Chrome Web Store
225Versions
1Code reviewed

Caution required

Suspicious in code review (v7.4.3.55)

Our reviewer found behaviour consistent with malware in version 7.4.3.55, but not enough to confirm it. Treat this extension as untrusted until it has been re-reviewed.

What our analysis found

Midia Medica Orientada is rated caution by Extension Auditor. Our code review reported 4 findings (2 high, 2 medium), led by remote code loading. It comes from a publisher with 18 extensions and was last updated in September 2026.

Key findings

  • high· remote code loading —The background worker fetches a JSON config from an external CDN (` `) on every 10-minute alarm tick and sends its contents as `Update_DomSelector` to every open WhatsApp Web tab. This gives the remote server the ability to push arbitrary DOM-selector overrides into an authenticated WhatsApp session at will. If ` ` is compromised or the publisher pushes a malicious update, the content script will execute attacker-controlled logic inside WhatsApp Web without any user interaction or extension update.
  • high· other —The `externally_connectable` manifest entry allows two external SaaS domains to send messages that inject a `bearer_token` directly into the WhatsApp Web URL via `chrome.tabs.update`. If either ` ` or ` ` is compromised or the publisher turns malicious post-ownership-transfer, an attacker can supply an arbitrary bearer token and redirect all WhatsApp Web tabs to an attacker-controlled auth state. The recorded publisher email change amplifies this risk.
  • medium· unauthorized data collection —The bundled WA-JS library forwards URLs extracted from WhatsApp chat messages to three third-party servers (` `, ` `, ` `) for link-preview generation. None of these domains appear in the publisher's privacy policy (` `) and none are disclosed in the CWS data-collection declaration. This means every URL the user sends or receives in WhatsApp is silently sent to third-party infrastructure outside the publisher's control.
  • medium· credential theft —On install, the background script scans all open Chrome Web Store tabs and extracts `bearer_token` values from their URL query parameters. Legitimate bearer tokens should never appear in URLs (they get logged in browser history, referrer headers, and server logs); their presence in CWS URLs suggests the SaaS authentication flow is non-standard and exposes session credentials to any other extension or page that can read tab URLs via the `tabs` permission. Combined with the publisher ownership change, this is a credential-handling concern.

The extension has a legitimate WhatsApp CRM purpose, but carries two concrete concerns: (1) polls ` every 10 minutes and broadcasts the response as `Update_DomSelector` to the WhatsApp Web content script, giving the publisher dynamic DOM-manipulation capability over an always-authenticated page — compromise of that CDN endpoint is a full takeover vector; (2) the primary content-script bundle chunk (` `) referenced in ` ` is absent from the analysed ZIP, so the actual WhatsApp data-handling, CRM sync, and license-check logic cannot be verified; the MalExt IoC report titled 'WaSteal' (added 2026-05-13) directly names this gap as the theft surface. Publisher has 18 other extensions with 0 malicious (contradicts ML verdict) and the code that was reviewable is consistent with a Brazilian SaaS CRM, but the remote-config loader and missing main chunk prevent a benign clearance.

Midia Medica Orientada

Midia Medica Orientada

ID: cellckcnenolgakggljkichbmgmbibgb

Supported Languages

🇧🇷Brazilian Portuguese

Extension Info & Metadata

Status
Active
Version
7.4.3.85
Size
5.51 MB
Rating
5.0/5
Reviews
1
Users
137
Type
Extension
Updated
Sep 30, 2026
Category
Productivity Workflow
Price
Free
Featured
No
Visibility
Listed
Mature
No
By Google
No
Trusted
No
This publisherTrack record
18extensions
1 no longer listed

Publisher Contextual Analysis

Author
wsllView Profile
MX records exist
Yes
Domain exists
Yes
Is disposable
No
Is role-based
No
Mailbox exists
Yes
Website
Visit
Extensions
18
Active
17
Obsolete
1
Listed
15
Unlisted
3
Users
102,689

Email Change History

1 change
Oct 9, 2025
Domain changed

Screenshots & videos

Screenshot 1

Install growth

Item
Type
Severity
Description
unlimitedStorage
Permission
Medium
This permission removes storage quota restrictions. Rated Medium because it can store large amounts of user data without limits, potentially impacting browser performance and storing extensive tracking data.
storage
Permission
Medium
This permission allows storing data locally in the browser. Rated Medium because it can persist sensitive user data, track user activities over time, and potentially store malicious payloads.
tabs
Permission
Medium
This permission enables tab management and monitoring. Rated Medium because it can track open tabs, access tab metadata, and monitor user browsing patterns.
https://web.whatsapp.com/*
Host
Medium
Host permission — access limited to this URL pattern.
alarms
Permission
Low
This permission schedules periodic tasks. Rated Low because it can only trigger events at specified times without access to sensitive data.

Gain full insight into all external connections.

Upgrade for full visibility.

About this extension

Mídia Médica Orientada é um CRM para WhatsApp Web. Organize seus chats e otimize seus negócios no WhatsApp Web

Read the publisher’s full description

Solução para whatsapp web com CRM Kanban

User reviews

Extension files

Browse and explore files within this extension package

Gain full insight into all external connections.

Upgrade for full visibility.

No network indicators were extracted from this version.

Showing 1 to 10 of 230 rows
Rows per page:

Code Diff

Compare extension code between any two versions.

0 changed files detected

No comparable text files found between these versions.

Gain full insight into all external connections.

Upgrade for full visibility.

Popular in productivity/workflow