IDM- integration addon

ID: pekpblgmdlmdpmleogokpeahkhginkab

Could be malicious

Supported Languages

๐Ÿ‡ง๐Ÿ‡ฉBengali
๐Ÿ‡ง๐Ÿ‡ทBrazilian Portuguese
๐Ÿ‡ฌ๐Ÿ‡งBritish English
๐Ÿ‡ง๐Ÿ‡ฌBulgarian
๐Ÿ‡ช๐Ÿ‡ธCatalan
๐Ÿ‡จ๐Ÿ‡ณChinese (Simplified)
๐Ÿ‡น๐Ÿ‡ผChinese (Traditional)
๐Ÿ‡ญ๐Ÿ‡ทCroatian
๐Ÿ‡จ๐Ÿ‡ฟCzech
๐Ÿ‡ฉ๐Ÿ‡ฐDanish
๐Ÿ‡ณ๐Ÿ‡ฑDutch
๐Ÿ‡บ๐Ÿ‡ธEnglish
๐Ÿ‡ช๐Ÿ‡ชEstonian
๐Ÿ‡ต๐Ÿ‡ญFilipino
๐Ÿ‡ซ๐Ÿ‡ฎFinnish
๐Ÿ‡ซ๐Ÿ‡ทFrench
๐Ÿ‡ฉ๐Ÿ‡ชGerman
๐Ÿ‡ฌ๐Ÿ‡ทGreek
๐Ÿ‡ฎ๐Ÿ‡ณGujarati
๐Ÿ‡ฎ๐Ÿ‡ณHindi
๐Ÿ‡ญ๐Ÿ‡บHungarian
๐Ÿ‡ฎ๐Ÿ‡ฉIndonesian
๐Ÿ‡ฎ๐Ÿ‡นItalian
๐Ÿ‡ฏ๐Ÿ‡ตJapanese
๐Ÿ‡ฐ๐Ÿ‡ทKorean
๐Ÿ‡ฒ๐Ÿ‡ฝLatin American Spanish
๐Ÿ‡ฑ๐Ÿ‡ปLatvian
๐Ÿ‡ฒ๐Ÿ‡พMalay
๐Ÿ‡ฎ๐Ÿ‡ณMalayalam
๐Ÿ‡ฎ๐Ÿ‡ณMarathi
๐Ÿ‡ณ๐Ÿ‡ดNorwegian
๐Ÿ‡ต๐Ÿ‡ฑPolish
๐Ÿ‡ต๐Ÿ‡นPortuguese
๐Ÿ‡ท๐Ÿ‡ดRomanian
๐Ÿ‡ท๐Ÿ‡บRussian
๐Ÿ‡ท๐Ÿ‡ธSerbian
๐Ÿ‡ธ๐Ÿ‡ฎSlovenian
๐Ÿ‡ช๐Ÿ‡ธSpanish
๐Ÿ‡ธ๐Ÿ‡ชSwedish
๐Ÿ‡ฎ๐Ÿ‡ณTamil
๐Ÿ‡ฎ๐Ÿ‡ณTelugu
๐Ÿ‡น๐Ÿ‡ญThai
๐Ÿ‡น๐Ÿ‡ทTurkish
๐Ÿ‡บ๐Ÿ‡ฆUkrainian
๐Ÿ‡ป๐Ÿ‡ณVietnamese

Extension Info & Metadata

Status
Removed
Version
0.0.3
Size
0.10 MB
Rating
2.9/5
Reviews
35
Users
534,830
Type
Extension
Updated
Nov 7, 2022
Category
22_accessibility
Price
Free
Featured
No
Visibility
Listed
Mature
No
By Google
No
Trusted
Yes

Publisher Contextual Analysis

Trusted
Author
Dev. GroupView Profile
MX records exist
Yes
Domain exists
Yes
Is disposable
No
Is role-based
No
Mailbox exists
Yes
Total Extensions
1
Active
0
Obsolete
1
Listed
1
Unlisted
0
Total Users
534,830

IDM integration - adds "Download with IDM" context menu item for the file links

Internet Download Manager ( IDM ) is a popular tool to increase download speeds by up to 5 times, resume and schedule downloads. Comprehensive error recovery and resume capability will restart broken or interrupted downloads due to lost connections, network problems, computer shutdowns, or unexpected power outages. This Chrome extension requires that Internet Download Manager ( IDM ) desktop application is installed. Integration module adds "Download with IDM" context menu item for the file links and displays Download panel over page-embedded multimedia content, providing various helper functions to the main application as well. Internet Download Manager can be downloaded and installed from the official website: http://www.internetdownloadmanager.com/ If you like Internet Download Manager - Please leave Review and 5*****.

Item
Type
Severity
Description
<all_urls>
Permission
Critical
This permission grants access to all websites without restriction. Rated High because it can access any web content, monitor all web activity, and potentially steal sensitive data across all sites.
webRequest
Permission
Critical
This permission enables the extension to monitor and analyze all web requests made by the browser. Rated Critical because it can observe all network traffic including sensitive data, track browsing behavior, and gather authentication tokens.
webRequestBlocking
Permission
Critical
This permission allows the extension to intercept, modify, or block any web request in real-time before it reaches its destination. Rated Critical because it can modify sensitive data (like passwords, credit cards) before encryption, redirect traffic to malicious sites, or block security updates.
proxy
Permission
Critical
This permission allows the extension to control the browser's proxy settings. Rated Critical because it can route all traffic through potentially malicious proxies, enabling man-in-the-middle attacks and traffic monitoring.
Dangerous Permission Combination: proxy,webRequestBlocking,webRequest
Risk Factor
Critical
Complete control over network traffic and routing
Dangerous Permission Combination: proxy,webRequestBlocking,cookies
Risk Factor
Critical
Allows extensions to intercept web requests, manage cookies, and access identity or certificate-related functionalities, potentially compromising secure access and authentication processes.
Dangerous Permission Combination
Risk Factor
Critical
This extension can intercept, modify, and block web requests in real-time.
cookies
Permission
High
This permission provides full access to read and modify browser cookies. Rated High because it can steal session tokens, modify authentication cookies, and compromise accounts across websites.
webNavigation
Permission
High
This permission enables monitoring of all browser navigation events and transitions. Rated High because it can track every page visit, navigation method, and browsing pattern, potentially exposing sensitive browsing behavior and user activities.
downloads
Permission
High
This permission controls file downloads and accesses download history. Rated High because it can download malicious files, access sensitive downloaded documents, and track user download patterns.
nativeMessaging
Permission
High
This permission enables communication with applications installed on your computer. Rated High because it can exchange data with native programs, potentially exposing system-level information and local files.
Contextual Risk Factors
Risk Factor
High
The following context increases the overall risk:โ€ข 10% increase: Early script execution enables pre-emptive content manipulationโ€ข 15% increase: Older manifest version lacks modern security controls
management
Permission
Medium
This permission manages other installed extensions. Rated Medium because it can enable/disable other extensions and modify their settings, with changes being visible to users.
storage
Permission
Medium
This permission allows storing data locally in the browser. Rated Medium because it can persist sensitive user data, track user activities over time, and potentially store malicious payloads.
Early Content Script Execution
Risk Factor
Medium
This extension runs content scripts at document_start.
Older Manifest Version
Risk Factor
Medium
This extension uses Manifest Version 2
contextMenus
Permission
Low
This permission adds items to browser context menus. Rated Medium because it only modifies right-click menus without access to page content.
downloads.shelf
Permission
Unknown
No classification available for this permission.

The function `P()` calls `browser.cookies.getAll({url})` to retrieve all cookies for a given URL, then `Q()` serializes them into a `name=value; name=value` string. This serialized cookie string is packed into field index 51 of the message payload and transmitted to the native IDM process via the WebSocket/native-messaging channel (function `O()`). This means session tokens, auth cookies, and tracking cookies for every URL the user downloads are exfiltrated to the native application with no user visibility.

background.js (Line 1467)
function P(a, b) {  w && a.startsWith("ftp:") ? b([]) : (a = {    url: a  }, ma && (a.firstPartyDomain = null), browser.cookies.getAll(a, b))}function Q(a) {  var b = "";  if (a && a.length)    for (var c = 0; c < a.length; c++) b && (b += "; "), b += a[c].name, b += "=", b += a[c].value;  return b}// Called at line 1211 before processing requests, and at line 1294:n.Ga = function(a, b, c) {  ...  e[51] = Q(b); // Q(b) is all serialized cookies  ...  return O(this, 13, 1, 129, d, e) || gc(this, a.id)};

The extension registers blocking `webRequest` listeners on all URLs (`*://*/*`) capturing request bodies, full request headers, and full response headers for every network request made by any tab. POST request bodies (`a.requestBody`) are stored at `a.f` and later serialized with `hc()` and sent in field 14 of messages to IDM. Response bodies are similarly captured in certain cases (e.g. M3U8/F4F streams via `XMLHttpRequest` at line 1198). This constitutes comprehensive man-in-the-middle surveillance of all browser traffic.

background.js (Line 381)
a.I(4, browser.webRequest.onBeforeRequest, a.La, {  urls: G,  types: b}, ["requestBody"]);a.I(4, browser.webRequest.onBeforeSendHeaders, a.vb, {  urls: G,  types: b}, ["requestHeaders"].concat(c, d));a.I(4, browser.webRequest.onHeadersReceived, a.xb, {  urls: G,  types: b}, ["responseHeaders"].concat(c));a.I(4, browser.webRequest.onResponseStarted, a.yb, {  urls: G,  types: b});a.I(4, browser.webRequest.onErrorOccurred, a.wb, {  urls: G,  types: b})

The extension establishes a persistent WebSocket connection to localhost ports 127.0.0.1:1001 or 0.1.0.1:1001 and falls back to native messaging (`connectNative('com.tonec.idm')`). All intercepted request/response data, cookies, headers, and page metadata are streamed through this channel to the IDM native application. While the stated purpose is download interception, the channel is bidirectional and can receive commands from the native app that drive extension behavior, creating a native-controlled backdoor into the browser.

background.js (Line 454)
n.na = function() {  var a = this.S % (F.length + 1);  if (a < F.length) this.A = a = new WebSocket("ws://" + F[a] + "/?cid=" + Math.random().toString().substr(2, 9), "plugin.v3.internetdownloadmanager.com"), a.onopen = this.pa, a.onclose = this.N, a.onmessage = this.pb, 1 == a.readyState ? this.pa() : 3 == a.readyState && this.N();  else if (w) this.N();  else {    this.da = a = browser.runtime.connectNative("com.tonec.idm");    try {      a.postMessage("")    } catch (b) {      a = null    }    a ? (a.onDisconnect.addListener(this.N), a.onMessage.addListener(this.cb), this.pa()) : this.N()  }};

The extension uses the `management` permission to look up a competing IDM extension by ID (`jeaohhlajejodfjadcponpnjgkiikocn`) and, if found enabled, calls `browser.management.setEnabled(d.id, false)` to forcibly disable it without user consent. It also conditionally self-disables in Edge-based browsers based on the detected version. Silently disabling other installed extensions is a privilege escalation and interference behavior not disclosed to users.

background.js (Line 1407)
n.Aa = J[J.length] = function wc(a, b, c, d, e) {    var h = ia && "llbjbkhnmlidjebalopleeepgdfgcpec" == browser.runtime.id && "ngpampappnmepgilojfohadhhmbhlaek";    if (!a) return this.ma = !1, browser.storage.local.get("version", b = R()), ...      u && browser.management.get("jeaohhlajejodfjadcponpnjgkiikocn", d = R()),      ia && browser.management.get(h || "llbjbkhnmlidjebalopleeepgdfgcpec", e = R()), S(wc, this, !0, b, c, d, e);    N(d) && d.enabled && browser.management.setEnabled(d.id, !1);    N(e) && e.enabled && browser.management.setEnabled(h || browser.runtime.id, !1);

This script is injected into every page's DOM via `content.js` (appended to `document.head`) and monkey-patches `XMLHttpRequest.prototype.open` and the global `fetch` function. The patches intercept XHR/fetch responses matching a configurable URL regex, read the response text/body, and relay them via `window.postMessage` back to the content script and ultimately to background.js. The regex patterns are provided dynamically from background.js, meaning the IDM native app can direct which response bodies are captured.

document.js (Line 1)
(function() {  function n(a, b) {    try {      h.test(b) && this.addEventListener("loadend", p.bind(this))    } catch (c) {}    return e.apply(this, arguments)  }  function p() {    try {      var a = this.getResponseHeader("X-IDM-Request-ID");      if (a) {        var b = k.exec(this.responseText);        g([1229212979, a, b && (b[1] || this.responseText)], "/")      }    } catch (c) {}  }  function q(a, b) {    var c = f.apply(this, arguments);    try {      if (h.test(a.url || a)) return c.then(r)    } catch (d) {}    return c  }  ...  window.addEventListener("message", function(a) {    ...    switch (b[0]) {      case 1229212978:        a = b[1];        var c = b[2],          d = b[3];        b = b[4];        d ? (h = RegExp(d), k = RegExp(b)) : a = c = !1;        try {          a ? e || (e = XMLHttpRequest.prototype.open) && (XMLHttpRequest.prototype.open = n) : e && (XMLHttpRequest.prototype.open = e, e = null),            c ? f || (f = fetch) && (fetch = q) : f && (fetch = f, f = null)        } catch (m) {}    }  }, !1);  g([1229212977], "/")})();

The extension reads the system proxy configuration on startup and subscribes to all changes via `browser.proxy.settings.onChange`. The extracted proxy mode, PAC script data/URL, and proxy server addresses are stored in `this.m` and transmitted to the IDM native process in the connection handshake (field 121 of the initial `pa()` message). Transmitting proxy configuration to a native application leaks network topology and could allow the native app to route traffic through the same proxy.

background.js (Line 388)
n.Ka = function(a) {  browser.runtime.lastError;  if (a) {    var b = a.value;    a = ab[b.mode];    ...    if (5 == a && (d = b.pacScript)) d.data && 5E4 < d.data.length ? a = 4 : (c = d.data) ? (a = 6, c = c.replace(...)) : c = d.url, this.U.fill(!0);    else if (7 == a) {      b = b.rules;...c = L(this, b.singleProxy);...    }    b = 5 > a ? a.toString() : c ? a + ":" + c : null;    b != this.m && (this.m && this.za(), this.m = b)  }};// registered at line 882:u && this.I(1, browser.proxy.settings.onChange, this.Ka);u && browser.proxy.settings.get({}, this.Ka);

On every page load and navigation event, the content script sends message type 21 containing the full current URL (`location.href`) and `document.referrer` to the background script, which forwards it to IDM. The page title (including OG title fallback) is also extracted and transmitted. This systematically builds a browsing history profile in the native IDM application, collecting every URL and referrer the user visits across all tabs.

content.js (Line 18)
f.wa = function(b) {  if (this.D(arguments)) {    var a = [21, this.tb || location.href, document.referrer];    b && a.push(document.getElementsByTagName("video").length, document.getElementsByTagName("audio").length);    this.a.postMessage(a)  }};// Called at f.Ra (message type 17 from background) and on DOMContentLoaded.// Also:f.l = function() {  var b = I ? 80 : 90;  try {    var a = window.top.document.title  } catch (c) {}  a || (a = (a = document.head.querySelector('meta[property="og:title"]')) && a.getAttribute("content"), b = 70);  a && (a = a.replace(...), a = new String(a.trim()), a.src = b);  return a;};

Upon establishing connection to the IDM process (WebSocket or native messaging), the extension immediately transmits a fingerprint containing browser version (`D` / `y`), platform window class name (`ya`, e.g. `Chrome_RenderWidgetHostHWND`), UI locale, and the full install/update event object (`this.Sa`). This device/environment fingerprint is sent on every reconnect and uniquely identifies the user's browser installation to the local IDM process, which may log or forward it.

background.js (Line 457)
n.pa = function() {  this.v = !0;  this.qa = 1;  var a = browser.i18n.getUILanguage().replace("_", "-");  "sr" == a && (a += "-Cyrl-CS");  var b = [15, 41, Na ? 1028 : 1031, 0],    c = {};  c[112] = D; // browser version  c[113] = la; // another version field  c[114] = ya; // window class name  c[125] = JSON.stringify(this.Sa); // install event info  c[116] = a; // UI language  O(this, 2, 1, Na ? 0 : 1024, b, c)};

By severity

Critical3
High6
Medium3
Low1

Versions scanned

Showing 2 of 3 scanned versions with more than one unique finding. Counts are unique findings that include each version.

Extension VersionCode Review Findings
0.0.38
0.0.25

Files with findings

3 distinct paths โ€” top paths by unique finding count:

  • background.js10
  • content.js2
  • document.js1
S.No.
Category
Severity
File
Summary
Found in Version
1Credential Theft
critical
background.js (line 1467)The function `P()` calls `browser.cookies.getAll({url})` to retrieve all cookies for a given URL, then `Q()` serializes them into a `name=value; name=value` string. This serialized cookie string is packed into field iโ€ฆ
2Data Exfiltration
critical
background.js (line 1981)This code packages large amounts of request metadata for export: request headers, response headers, POST bodies, cookies/origin context, user agent, and even proxy authorization material. It then forwards the bundle tโ€ฆ
3Network Interception
critical
background.js (line 381)The extension registers blocking `webRequest` listeners on all URLs (`*://*/*`) capturing request bodies, full request headers, and full response headers for every network request made by any tab. POST request bodies โ€ฆ
4Code Injection
high
content.js (line 200)The content script injects an extension-controlled script into every page context and all frames at document start, then enumerates inline scripts and sends matching script HTML back to the extension. Injecting into tโ€ฆ
5Network Interception
high
background.js (line 454)The extension establishes a persistent WebSocket connection to localhost ports 127.0.0.1:1001 or 0.1.0.1:1001 and falls back to native messaging (`connectNative('com.tonec.idm')`). All intercepted request/response datโ€ฆ
6Network Interception
high
document.js (line 1)This script is injected into every page's DOM via `content.js` (appended to `document.head`) and monkey-patches `XMLHttpRequest.prototype.open` and the global `fetch` function. The patches intercept XHR/fetch responseโ€ฆ
7Network Interception
high
background.js (line 480)The background page installs blocking `webRequest` handlers across `*://*/*`, including access to request bodies, request headers, and response headers. This gives the extension full interception capability over most โ€ฆ
8Privilege Escalation
high
background.js (line 1407)The extension uses the `management` permission to look up a competing IDM extension by ID (`jeaohhlajejodfjadcponpnjgkiikocn`) and, if found enabled, calls `browser.management.setEnabled(d.id, false)` to forcibly disaโ€ฆ
9Privilege Escalation
high
background.js (line 641)The extension opens a WebSocket to localhost and, if that fails, falls back to native messaging with `com.tonec.idm`. Native messaging is a privileged bridge out of the browser sandbox, so combined with the captured nโ€ฆ
10Other
medium
background.js (line 2270)The extension queries other extension IDs via the `management` API and disables them, and in one branch even disables itself. Programmatically turning off other installed extensions is atypical for a download helper aโ€ฆ
11Tracking
medium
content.js (line 18)On every page load and navigation event, the content script sends message type 21 containing the full current URL (`location.href`) and `document.referrer` to the background script, which forwards it to IDM. The page โ€ฆ
12Unauthorized Data Collection
medium
background.js (line 388)The extension reads the system proxy configuration on startup and subscribes to all changes via `browser.proxy.settings.onChange`. The extracted proxy mode, PAC script data/URL, and proxy server addresses are stored iโ€ฆ
13Tracking
low
background.js (line 457)Upon establishing connection to the IDM process (WebSocket or native messaging), the extension immediately transmits a fingerprint containing browser version (`D` / `y`), platform window class name (`ya`, e.g. `Chromeโ€ฆ
URLs
12
IPv4
2
IPv6
0

URLs

View the external URLs this extension communicates with to understand its network activity and data interactions.

Gain full insight into all external connections.

Upgrade for full visibility.

www.internetdownloadmanager.com/support/msedge_integration.htmlhttp://www.internetdownloadmanager.com/support/msedge_integration.html
www.internetdownloadmanager.com/support/firefox_integration.htmlhttp://www.internetdownloadmanager.com/support/firefox_integration.html
www.internetdownloadmanager.com/support/opera_integration.htmlhttp://www.internetdownloadmanager.com/support/opera_integration.html
clients2.google.com/service/update2/crxhttps://clients2.google.com/service/update2/crx
*/*http://*/*
*/*https://*/*
www.w3.org/1999/02/22-rdf-syntax-nshttp://www.w3.org/1999/02/22-rdf-syntax-ns#
ns.adobe.com/xap/1.0/http://ns.adobe.com/xap/1.0/
purl.org/dc/elements/1.1/http://purl.org/dc/elements/1.1/
ns.adobe.com/photoshop/1.0/http://ns.adobe.com/photoshop/1.0/
Showing 1 to 10 of 20 rows
Rows per page:

Gain full insight into all external connections.

Upgrade for full visibility.

127.0.0.1
IPv4
-
0.1.0.1
IPv4
-
Showing 1 to 3 of 10 rows
Rows per page:

Code Diff

Compare extension code between any two versions.

0 changed files (scanned top 25 shared text files)

No comparable text files found between these versions.

Browse and explore files within this extension package

Gain full insight into all external connections.

Upgrade for full visibility.