PixViewer

PixViewer

ID: lbdkjmcmikdimbaclamdopflohiidbpn

Supported Languages

🇺🇸English

Extension Info & Metadata

Status
Active
Version
1.0.1
Size
0.12 MB
Rating
4.2/5
Reviews
9
Users
556
Type
Extension
Updated
Sep 11, 2023
Category
Functionality & ui
Price
Free
Featured
Yes
Visibility
Listed
Mature
No
By Google
No
Trusted
Yes

Publisher Contextual Analysis

Trusted
Author
nmihaly0113View Profile
MX records exist
Yes
Domain exists
Yes
Is disposable
No
Is role-based
No
Mailbox exists
Yes
Total Extensions
6
Active
4
Obsolete
2
Listed
6
Unlisted
0
Total Users
2,322
Screenshot 1
Screenshot 2

Desktop experience in your browser - inspired by the Google™ Image Viewer

❓ Do you want to inspect an image quickly in your browser? 🤩 Then Say Hello To PixViewer! ⭐A full-fledged image viewer with many features, while remaining easy-to-use! 🔥 It is lightweight and incredibly fast! 💯 Works on every image - even SVGs! ⚪ Modern and safe: 👉 Comes with a built-in feature that can access hidden details of the photo like the creation date or location, without ever having to download or upload the image anywhere! ⚪ Make it your own: 👉 Fully customizable look and feel - change the list of displayed buttons with ease, or hide the UI completely!

This extension requests no permissions and has no recorded risk factors.

The bundled manifest declares zero permissions, yet the live CWS listing for this same extension ID discloses permissions=[storage, scripting, declarativeNetRequest] and host_permissions=[<all_urls>]. 'scripting' grants programmatic JS injection into any page, and 'declarativeNetRequest' grants the ability to block or redirect network requests — both high-capability APIs entirely absent from the analysed code. The discrepancy strongly indicates a version on the store that differs from the ZIP captured for analysis, consistent with a post-install permission-escalation update pattern.

manifest.json (Line 1)
{  "name": "Image Viewer+",  "author": "skyfighteer",  "version": "1.0.1",  "manifest_version": 3,  "content_scripts": [    {      "js": ["content-script.js"],      "matches": ["<all_urls>"]    }  ]  // NO 'permissions' or 'host_permissions' keys present}

The extension identity inside the ZIP (name 'Image Viewer+', author 'skyfighteer') does not match the CWS listing (name 'PixViewer', publisher 'nmihaly0113'). An identity mismatch of this magnitude — both name and author — suggests the extension was transferred or rebranded, which is a known vector for bait-and-switch attacks where a clean extension acquires users before ownership changes and a malicious update is pushed. This corroborates the permission mismatch above.

manifest.json (Line 3)
{  "name": "Image Viewer+",  "author": "skyfighteer",  ...}// CWS listing name: 'PixViewer', publisher account: 'nmihaly0113'

By severity

Critical0
High1
Medium1
Low0

Versions scanned

Showing 1 of 10 scanned versions with more than one unique finding. Counts are unique findings that include each version.

Extension VersionCode Review Findings
1.0.12

Files with findings

1 distinct path — top paths by unique finding count:

  • manifest.json2
S.No.
Category
Severity
File
Summary
Found in Version
1Other
high
manifest.json (line 1)The bundled manifest declares zero permissions, yet the live CWS listing for this same extension ID discloses permissions=[storage, scripting, declarativeNetRequest] and host_permissions=[<all_urls>]. 'scripting' gran…
2Other
medium
manifest.json (line 3)The extension identity inside the ZIP (name 'Image Viewer+', author 'skyfighteer') does not match the CWS listing (name 'PixViewer', publisher 'nmihaly0113'). An identity mismatch of this magnitude — both name and aut…
URLs
3
IPv4
0
IPv6
0

URLs

View the external URLs this extension communicates with to understand its network activity and data interactions.

Gain full insight into all external connections.

Upgrade for full visibility.

chrome.google.com/webstore/detail/image-zoom/hjapegicpojdkoinhhdpjmpkomkjccaahttps://chrome.google.com/webstore/detail/image-zoom/hjapegicpojdkoinhhdpjmpkomkjccaa
gomakethings.com/how-to-check-if-any-part-of-an-element-is-out-of-the-viewport-with-vanilla-js/https://gomakethings.com/how-to-check-if-any-part-of-an-element-is-out-of-the-viewport-with-vanilla-js/
clients2.google.com/service/update2/crxhttps://clients2.google.com/service/update2/crx

Gain full insight into all external connections.

Upgrade for full visibility.

No IP addresses found
Version
Size
Is Malicious
Findings
Permhash
1.2.4
Latest
0.12 MB
Benign
1.2.3
0.12 MB
Benign
1.2.2
0.12 MB
Benign
1.2.1
0.12 MB
Benign
1.2
0.12 MB
Benign
1.1
0.02 MB
Malicious
N/A
1.0.2
0.02 MB
Malicious
N/A
1.0.1
0.02 MB
Malicious
2N/A
1.0
0.07 MB
Malicious
N/A
1.2.5
0.12 MB
Benign
Showing 1 to 10 of 10 rows
Rows per page:

Code Diff

Compare extension code between any two versions.

0 changed files (scanned top 25 shared text files)

No comparable text files found between these versions.

Browse and explore files within this extension package

Gain full insight into all external connections.

Upgrade for full visibility.