MultiLogin

ID: ijfgglilaeakmoilplpcjcgjaoleopfi

Could be malicious

Supported Languages

🇺🇸English
🇫🇷French
🇩🇪German
🇯🇵Japanese
🇷🇺Russian
🇪🇸Spanish

Extension Info & Metadata

Status
Removed
Version
1.0.26
Size
0.02 MB
Rating
4.6/5
Reviews
936
Users
100,000
Type
Extension
Updated
Mar 30, 2022
Category
Productivity Workflow
Price
Free
Featured
No
Visibility
Listed
Mature
No
By Google
No
Trusted
Yes

Publisher Contextual Analysis

Trusted
Author
https://multilogin.topView Profile
MX records exist
Yes
Domain exists
Yes
Is disposable
No
Is role-based
No
Mailbox exists
Yes
Website
Visit
Total Extensions
1
Active
0
Obsolete
1
Listed
1
Unlisted
0
Total Users
100,000

Using websites with multiple accounts at the same time is made easy. Create an independent tab with a click of a button.

This plugin makes it very easy to use multiple accounts on the same site at the same time. Simply click on the plugin icon and go to the site in the created tab of the browser. Reliably works in facebook, tweeter, instagram and other social networks. The plugin is safe to use, your data is not sent anywhere. After the browser is closed, the data is deleted. P.S. Plugin does not work correctly in google services 1.0.10 - fixed bug in 72 Chrome version 1.0.14 - fixed bug in 80 Chrome version 1.0.17 - fixed bug in 87 Chrome version 1.0.19 - fixed error in gmail 1.0.25 - change tab image check url

Item
Type
Severity
Description
webRequest
Permission
Critical
This permission enables the extension to monitor and analyze all web requests made by the browser. Rated Critical because it can observe all network traffic including sensitive data, track browsing behavior, and gather authentication tokens.
webRequestBlocking
Permission
Critical
This permission allows the extension to intercept, modify, or block any web request in real-time before it reaches its destination. Rated Critical because it can modify sensitive data (like passwords, credit cards) before encryption, redirect traffic to malicious sites, or block security updates.
Dangerous Permission Combination
Risk Factor
Critical
This extension can intercept, modify, and block web requests in real-time.
cookies
Permission
High
This permission provides full access to read and modify browser cookies. Rated High because it can steal session tokens, modify authentication cookies, and compromise accounts across websites.
webNavigation
Permission
High
This permission enables monitoring of all browser navigation events and transitions. Rated High because it can track every page visit, navigation method, and browsing pattern, potentially exposing sensitive browsing behavior and user activities.
Contextual Risk Factors
Risk Factor
High
The following context increases the overall risk:• 10% increase: Early script execution enables pre-emptive content manipulation• 15% increase: Older manifest version lacks modern security controls
storage
Permission
Medium
This permission allows storing data locally in the browser. Rated Medium because it can persist sensitive user data, track user activities over time, and potentially store malicious payloads.
tabs
Permission
Medium
This permission enables tab management and monitoring. Rated Medium because it can track open tabs, access tab metadata, and monitor user browsing patterns.
Early Content Script Execution
Risk Factor
Medium
This extension runs content scripts at document_start.
Older Manifest Version
Risk Factor
Medium
This extension uses Manifest Version 2
contextMenus
Permission
Low
This permission adds items to browser context menus. Rated Medium because it only modifies right-click menus without access to page content.
http://*/*
Permission
Unknown
No classification available for this permission.
https://*/*
Permission
Unknown
No classification available for this permission.

By severity

Critical1
High3
Medium1
Low0

Versions scanned

Showing 1 of 11 scanned versions with more than one unique finding. Counts are unique findings that include each version.

Extension VersionCode Review Findings
1.0.215

Files with findings

2 distinct paths — top paths by unique finding count:

  • content.min.js4
  • background.html1
S.No.
Category
Severity
File
Summary
Found in Version
1Other
critical
background.html (line 1)background.html loads background.min.js which is the sole implementor of webRequest and webRequestBlocking handlers across all URLs. This file is absent from the analysis bundle despite being listed in verified_conten…
2Credential Theft
high
content.min.js (line 86)Injects a script into every page's execution context (at document_start, all_frames) that overrides document.cookie getter and setter via __defineSetter__/__defineGetter__. Every cookie read and write across every sit…
3Obfuscation
high
content.min.js (line 130)Makes a synchronous XHR to a wikipedia.org image and reads a custom HTTP response header named '6' to receive profile data from the background script. Using a trusted third-party domain as a covert messaging channel —…
4Unauthorized Data Collection
high
content.min.js (line 144)The cookie setter intercepts every site's cookie write and prepends a profile prefix (m) before storing. The getter filters out cookies not matching the profile prefix and strips the prefix before returning them. Whil…
5Tracking
medium
content.min.js (line 53)Injects a script that overrides document.title getter and setter on every page, emitting a CustomEvent on every title change. This allows the extension to observe every page title transition across all browsing, which…
URLs
12
IPv4
0
IPv6
0

URLs

View the external URLs this extension communicates with to understand its network activity and data interactions.

Gain full insight into all external connections.

Upgrade for full visibility.

www.google-analytics.com/analytics.jshttps://www.google-analytics.com/analytics.js
chrome.google.com/webstore*https://chrome.google.com/webstore*
*/*http://*/*
*/*https://*/*
translate.googleapis.com/translate_static/img/loading.gifhttps://translate.googleapis.com/translate_static/img/loading.gif
accounts.google.com-https://accounts.google.com/
chrome.google.com/webstorehttps://chrome.google.com/webstore
mail.google.com/mail/ca/https://mail.google.com/mail/ca/
mail.google.com/mail/https://mail.google.com/mail/
mail.google.com/mail/ca/*https://mail.google.com/mail/ca/*
Showing 1 to 10 of 20 rows
Rows per page:

Gain full insight into all external connections.

Upgrade for full visibility.

No IP addresses found
Showing 1 to 10 of 20 rows
Rows per page:

Code Diff

Compare extension code between any two versions.

0 changed files (scanned top 25 shared text files)

No comparable text files found between these versions.

Browse and explore files within this extension package

Gain full insight into all external connections.

Upgrade for full visibility.