Chrome Web Store
169Versions
15Code reviewed

Caution required

Suspicious in code review (v2.26.1)

Our reviewer found behaviour consistent with malware in version 2.26.1, but not enough to confirm it. Treat this extension as untrusted until it has been re-reviewed.

What our analysis found

Pocket Universe, used by 100,000 people, is rated caution by Extension Auditor. Our code review reported 2 findings (1 high, 1 medium), led by other. Its permissions mean it can inject scripts into pages and can observe network requests.

Key findings

  • high· other —The bundled manifest declares `sidePanel` (line 38) and `offscreen` (line 39) permissions that are absent from the published CWS manifest. The published manifest additionally lists `file://*/*` in host_permissions, which the bundled manifest omits. Because `sidePanel` and `offscreen` cannot be acquired at runtime—they must be in the installed manifest—users approved a narrower permission scope than what the extension actually holds. This divergence between disclosed and actual permissions is a meaningful integrity concern for an extension that handles wallet transaction signing.
  • medium· obfuscation —The build system injects documentation strings explicitly asserting that the visible API domain strings are decoy 'honeypot' aliases and that real network traffic is domain-fronted through Cloudflare Workers in a way designed to evade network monitoring. Companion comments in aster-consent-bridge. (lines 447–452, 1042–1043) make parallel claims: visible postMessage event types deliver only 'synthetic honeypot data' while real inter-context messaging uses ECDH-derived encrypted BroadcastChannel, and visible storage keys are write-only honeypots while real storage uses opaque HKDF-derived IndexedDB identifiers. These strings are dead code (assigned to unused variables), but the explicit intent to present false artifacts to code analysis tools—rather than merely encrypting communications for security—is an unusual anti-analysis posture that cannot be reconciled with the visible source alone. Without the background service worker the claims are unverifiable.

Pocket Universe is a well-established Web3 security extension (4+ years, 100K users, Google, ML score 0.00) whose core function—intercepting transactions to warn on scams and collecting builder fees from DeFi protocols—explains its broad permissions and all-site content scripts. Two concrete concerns prevent a clean clearance: (1) the bundled manifest includes `sidePanel` and `offscreen` permissions absent from the published CWS manifest, meaning the extension operates with elevated permissions beyond what users approved at install time; (2) build-transform comment strings in relay-website. and aster-consent-bridge. explicitly state that visible API domains, message type strings, and storage keys are injected as 'honeypot' decoys and that real traffic, messaging, and storage use encrypted, opaque channels designed to be undetectable by network monitoring and code analysis—language that goes well beyond standard anti-tamper hardening. The third-party likelihood score () and corroboration signals (publisher trust, user count, age) favor a legitimate product, but the anti-analysis documentation and permission mismatch warrant a suspicious rather than benign rating, particularly without access to the background service worker where the claimed hidden behavior would reside.

Pocket Universe

Pocket Universe Chrome extension security report

ID: gacgndbocaddlemdiaadajmlggabdeod

Supported Languages

🇺🇸English

Extension Info & Metadata

Status
Active
Version
2.33.0
Size
7.51 MB
Rating
4.8/5
Reviews
196
Users
100,000
Type
Extension
Updated
Oct 5, 2026
Category
Make_chrome_yours Privacy
Price
Free
Featured
Yes
Visibility
Listed
Mature
No
By Google
No
Trusted
Yes
This publisherTrack record
1extension
All still listed

Publisher Contextual Analysis

Trusted
Author
https://pocketuniverse.app
Country
US
MX records exist
Yes
Domain exists
Yes
Is disposable
No
Is role-based
No
Mailbox exists
Yes
Address
254 Chapman Rd ste 209 Newark, DE 19702 US
Website
Visit
Extensions
1
Active
1
Obsolete
0
Listed
1
Unlisted
0
Users
100,000

Email Change History

2 changes
Aug 14, 2024
Domain changed
Aug 14, 2025
Domain changed

You reached today's free scan limit (3/3 unique extensions).

Upgrade for full visibility.

Screenshots & videos

Screenshot 1
Screenshot 2
Screenshot 3
Screenshot 4

Install growth

Item
Type
Severity
Description
scripting
Permission
Critical
This permission allows injection and execution of JavaScript on any webpage. Rated Critical because it can modify page content, steal sensitive data, and inject malicious code into any site the extension has access to.
declarativeNetRequest
Permission
Critical
This permission allows the extension to define rules to block, redirect, or modify network requests. Rated Critical because it can control all network traffic, potentially blocking security updates or redirecting to malicious sites.
webRequest
Permission
Critical
This permission enables the extension to monitor and analyze all web requests made by the browser. Rated Critical because it can observe all network traffic including sensitive data, track browsing behavior, and gather authentication tokens.
http://*/*
Host
Critical
Broad host access — the extension can read/modify content on every website.
https://*/*
Host
Critical
Broad host access — the extension can read/modify content on every website.
offscreen
Permission
High
This permission creates hidden browser documents with full DOM access. Rated High because it can run background operations invisibly, potentially executing malicious code without user awareness.
Contextual Risk Factors
Risk Factor
High
The following context increases the overall risk: • 10% increase: Early script execution enables pre-emptive content manipulation • 10% increase: About:blank access enables potential sandbox escape vectors
storage
Permission
Medium
This permission allows storing data locally in the browser. Rated Medium because it can persist sensitive user data, track user activities over time, and potentially store malicious payloads.
ws://*/*
Host
Medium
Host permission — access limited to this URL pattern.
wss://*/*
Host
Medium
Host permission — access limited to this URL pattern.
Early Content Script Execution
Risk Factor
Medium
This extension runs content scripts at document_start.
About:blank Access
Risk Factor
Medium
This extension can run content scripts in about:blank pages.
sidePanel
Permission
Low
This permission adds custom panels to the browser interface. Rated Low because it only affects browser UI elements and cannot access page content.
alarms
Permission
Low
This permission schedules periodic tasks. Rated Low because it can only trigger events at specified times without access to sensitive data.

You reached today's free scan limit (3/3 unique extensions).

Upgrade for full visibility.

About this extension

Protects your assets from scams.

Read the publisher’s full description

Join Pocket Universe, the security tool that protects you from scams. ☔ Every Pocket Universe user can get transaction coverage up to $20,000 (it’s optional and comes with a fee) 🛡️ We protect over 200K+ users. Add our extension to your browser and transact like normal. We’ll pop up before your wallet so that you can: 1️⃣ See what you’re signing See what assets are being moved in every web3 transaction. 2️⃣ Get clear warnings on scams We detect malicious transactions designed to steal your assets. It takes one click to install and you don’t need to connect your wallet. 
Get your peace of mind back with Pocket Universe.

User reviews

Extension files

Browse and explore files within this extension package

You reached today's free scan limit (3/3 unique extensions).

Upgrade for full visibility.

URLs
147
IPv4
9

URLs

View the external URLs this extension communicates with to understand its network activity and data interactions.

No URLs found
No IP addresses found

You reached today's free scan limit (3/3 unique extensions).

Upgrade for full visibility.

Version
Size
Verdict
Findings
Permhash
2.33.0
Latest
7.51 MBNot scanned—
cae9b4f31607c95a37d35b16f6bec6339355e9f59a12a276bb3fbd5242be8e2a
2.32.0
7.34 MBNot scanned—
cae9b4f31607c95a37d35b16f6bec6339355e9f59a12a276bb3fbd5242be8e2a
2.31.0
7.32 MBNot scanned—
cae9b4f31607c95a37d35b16f6bec6339355e9f59a12a276bb3fbd5242be8e2a
2.29.0
7.16 MBNot scanned—
cae9b4f31607c95a37d35b16f6bec6339355e9f59a12a276bb3fbd5242be8e2a
2.28.0
6.94 MBNot scanned—
cae9b4f31607c95a37d35b16f6bec6339355e9f59a12a276bb3fbd5242be8e2a
2.27.0
6.94 MBNot scanned—
cae9b4f31607c95a37d35b16f6bec6339355e9f59a12a276bb3fbd5242be8e2a
2.26.1
8.88 MBCaution0
cae9b4f31607c95a37d35b16f6bec6339355e9f59a12a276bb3fbd5242be8e2a
2.25.0
8.87 MBCaution0
cae9b4f31607c95a37d35b16f6bec6339355e9f59a12a276bb3fbd5242be8e2a
2.24.0
8.86 MBCaution0
cae9b4f31607c95a37d35b16f6bec6339355e9f59a12a276bb3fbd5242be8e2a
2.23.0
8.67 MBCaution0
cae9b4f31607c95a37d35b16f6bec6339355e9f59a12a276bb3fbd5242be8e2a
Showing 1 to 10 of 170 rows
Rows per page:

Code Diff

Compare extension code between any two versions.

0 changed files detected

No comparable text files found between these versions.

You reached today's free scan limit (3/3 unique extensions).

Upgrade for full visibility.

Popular in make_chrome_yours/privacy