Security Warning: High Security Risk
PixViewer
ID: lbdkjmcmikdimbaclamdopflohiidbpn
Supported Languages
Extension Info & Metadata
Publisher Contextual Analysis
- Author
- nmihaly0113View Profile
- Privacy
- Privacy Policy
- MX records exist
- Yes
- Domain exists
- Yes
- Is disposable
- No
- Is role-based
- No
- Mailbox exists
- Yes
Desktop experience in your browser - inspired by the Google™ Image Viewer
❓ Do you want to inspect an image quickly in your browser? 🤩 Then Say Hello To PixViewer! ⭐A full-fledged image viewer with many features, while remaining easy-to-use! 🔥 It is lightweight and incredibly fast! 💯 Works on every image - even SVGs! ⚪ Modern and safe: 👉 Comes with a built-in feature that can access hidden details of the photo like the creation date or location, without ever having to download or upload the image anywhere! ⚪ Make it your own: 👉 Fully customizable look and feel - change the list of displayed buttons with ease, or hide the UI completely!
This extension requests no permissions and has no recorded risk factors.
The bundled manifest declares zero permissions, yet the live CWS listing for this same extension ID discloses permissions=[storage, scripting, declarativeNetRequest] and host_permissions=[<all_urls>]. 'scripting' grants programmatic JS injection into any page, and 'declarativeNetRequest' grants the ability to block or redirect network requests — both high-capability APIs entirely absent from the analysed code. The discrepancy strongly indicates a version on the store that differs from the ZIP captured for analysis, consistent with a post-install permission-escalation update pattern.
{ "name": "Image Viewer+", "author": "skyfighteer", "version": "1.0.1", "manifest_version": 3, "content_scripts": [ { "js": ["content-script.js"], "matches": ["<all_urls>"] } ] // NO 'permissions' or 'host_permissions' keys present}The extension identity inside the ZIP (name 'Image Viewer+', author 'skyfighteer') does not match the CWS listing (name 'PixViewer', publisher 'nmihaly0113'). An identity mismatch of this magnitude — both name and author — suggests the extension was transferred or rebranded, which is a known vector for bait-and-switch attacks where a clean extension acquires users before ownership changes and a malicious update is pushed. This corroborates the permission mismatch above.
{ "name": "Image Viewer+", "author": "skyfighteer", ...}// CWS listing name: 'PixViewer', publisher account: 'nmihaly0113'By severity
Versions scanned
Showing 1 of 10 scanned versions with more than one unique finding. Counts are unique findings that include each version.
| Extension Version | Code Review Findings |
|---|---|
| 1.0.1 | 2 |
Files with findings
1 distinct path — top paths by unique finding count:
- manifest.json2
URLs
View the external URLs this extension communicates with to understand its network activity and data interactions.
Gain full insight into all external connections.
Upgrade for full visibility.
Gain full insight into all external connections.
Upgrade for full visibility.
Code Diff
Compare extension code between any two versions.
No comparable text files found between these versions.
Browse and explore files within this extension package
Gain full insight into all external connections.
Upgrade for full visibility.