Chrome Web Store
2Versions
1Code reviewed

Do not install

Code review: critical

Our reviewer read this extension’s code and confirmed malicious behaviour. 3 security findings documented below. Do not install it. Remove it if you already have it.

What our analysis found

吕睿云客授权 is rated malicious by Extension Auditor. Our code review reported 3 findings (2 critical, 1 high), led by credential theft. It comes from a publisher with 2 extensions and was last updated in November 2022.

Key findings

  • critical· credential theft —The `saveToBackend` function serialises the full set of ` ` cookies and POSTs them to ` a third-party server with no relationship to the publisher's declared website or privacy policy domain. ZTO Express session cookies grant authenticated access to an internal logistics portal; exfiltrating them allows the operator of ` ` to hijack those sessions entirely. This is not disclosed as first-party collection and ` ` is not the publisher's own domain.
  • critical· data exfiltration —When the popup user clicks 'Authorize' the message handler verifies the user is logged into ` ` (ensuring fresh session cookies exist), then calls `chrome.cookies.getAll({domain: " "})` to collect all cookies for that domain and passes them to `saveToBackend`. The UX is designed to maximise the likelihood of a valid, active session being present before exfiltration occurs, confirming the intent is session hijacking rather than a legitimate delegation workflow.
  • high· unauthorized data collection —The content script runs on ` ` pages and strips the platform's deliberate masking of buyer identity (replacing masked `**` names with the raw `data-nick` attribute values). ZTO Express masks buyer names to protect personal data; this script deliberately circumvents that privacy control, exposing real customer identities to the extension's operator without buyer consent. Combined with the cookie exfiltration, this gives the attacker both session access and de-anonymised customer data from the logistics portal.

The explicitly harvests all cookies for the ` ` domain via `chrome.cookies.getAll({domain: " "})` and immediately POSTs them as JSON to ` — a third-party domain unrelated to the publisher's stated website (). The popup UI is social-engineered as an "authorization" flow (directing users to log into ` ` first, then click 'Authorize'), which tricks ZTO Express employees into voluntarily triggering the theft of their live session cookies. The publisher's only other extension is also flagged malicious (), and the 17% malicious peer rate in the permhash cluster corroborates the verdict; no signal contradicts it.

吕睿云客授权

吕睿云客授权 Chrome extension security report

ID: iabpgmoaamgnenbgpoadonllpamnhidk

Supported Languages

🇨🇳Chinese (Simplified)

Extension Info & Metadata

Status
Active
Version
0.2.2
Size
0.10 MB
Rating
0.0/5
Reviews
0
Users
5
Type
Extension
Updated
Nov 27, 2022
Category
Workflow & planning
Price
Free
Featured
No
Visibility
Listed
Mature
No
By Google
No
Trusted
No
This publisherTrack record
2extensions
1 no longer listed

Publisher Contextual Analysis

Author
zhunipinganai
Country
CN
MX records exist
Yes
Domain exists
Yes
Is disposable
No
Is role-based
No
Mailbox exists
Yes
Address
义乌市福田街道 金华市, 浙江省 322000 CN
Website
Visit
Extensions
2
Active
1
Obsolete
1
Listed
2
Unlisted
0
Users
7

Screenshots & videos

Screenshot 1

Install growth

Item
Type
Severity
Description
cookies
Permission
High
This permission provides full access to read and modify browser cookies. Rated High because it can steal session tokens, modify authentication cookies, and compromise accounts across websites.
*://*.zto.com/*
Host
Medium
Host permission — access limited to this URL pattern.
*://1.117.139.168/*
Host
Medium
Host permission — access limited to this URL pattern.
*://*.fxqvlog.cn/*
Host
Medium
Host permission — access limited to this URL pattern.
  • 2 critical
  • 1 high

The file, code excerpt and explanation behind each finding are part of the full report. No conclusion has been withheld — only the evidence. The verdict above already reflects everything found here.

Gain full insight into all external connections.

Upgrade for full visibility.

About this extension

lryk@pingan

Read the publisher’s full description

该插件只提供给与吕睿云客合作的用户进行使用,用户可以根据需要授权给吕睿云客公司获取到权限,来帮助用户实现自动化处理工单

User reviews

Extension files

Browse and explore files within this extension package

Gain full insight into all external connections.

Upgrade for full visibility.

URLs
3
IPv4
1

URLs

View the external URLs this extension communicates with to understand its network activity and data interactions.

No URLs found
No IP addresses found

Gain full insight into all external connections.

Upgrade for full visibility.

Version
Size
Verdict
Findings
Permhash
0.2.1
Latest
0.10 MBNot scanned—
2f0030c535193fc164e4e2b5371e8e676510cf0a64b2689d9aba6533e6ddea82
0.2.2
0.10 MBMalicious0
2f0030c535193fc164e4e2b5371e8e676510cf0a64b2689d9aba6533e6ddea82
Showing 1 to 2 of 10 rows
Rows per page:

Code Diff

Compare extension code between any two versions.

0 changed files detected

No comparable text files found between these versions.

Gain full insight into all external connections.

Upgrade for full visibility.

More from zhunipinganai

Popular in Workflow & Planning