Multi Auto Refresh

ID: khcoicdmealcbghjdamcdipkbljpkmlj

Could be malicious

Supported Languages

๐Ÿ‡ง๐Ÿ‡ฉBengali
๐Ÿ‡ง๐Ÿ‡ทBrazilian Portuguese
๐Ÿ‡ฌ๐Ÿ‡งBritish English
๐Ÿ‡ง๐Ÿ‡ฌBulgarian
๐Ÿ‡ช๐Ÿ‡ธCatalan
๐Ÿ‡จ๐Ÿ‡ณChinese (Simplified)
๐Ÿ‡น๐Ÿ‡ผChinese (Traditional)
๐Ÿ‡ญ๐Ÿ‡ทCroatian
๐Ÿ‡จ๐Ÿ‡ฟCzech
๐Ÿ‡ฉ๐Ÿ‡ฐDanish
๐Ÿ‡ณ๐Ÿ‡ฑDutch
๐Ÿ‡บ๐Ÿ‡ธEnglish
๐Ÿ‡ช๐Ÿ‡ชEstonian
๐Ÿ‡ต๐Ÿ‡ญFilipino
๐Ÿ‡ซ๐Ÿ‡ฎFinnish
๐Ÿ‡ซ๐Ÿ‡ทFrench
๐Ÿ‡ฉ๐Ÿ‡ชGerman
๐Ÿ‡ฌ๐Ÿ‡ทGreek
๐Ÿ‡ฎ๐Ÿ‡ณGujarati
๐Ÿ‡ฎ๐Ÿ‡ณHindi
๐Ÿ‡ญ๐Ÿ‡บHungarian
๐Ÿ‡ฎ๐Ÿ‡ฉIndonesian
๐Ÿ‡ฎ๐Ÿ‡นItalian
๐Ÿ‡ฏ๐Ÿ‡ตJapanese
๐Ÿ‡ฐ๐Ÿ‡ทKorean
๐Ÿ‡ฒ๐Ÿ‡ฝLatin American Spanish
๐Ÿ‡ฑ๐Ÿ‡ปLatvian
๐Ÿ‡ฑ๐Ÿ‡นLithuanian
๐Ÿ‡ฒ๐Ÿ‡พMalay
๐Ÿ‡ฎ๐Ÿ‡ณMalayalam
๐Ÿ‡ฎ๐Ÿ‡ณMarathi
๐Ÿ‡ณ๐Ÿ‡ดNorwegian
๐Ÿ‡ต๐Ÿ‡ฑPolish
๐Ÿ‡ต๐Ÿ‡นPortuguese
๐Ÿ‡ท๐Ÿ‡ดRomanian
๐Ÿ‡ท๐Ÿ‡บRussian
๐Ÿ‡ท๐Ÿ‡ธSerbian
๐Ÿ‡ธ๐Ÿ‡ฐSlovak
๐Ÿ‡ธ๐Ÿ‡ฎSlovenian
๐Ÿ‡ช๐Ÿ‡ธSpanish
๐Ÿ‡ธ๐Ÿ‡ชSwedish
๐Ÿ‡ฎ๐Ÿ‡ณTamil
๐Ÿ‡ฎ๐Ÿ‡ณTelugu
๐Ÿ‡น๐Ÿ‡ญThai
๐Ÿ‡น๐Ÿ‡ทTurkish
๐Ÿ‡บ๐Ÿ‡ฆUkrainian
๐Ÿ‡บ๐Ÿ‡ธUS English
๐Ÿ‡ป๐Ÿ‡ณVietnamese

Extension Info & Metadata

Status
Removed
Version
1.1.0
Size
0.47 MB
Rating
3.1/5
Reviews
8
Users
200,000
Type
Extension
Updated
Sep 6, 2021
Category
7_productivity
Price
Free
Featured
No
Visibility
Listed
Mature
No
By Google
No
Trusted
No

Publisher Contextual Analysis

Author
Frances MargretView Profile
MX records exist
Yes
Domain exists
Yes
Is disposable
No
Is role-based
No
Mailbox exists
Yes
Total Extensions
1
Active
0
Obsolete
1
Listed
1
Unlisted
0
Total Users
200,000

Set up refresh timers on multiple tabs. Both powerful and easy-to-use tool.

Multi Auto Refresh allows you to set up multiple refresh timers. The timer will reload a certain page every N seconds. โœฐโœฐโœฐ Features โœฐโœฐโœฐ - Auto refresh timer with second precision - Predefined simple-click intervals (see a screenshot) - You can set up multiple timers. Easy to manage. - Prevents โ€œAre you sure you want to leave this pageโ€ pop ups while refreshing.

Item
Type
Severity
Description
<all_urls>
Permission
Critical
This permission grants access to all websites without restriction. Rated High because it can access any web content, monitor all web activity, and potentially steal sensitive data across all sites.
Contextual Risk Factors
Risk Factor
High
The following context increases the overall risk:โ€ข 10% increase: Early script execution enables pre-emptive content manipulationโ€ข 15% increase: Older manifest version lacks modern security controlsโ€ข 10% increase: About:blank access enables potential sandbox escape vectors
storage
Permission
Medium
This permission allows storing data locally in the browser. Rated Medium because it can persist sensitive user data, track user activities over time, and potentially store malicious payloads.
tabs
Permission
Medium
This permission enables tab management and monitoring. Rated Medium because it can track open tabs, access tab metadata, and monitor user browsing patterns.
Early Content Script Execution
Risk Factor
Medium
This extension runs content scripts at document_start.
About:blank Access
Risk Factor
Medium
This extension can run content scripts in about:blank pages.
Older Manifest Version
Risk Factor
Medium
This extension uses Manifest Version 2
alarms
Permission
Low
This permission schedules periodic tasks. Rated Low because it can only trigger events at specified times without access to sensitive data.

The extension requests the '<all_urls>' and 'tabs' permissions, granting it broad access to the user's browsing activity across all websites. This is a high-privilege state that, combined with the auto-refresh functionality, could be abused for wide-scale monitoring or network-based attacks.

manifest.json (Line 38)
{  "permissions": [    "storage",    "alarms",    "tabs",    "<all_urls>"  ]}

The extension generates and persists a unique client ID in local storage, then sends it to Google Analytics along with the extension ID as a background pageview. This is a tracking pattern rather than overt malware, but it creates persistent telemetry for each install without any visible user consent flow.

js/background.js (Line 1474)
const s = e("uuid");async function n() {  const e = await new Promise((e => {    chrome.storage.local.get(["cid"], (r => {      e(r)    }))  }));  let {    cid: r  } = e;  return r || (r = s.v4(), chrome.storage.local.set({    cid: r  })), r}async function a(e) {  const r = undefined,    t = {      v: "1",      tid: e,      cid: await n(),      t: "pageview",      dp: "/background",      dt: "background",      dh: `chrome-extension://${chrome.runtime.id}`    },    s = `https://www.google-analytics.com/collect?${new URLSearchParams(t).toString()}`;  await fetch(s, {    method: "POST",    body: ""  })}

The extension uses Google Analytics to track background pageviews, sending a unique client ID (cid) and extension information to a remote server (UA-198889555-1). While common, this constitutes data collection and tracking of the extension's lifecycle.

js/background.js (Line 1487)
async function a(e) {  const r = undefined,    t = {      v: "1",      tid: e,      cid: await n(),      t: "pageview",      dp: "/background",      dt: "background",      dh: `chrome-extension://${chrome.runtime.id}`    },    s = `https://www.google-analytics.com/collect?${new URLSearchParams(t).toString()}`;  await fetch(s, {    method: "POST",    body: ""  })}

The extension requests permission to inject a content script into all URLs, all frames, and at document_start. However, the injected file 'js/content.js' is currently empty, which is suspicious and could serve as a placeholder for future malicious code injection.

manifest.json (Line 22)
{  "content_scripts": [    {      "matches": [        "http://*/*",        "https://*/*"      ],      "js": [        "js/content.js"      ],      "all_frames": true,      "match_about_blank": true,      "run_at": "document_start"    }  ]}

The manifest injects a content script into every HTTP and HTTPS page, all subframes, and even about:blank frames at document start. The shipped content script is empty, so this is not active abuse by itself, but it is an unusually broad early-execution footprint that would enable pervasive page access if later repurposed.

manifest.json (Line 1)
{  "update_url": "https://clients2.google.com/service/update2/crx",  "author": "Multi Auto Refresh team",  "background": {    "scripts": ["js/background.js"],    "persistent": true  },  "browser_action": {    "default_icon": {      "16": "icons/icon16.png",      "48": "icons/icon48.png",      "128": "icons/icon128.png",      "300": "icons/icon300.png"    },    "default_title": "__MSG_extName__",    "default_popup": "html/popup.html"  },  "content_scripts": [{    "matches": ["http://*/*", "https://*/*"],    "js": ["js/content.js"],    "all_frames": true,    "match_about_blank": true,    "run_at": "document_start"  }],

On installation, the background script enumerates all open tabs and forcibly injects the content script into every frame. Because `content.js` is empty, this currently does nothing observable, but the pattern is still noteworthy because it grants immediate execution across the user's active browsing session.

js/background.js (Line 1521)
n.browser.runtime.onInstalled.addListener((async e => {  if ("install" === e.reason) {    const e = "js/content.js",      r = await n.browser.tabs.query({});    for (const t of r)      if (t.id) try {        await n.browser.tabs.executeScript(t.id, {          allFrames: !0,          file: e        })      } catch (e) {}  }}));let o = [];

By severity

Critical0
High0
Medium2
Low4

Versions scanned

Showing 1 of 2 scanned versions with more than one unique finding. Counts are unique findings that include each version.

Extension VersionCode Review Findings
1.1.06

Files with findings

2 distinct paths โ€” top paths by unique finding count:

  • js/background.js3
  • manifest.json3
S.No.
Category
Severity
File
Summary
Found in Version
1Privilege Escalation
medium
manifest.json (line 38)The extension requests the '<all_urls>' and 'tabs' permissions, granting it broad access to the user's browsing activity across all websites. This is a high-privilege state that, combined with the auto-refresh functioโ€ฆ
2Tracking
medium
js/background.js (line 1474)The extension generates and persists a unique client ID in local storage, then sends it to Google Analytics along with the extension ID as a background pageview. This is a tracking pattern rather than overt malware, bโ€ฆ
3Other
low
manifest.json (line 22)The extension requests permission to inject a content script into all URLs, all frames, and at document_start. However, the injected file 'js/content.js' is currently empty, which is suspicious and could serve as a plโ€ฆ
4Other
low
manifest.json (line 1)The manifest injects a content script into every HTTP and HTTPS page, all subframes, and even about:blank frames at document start. The shipped content script is empty, so this is not active abuse by itself, but it isโ€ฆ
5Privilege Escalation
low
js/background.js (line 1521)On installation, the background script enumerates all open tabs and forcibly injects the content script into every frame. Because `content.js` is empty, this currently does nothing observable, but the pattern is stillโ€ฆ
6Tracking
low
js/background.js (line 1487)The extension uses Google Analytics to track background pageviews, sending a unique client ID (cid) and extension information to a remote server (UA-198889555-1). While common, this constitutes data collection and traโ€ฆ
URLs
48
IPv4
0
IPv6
0

URLs

View the external URLs this extension communicates with to understand its network activity and data interactions.

Gain full insight into all external connections.

Upgrade for full visibility.

getbootstrap.com-https://getbootstrap.com/
github.com/twbs/bootstrap/blob/main/LICENSEhttps://github.com/twbs/bootstrap/blob/main/LICENSE
www.w3.org/2000/svghttp://www.w3.org/2000/svg
github.com/uuidjs/uuidhttps://github.com/uuidjs/uuid#getrandomvalues-not-supported
developer.mozilla.org/docs/Mozilla/Add-ons/WebExtensions/API/runtime/onMessagehttps://developer.mozilla.org/docs/Mozilla/Add-ons/WebExtensions/API/runtime/onMessage
www.google-analytics.com/collecthttps://www.google-analytics.com/collect?${new
popper.js.org-https://popper.js.org
momentjs.com/guides/http://momentjs.com/guides/#/warnings/define-locale/
momentjs.com/guides/http://momentjs.com/guides/#/warnings/js-date/
momentjs.com/guides/http://momentjs.com/guides/#/warnings/min-max/
Showing 1 to 10 of 50 rows
Rows per page:

Gain full insight into all external connections.

Upgrade for full visibility.

No IP addresses found
Version
Size
Is Malicious
Findings
Permhash
1.1.0
Latest
0.46 MB
Malicious
6
1.1.2
0.47 MB
Malicious
โ€”
Showing 1 to 2 of 10 rows
Rows per page:

Code Diff

Compare extension code between any two versions.

0 changed files (scanned top 25 shared text files)

No comparable text files found between these versions.

Browse and explore files within this extension package

Gain full insight into all external connections.

Upgrade for full visibility.