IDM- integration addon

ID: pekpblgmdlmdpmleogokpeahkhginkab

Could be malicious

Supported Languages

๐Ÿ‡ง๐Ÿ‡ฉBengali
๐Ÿ‡ง๐Ÿ‡ทBrazilian Portuguese
๐Ÿ‡ฌ๐Ÿ‡งBritish English
๐Ÿ‡ง๐Ÿ‡ฌBulgarian
๐Ÿ‡ช๐Ÿ‡ธCatalan
๐Ÿ‡จ๐Ÿ‡ณChinese (Simplified)
๐Ÿ‡น๐Ÿ‡ผChinese (Traditional)
๐Ÿ‡ญ๐Ÿ‡ทCroatian
๐Ÿ‡จ๐Ÿ‡ฟCzech
๐Ÿ‡ฉ๐Ÿ‡ฐDanish
๐Ÿ‡ณ๐Ÿ‡ฑDutch
๐Ÿ‡บ๐Ÿ‡ธEnglish
๐Ÿ‡ช๐Ÿ‡ชEstonian
๐Ÿ‡ต๐Ÿ‡ญFilipino
๐Ÿ‡ซ๐Ÿ‡ฎFinnish
๐Ÿ‡ซ๐Ÿ‡ทFrench
๐Ÿ‡ฉ๐Ÿ‡ชGerman
๐Ÿ‡ฌ๐Ÿ‡ทGreek
๐Ÿ‡ฎ๐Ÿ‡ณGujarati
๐Ÿ‡ฎ๐Ÿ‡ณHindi
๐Ÿ‡ญ๐Ÿ‡บHungarian
๐Ÿ‡ฎ๐Ÿ‡ฉIndonesian
๐Ÿ‡ฎ๐Ÿ‡นItalian
๐Ÿ‡ฏ๐Ÿ‡ตJapanese
๐Ÿ‡ฐ๐Ÿ‡ทKorean
๐Ÿ‡ฒ๐Ÿ‡ฝLatin American Spanish
๐Ÿ‡ฑ๐Ÿ‡ปLatvian
๐Ÿ‡ฒ๐Ÿ‡พMalay
๐Ÿ‡ฎ๐Ÿ‡ณMalayalam
๐Ÿ‡ฎ๐Ÿ‡ณMarathi
๐Ÿ‡ณ๐Ÿ‡ดNorwegian
๐Ÿ‡ต๐Ÿ‡ฑPolish
๐Ÿ‡ต๐Ÿ‡นPortuguese
๐Ÿ‡ท๐Ÿ‡ดRomanian
๐Ÿ‡ท๐Ÿ‡บRussian
๐Ÿ‡ท๐Ÿ‡ธSerbian
๐Ÿ‡ธ๐Ÿ‡ฎSlovenian
๐Ÿ‡ช๐Ÿ‡ธSpanish
๐Ÿ‡ธ๐Ÿ‡ชSwedish
๐Ÿ‡ฎ๐Ÿ‡ณTamil
๐Ÿ‡ฎ๐Ÿ‡ณTelugu
๐Ÿ‡น๐Ÿ‡ญThai
๐Ÿ‡น๐Ÿ‡ทTurkish
๐Ÿ‡บ๐Ÿ‡ฆUkrainian
๐Ÿ‡ป๐Ÿ‡ณVietnamese

Extension Info & Metadata

Status
Removed
Version
0.0.2
Size
0.10 MB
Rating
2.9/5
Reviews
35
Users
534,830
Type
Extension
Updated
Nov 7, 2022
Category
22_accessibility
Price
Free
Featured
No
Visibility
Listed
Mature
No
By Google
No
Trusted
Yes

Publisher Contextual Analysis

Trusted
Author
Dev. GroupView Profile
MX records exist
Yes
Domain exists
Yes
Is disposable
No
Is role-based
No
Mailbox exists
Yes
Total Extensions
1
Active
0
Obsolete
1
Listed
1
Unlisted
0
Total Users
534,830

IDM integration - adds "Download with IDM" context menu item for the file links

Internet Download Manager ( IDM ) is a popular tool to increase download speeds by up to 5 times, resume and schedule downloads. Comprehensive error recovery and resume capability will restart broken or interrupted downloads due to lost connections, network problems, computer shutdowns, or unexpected power outages. This Chrome extension requires that Internet Download Manager ( IDM ) desktop application is installed. Integration module adds "Download with IDM" context menu item for the file links and displays Download panel over page-embedded multimedia content, providing various helper functions to the main application as well. Internet Download Manager can be downloaded and installed from the official website: http://www.internetdownloadmanager.com/ If you like Internet Download Manager - Please leave Review and 5*****.

Item
Type
Severity
Description
<all_urls>
Permission
Critical
This permission grants access to all websites without restriction. Rated High because it can access any web content, monitor all web activity, and potentially steal sensitive data across all sites.
webRequest
Permission
Critical
This permission enables the extension to monitor and analyze all web requests made by the browser. Rated Critical because it can observe all network traffic including sensitive data, track browsing behavior, and gather authentication tokens.
webRequestBlocking
Permission
Critical
This permission allows the extension to intercept, modify, or block any web request in real-time before it reaches its destination. Rated Critical because it can modify sensitive data (like passwords, credit cards) before encryption, redirect traffic to malicious sites, or block security updates.
proxy
Permission
Critical
This permission allows the extension to control the browser's proxy settings. Rated Critical because it can route all traffic through potentially malicious proxies, enabling man-in-the-middle attacks and traffic monitoring.
Dangerous Permission Combination: proxy,webRequestBlocking,webRequest
Risk Factor
Critical
Complete control over network traffic and routing
Dangerous Permission Combination: proxy,webRequestBlocking,cookies
Risk Factor
Critical
Allows extensions to intercept web requests, manage cookies, and access identity or certificate-related functionalities, potentially compromising secure access and authentication processes.
Dangerous Permission Combination
Risk Factor
Critical
This extension can intercept, modify, and block web requests in real-time.
cookies
Permission
High
This permission provides full access to read and modify browser cookies. Rated High because it can steal session tokens, modify authentication cookies, and compromise accounts across websites.
webNavigation
Permission
High
This permission enables monitoring of all browser navigation events and transitions. Rated High because it can track every page visit, navigation method, and browsing pattern, potentially exposing sensitive browsing behavior and user activities.
downloads
Permission
High
This permission controls file downloads and accesses download history. Rated High because it can download malicious files, access sensitive downloaded documents, and track user download patterns.
nativeMessaging
Permission
High
This permission enables communication with applications installed on your computer. Rated High because it can exchange data with native programs, potentially exposing system-level information and local files.
Contextual Risk Factors
Risk Factor
High
The following context increases the overall risk:โ€ข 10% increase: Early script execution enables pre-emptive content manipulationโ€ข 15% increase: Older manifest version lacks modern security controls
management
Permission
Medium
This permission manages other installed extensions. Rated Medium because it can enable/disable other extensions and modify their settings, with changes being visible to users.
storage
Permission
Medium
This permission allows storing data locally in the browser. Rated Medium because it can persist sensitive user data, track user activities over time, and potentially store malicious payloads.
Early Content Script Execution
Risk Factor
Medium
This extension runs content scripts at document_start.
Older Manifest Version
Risk Factor
Medium
This extension uses Manifest Version 2
contextMenus
Permission
Low
This permission adds items to browser context menus. Rated Medium because it only modifies right-click menus without access to page content.
downloads.shelf
Permission
Unknown
No classification available for this permission.

This code packages large amounts of request metadata for export: request headers, response headers, POST bodies, cookies/origin context, user agent, and even proxy authorization material. It then forwards the bundle through `O(...)`, which elsewhere sends data to the companion process/backend, making this a direct browser-to-external-process data exfiltration path.

background.js (Line 1981)
l = [p, q, Math.floor(r / 1E3), Math.floor(r % 1E3 * 1E3), l & 7, a, b.tabId, b.frameId];p = {};p[6] = Ib(g, k && 4 > a);p[17] = b.Y;p[4] = b.A;p[100] = b.P;p[8] = C;p[129] = B;p[122] = this.m;p[11] = tc(m);p[13] = tc(z);p[18] = tc(e);b.f && (p[14] = hc(b.f, Z(m, "Content-Type")));b.H && (p[19] = hc(b.H, Z(e, "Content-Type")));if (null == m) {  a = this.s;  g = b.tabId + "," + b.frameId;  do g = (k = a[g]) && k.c, k = k && k.o, "about:blank" == k && (k = null); while (!k && g);  p[50] = k;  p[51] = f;  p[54] = navigator.userAgent}x && (p[122] = ub(this, b.proxyInfo, Z(m, "Proxy-Authorization")), p[55] =  ub(this, b.$, Z(e, "Proxy-Authorization")));if (!b.ca || !b.v)  if (b = this.a[b.tabId]) p[7] = b.o;return O(this, 13, 1, c, l, p, d)

The content script injects an extension-controlled script into every page context and all frames at document start, then enumerates inline scripts and sends matching script HTML back to the extension. Injecting into the page context plus harvesting script contents is a strong code-injection and page-surveillance pattern.

content.js (Line 200)
f.s = function() {  if (!this.Fa) {    this.Fa = !0;    this.b(2, window, "message", this.qb);    var b = document.createElement("script");    b.src = browser.extension.getURL("document.js");    b.onload = b.remove.bind(b);    document.head.appendChild(b)  }};f.J = function(b) {    var a = this.a,      c;    for (c of document.getElementsByTagName("script")) !c.src && b.test(c.innerText) && a.postMessage([34, null, -1, c      .outerHTML    ]);    a.postMessage([34, this.l()])

The background page installs blocking `webRequest` handlers across `*://*/*`, including access to request bodies, request headers, and response headers. This gives the extension full interception capability over most browsing traffic, which is a high-risk pattern when combined with its later forwarding of captured data.

background.js (Line 480)
const c = ["blocking"],  d = u && !oa && 1207959552 <= y ? ["extraHeaders"] : [];a.I(4, browser.webRequest.onBeforeRequest, a.La, {  urls: Ea,  types: Aa}, c);a.I(4, browser.webRequest.onBeforeRequest, a.La, {  urls: G,  types: b}, ["requestBody"]);a.I(4, browser.webRequest.onBeforeSendHeaders, a.vb, {  urls: G,  types: b}, ["requestHeaders"].concat(c, d));a.I(4, browser.webRequest.onHeadersReceived, a.xb, {  urls: G,  types: b}, ["responseHeaders"].concat(c));a.I(4, browser.webRequest.onResponseStarted, a.yb, {  urls: G,  types: b});a.I(4, browser.webRequest.onErrorOccurred, a.wb, {      urls: G,      types: b

The extension opens a WebSocket to localhost and, if that fails, falls back to native messaging with `com.tonec.idm`. Native messaging is a privileged bridge out of the browser sandbox, so combined with the captured network/page data above it creates a high-risk path for unrestricted local processing or onward exfiltration.

background.js (Line 641)
n.na = function() {    var a = this.S % (F.length + 1);    if (a < F.length) this.A = a = new WebSocket("ws://" + F[a] + "/?cid=" + Math.random()        .toString()        .substr(2, 9), "plugin.v3.internetdownloadmanager.com"), a.onopen = this.pa, a.onclose = this.N, a.onmessage =      this.pb, 1 == a.readyState ? this.pa() : 3 == a.readyState && this.N();    else if (w) this.N();    else {      this.da = a = browser.runtime.connectNative("com.tonec.idm");      try {        a.postMessage("")      } catch (b) {        a = null      }      a ? (a.onDisconnect.addListener(this.N), a.onMessage.addListener(this.cb), this.pa()) : this.N()    }

The extension queries other extension IDs via the `management` API and disables them, and in one branch even disables itself. Programmatically turning off other installed extensions is atypical for a download helper and can be used to suppress competing tools, interfere with analysis, or alter the user's browser environment without consent.

background.js (Line 2270)
n.Aa = J[J.length] = function wc(a, b, c, d, e) {    var h = ia && "llbjbkhnmlidjebalopleeepgdfgcpec" == browser.runtime.id && "ngpampappnmepgilojfohadhhmbhlaek";    if (!a) return this.ma = !1, browser.storage.local.get("version", b = R()), (x ? 1124073472 <= y : w ? 1073741824 <=      y : 1) && browser.extension.isAllowedIncognitoAccess(c = R()), u && browser.management.get(      "jeaohhlajejodfjadcponpnjgkiikocn", d = R()), ia && browser.management.get(h ||      "llbjbkhnmlidjebalopleeepgdfgcpec", e = R()), S(wc, this, !0, b, c, d, e);    N(d) && d.enabled && browser.management.setEnabled(d.id,      !1);    N(e) && e.enabled && browser.management.setEnabled(h || browser.runtime.id, !1);

By severity

Critical3
High6
Medium3
Low1

Versions scanned

Showing 2 of 3 scanned versions with more than one unique finding. Counts are unique findings that include each version.

Extension VersionCode Review Findings
0.0.38
0.0.25

Files with findings

3 distinct paths โ€” top paths by unique finding count:

  • background.js10
  • content.js2
  • document.js1
S.No.
Category
Severity
File
Summary
Found in Version
1Credential Theft
critical
background.js (line 1467)The function `P()` calls `browser.cookies.getAll({url})` to retrieve all cookies for a given URL, then `Q()` serializes them into a `name=value; name=value` string. This serialized cookie string is packed into field iโ€ฆ
2Data Exfiltration
critical
background.js (line 1981)This code packages large amounts of request metadata for export: request headers, response headers, POST bodies, cookies/origin context, user agent, and even proxy authorization material. It then forwards the bundle tโ€ฆ
3Network Interception
critical
background.js (line 381)The extension registers blocking `webRequest` listeners on all URLs (`*://*/*`) capturing request bodies, full request headers, and full response headers for every network request made by any tab. POST request bodies โ€ฆ
4Code Injection
high
content.js (line 200)The content script injects an extension-controlled script into every page context and all frames at document start, then enumerates inline scripts and sends matching script HTML back to the extension. Injecting into tโ€ฆ
5Network Interception
high
background.js (line 454)The extension establishes a persistent WebSocket connection to localhost ports 127.0.0.1:1001 or 0.1.0.1:1001 and falls back to native messaging (`connectNative('com.tonec.idm')`). All intercepted request/response datโ€ฆ
6Network Interception
high
document.js (line 1)This script is injected into every page's DOM via `content.js` (appended to `document.head`) and monkey-patches `XMLHttpRequest.prototype.open` and the global `fetch` function. The patches intercept XHR/fetch responseโ€ฆ
7Network Interception
high
background.js (line 480)The background page installs blocking `webRequest` handlers across `*://*/*`, including access to request bodies, request headers, and response headers. This gives the extension full interception capability over most โ€ฆ
8Privilege Escalation
high
background.js (line 1407)The extension uses the `management` permission to look up a competing IDM extension by ID (`jeaohhlajejodfjadcponpnjgkiikocn`) and, if found enabled, calls `browser.management.setEnabled(d.id, false)` to forcibly disaโ€ฆ
9Privilege Escalation
high
background.js (line 641)The extension opens a WebSocket to localhost and, if that fails, falls back to native messaging with `com.tonec.idm`. Native messaging is a privileged bridge out of the browser sandbox, so combined with the captured nโ€ฆ
10Other
medium
background.js (line 2270)The extension queries other extension IDs via the `management` API and disables them, and in one branch even disables itself. Programmatically turning off other installed extensions is atypical for a download helper aโ€ฆ
11Tracking
medium
content.js (line 18)On every page load and navigation event, the content script sends message type 21 containing the full current URL (`location.href`) and `document.referrer` to the background script, which forwards it to IDM. The page โ€ฆ
12Unauthorized Data Collection
medium
background.js (line 388)The extension reads the system proxy configuration on startup and subscribes to all changes via `browser.proxy.settings.onChange`. The extracted proxy mode, PAC script data/URL, and proxy server addresses are stored iโ€ฆ
13Tracking
low
background.js (line 457)Upon establishing connection to the IDM process (WebSocket or native messaging), the extension immediately transmits a fingerprint containing browser version (`D` / `y`), platform window class name (`ya`, e.g. `Chromeโ€ฆ
URLs
12
IPv4
2
IPv6
0

URLs

View the external URLs this extension communicates with to understand its network activity and data interactions.

Gain full insight into all external connections.

Upgrade for full visibility.

www.internetdownloadmanager.com/support/msedge_integration.htmlhttp://www.internetdownloadmanager.com/support/msedge_integration.html
www.internetdownloadmanager.com/support/firefox_integration.htmlhttp://www.internetdownloadmanager.com/support/firefox_integration.html
www.internetdownloadmanager.com/support/opera_integration.htmlhttp://www.internetdownloadmanager.com/support/opera_integration.html
clients2.google.com/service/update2/crxhttps://clients2.google.com/service/update2/crx
*/*http://*/*
*/*https://*/*
www.w3.org/1999/02/22-rdf-syntax-nshttp://www.w3.org/1999/02/22-rdf-syntax-ns#
ns.adobe.com/xap/1.0/http://ns.adobe.com/xap/1.0/
purl.org/dc/elements/1.1/http://purl.org/dc/elements/1.1/
ns.adobe.com/photoshop/1.0/http://ns.adobe.com/photoshop/1.0/
Showing 1 to 10 of 20 rows
Rows per page:

Gain full insight into all external connections.

Upgrade for full visibility.

127.0.0.1
IPv4
-
0.1.0.1
IPv4
-
Showing 1 to 3 of 10 rows
Rows per page:

Code Diff

Compare extension code between any two versions.

0 changed files (scanned top 25 shared text files)

No comparable text files found between these versions.

Browse and explore files within this extension package

Gain full insight into all external connections.

Upgrade for full visibility.