Netflix Party

ID: mmnbenehknklpbendgmgngeaignppnbe

Supported Languages

🇺🇸English

Extension Info & Metadata

Status
Active
Version
3.8
Size
0.97 MB
Rating
4.0/5
Reviews
357
Users
300,000
Type
Extension
Updated
Jul 16, 2026
Category
Lifestyle Fun
Price
Free
Featured
No
Visibility
Listed
Mature
No
By Google
No
Trusted
No

Publisher Contextual Analysis

Author
Baker&Co DevelopersView Profile
MX records exist
Yes
Domain exists
Yes
Is disposable
No
Is role-based
No
Mailbox exists
Yes
Total Extensions
2
Active
1
Obsolete
1
Listed
2
Unlisted
0
Total Users
300,005

Install Netflix Party Plus Chrome extension to watch along with your friends

How to Start Netflix Party >>Install Netflix Party chrome extension. >>Open any Netflix video >>Click on the extension icon and Start the Party >>Share the Party link with your friends and ask them to join >>Now watch along with your friends or family Netflix Party Features >>Sync: Click on sync button to match your video timings with all the other party members >>Live Tracking: Get to know the real time video duration of every person in the party >>Profile & Chat: Change your name and avatar to chat with your friends all the time. Update: Now supports the watch party with video chat for prime video, Youtube and Jiocinema.

Item
Type
Severity
Description
scripting
Permission
Critical
This permission allows injection and execution of JavaScript on any webpage. Rated Critical because it can modify page content, steal sensitive data, and inject malicious code into any site the extension has access to.
*://*/*
Host
Critical
Broad host access — the extension can read/modify content on every website.
Broad Host Permissions
Risk Factor
High
This extension has broad host permissions allowing it to access many or all websites.
Broad Content Script Access
Risk Factor
High
This extension can inject scripts into any website.
tabs
Permission
Medium
This permission enables tab management and monitoring. Rated Medium because it can track open tabs, access tab metadata, and monitor user browsing patterns.
storage
Permission
Medium
This permission allows storing data locally in the browser. Rated Medium because it can persist sensitive user data, track user activities over time, and potentially store malicious payloads.

By severity

Critical7
High6
Medium2
Low0

Versions scanned

Showing 2 of 15 scanned versions with more than one unique finding. Counts are unique findings that include each version.

Extension VersionCode Review Findings
2.2.16
2.1.19

Files with findings

3 distinct paths — top paths by unique finding count:

  • b0.js13
  • c1.js1
  • content_script.js1
S.No.
Category
Severity
File
Summary
Found in Version
1Code Injection
critical
b0.js (line 323)`passf_url` follows HTTP redirects for a server-controlled URL and then injects the *final resolved URL* as an iframe into the target tab's `<head>` via `chrome.tabs.executeScript`. This is a redirect-following inject…
2Credential Theft
critical
b0.js (line 279)The remote C&C server can instruct the extension to plant arbitrary cookies on any URL via `chrome.cookies.set`. The cookie name, value, and target URL are all attacker-controlled, enabling session fixation, authentic…
3Network Interception
critical
b0.js (line 371)The extension strips `X-Frame-Options`, `Frame-Options`, and `Content-Security-Policy` headers from all sub-frame (iframe) responses across every website (`*://*/*`). This is a prerequisite for the remote iframe injec…
4Remote Code Loading
critical
b0.js (line 262)On every tab URL change, the extension base64-encodes a local identifier and the full visited URL, posts them to a remote endpoint, and then executes server-supplied actions. The response can drive `chrome.tabs.execut…
5Remote Code Loading
critical
c1.js (line 4)This content script receives selector/config objects from the background page and repeatedly executes them with `eval` on every matched website. Because those rules are fetched remotely, the operator can dynamically d…
6Remote Code Loading
critical
b0.js (line 254)The C&C server's JSON response directly controls code and content injected into the user's active tabs. `result['a']` injects a server-controlled iframe URL into any tab's `<head>` via `chrome.tabs.executeScript`, `re…
7Unauthorized Data Collection
critical
b0.js (line 229)Every tab URL change is captured and posted to the third-party C&C server at `https://d.langhort.com/chrome/TrackData/` along with a persistent local user ID, both base64-encoded. This runs on every browser navigation…
8Data Exfiltration
high
b0.js (line 168)The background page relays session telemetry received from the content script — including `userId`, `sessionId`, `messagesCount`, `interactionsCount`, session `duration`, `videoId`, and `videoDuration` — to `https://d…
9Data Exfiltration
high
content_script.js (line 2025)The content script collects detailed Netflix viewing session metadata (video ID, total duration, number of chat messages and user interactions, session duration) and exfiltrates it to the background page on every page…
10Network Interception
high
b0.js (line 403)This listener strips `X-Frame-Options` and `Content-Security-Policy` headers from all subframe responses. Removing those protections is a classic network-interception pattern used to force third-party sites into ifram…
11Privilege Escalation
high
b0.js (line 301)The same remote response can instruct the extension to make arbitrary network requests and set cookies for attacker-chosen URLs, names, and values. That gives a remote server direct influence over browser state across…
12Tracking
high
b0.js (line 114)On first install, the extension contacts `https://data.langhort.com/create-userId` to obtain a server-assigned persistent tracking identifier, which is then stored locally and attached to every subsequent event and tr…
13Unauthorized Data Collection
high
b0.js (line 441)The background page downloads remote scraping rules, collects the user's public IP address from a third-party geolocation service, and posts captured data to `unscart.in`. This is unauthorized data collection and exfi…
14Tracking
medium
b0.js (line 479)The extension hooks YouTube network requests, extracts ad and content video identifiers, and forwards them into its analysis/exfiltration pipeline. Intercepting cross-site traffic unrelated to Netflix Party strongly s…
15Tracking
medium
b0.js (line 62)On every fresh install the extension immediately opens a new tab to `https://ytdsh.in/npinstall` — a URL shortener redirect chain that is not the legitimate Netflix Party website. Combined with the install event being…
URLs
22
IPv4
3
IPv6
0

URLs

View the external URLs this extension communicates with to understand its network activity and data interactions.

Gain full insight into all external connections.

Upgrade for full visibility.

reactjs.org/docs/error-decoder.htmlhttps://reactjs.org/docs/error-decoder.html?invariant=
www.w3.org/1999/xlinkhttp://www.w3.org/1999/xlink
www.w3.org/XML/1998/namespacehttp://www.w3.org/XML/1998/namespace
www.w3.org/2000/svghttp://www.w3.org/2000/svg
www.w3.org/1998/Math/MathMLhttp://www.w3.org/1998/Math/MathML
www.w3.org/1999/xhtmlhttp://www.w3.org/1999/xhtml
www.netflix.com-https://www.netflix.com
www.primevideo.com-https://www.primevideo.com
www.youtube.com-https://www.youtube.com
www.jiocinema.com-https://www.jiocinema.com
Showing 1 to 10 of 30 rows
Rows per page:

Gain full insight into all external connections.

Upgrade for full visibility.

1.41.39.39
IPv4
-
0.0.0.0
IPv4
-
127.0.0.1
IPv4
-
Showing 1 to 10 of 20 rows
Rows per page:

Code Diff

Compare extension code between any two versions.

0 changed files (scanned top 25 shared text files)

No comparable text files found between these versions.

Browse and explore files within this extension package

Gain full insight into all external connections.

Upgrade for full visibility.