line 41)The bundled manifest declares 'activeTab' and 'clipboardWrite' permissions, but the published CWS manifest summary shows only 'storage'. While activeTab and clipboardWrite are low-severity on their own, the discrepanc…
URLs
20
IPv4
0
IPv6
0

URLs

View the external URLs this extension communicates with to understand its network activity and data interactions.

Gain full insight into all external connections.

Upgrade for full visibility.

hub.fastgit.org-https://hub.fastgit.org
github.com.cnpmjs.org-https://github.com.cnpmjs.org
github.91chifun.workers.dev-https://github.91chifun.workers.dev/
docs.github.com/cn/github/using-git/which-remote-url-should-i-usehttps://docs.github.com/cn/github/using-git/which-remote-url-should-i-use
fastgit.org-https://fastgit.org
github.com/$%7Bgithub_auth_name%7D/$%7Bgit_name%7D.githttps://github.com/${github_auth_name}/${git_name}.git
github.zhlh6.cn-https://github.zhlh6.cn/
github.com/fhefh2015/Fast-GitHubhttps://github.com/fhefh2015/Fast-GitHub
github.com/$%7Bgithub_auth_name%7D/$%7Bgit_name%7D/archive/master.ziphttps://github.com/${github_auth_name}/${git_name}/archive/master.zip
github.com-https://github.com
Showing 1 to 10 of 20 rows
Rows per page:

Gain full insight into all external connections.

Upgrade for full visibility.

No IP addresses found
Version
Size
Is Malicious
Findings
Permhash
1.3.4
Latest
0.24 MB
Malicious
1.3.3
0.32 MB
Malicious
N/A
1.3.2
0.32 MB
Malicious
N/A
1.3.0
0.32 MB
Malicious
N/A
1.2.4
0.32 MB
Malicious
N/A
1.2.3
0.32 MB
Malicious
1.2.1
0.17 MB
Malicious
1.1.1
0.20 MB
Malicious
1.1.0
0.20 MB
Malicious
1.0.9
0.23 MB
Malicious
2
Showing 1 to 10 of 20 rows
Rows per page:

Code Diff

Compare extension code between any two versions.

0 changed files (scanned top 25 shared text files)

No comparable text files found between these versions.

Browse and explore files within this extension package

Gain full insight into all external connections.

Upgrade for full visibility.