Security Alert: Malware Risk Confirmed
Real Valladolid Club De Fútbol
ID: opjmhbemagooegecfaakiihaoooljbhi
Extension Info & Metadata
Publisher Contextual Analysis
- Author
- brandTURBOView Profile
- Privacy
- Privacy Policy
- Help
- Help Center
- Country
- DE
- MX records exist
- Yes
- Domain exists
- Yes
- Is disposable
- No
- Is role-based
- Yes
- Mailbox exists
- Yes
- Address
- Straßburger Str. 55 Berlin 10405 DE
- Website
- Visit
Contenido exclusivo del del Real Valladolid Club de fútbol.
Contenido creado exclusivamente para el google store. Los aficionados podrán personalizar su escritorio con contenido especial del Real Valladolid. Además podrán estar al tanto de todas las noticias y tener acceso directo a las secciones principales del club. Descarga esta extensión para ser el mayor fanático del club y contar con nuevos elementos exclusivos. Se trata de una extensión empresarial de marca blanca para Real Valladolid CF.
All user searches are routed through m.instantsearch.net with a persistent revenue-tracking tag (rtag=rlvll, rsrc=e). The 'search' permission in the bundled manifest enables this browser-level search override. This constitutes undisclosed commercial search monetization to a third-party platform — the CWS listing describes only branded fan content with no mention of search redirection.
e.n = 1, fetch(i, { mode: "cors", credentials: "include", redirect: "follow", method: "GET"})// where i = (0, u.Gy)("https://m.instantsearch.net/themes", d(d({},// r), {}, {// id: o,// rtag: s.XZ,// rsrc: "e",// jsv: s.Y3// }))The bundled manifest (MV3) declares 'favicon' and 'search' as required permissions while the published CWS listing shows MV2 with only 'topSites' required (favicon as optional via chrome://favicon/, search absent). The 'search' permission specifically enables overriding the browser's search engine — the mechanism that powers the undisclosed search monetization through instantsearch.net. This version-to-listing mismatch suggests the publisher updated the bundle without updating the CWS listing metadata.
{ "manifest_version": 3, "permissions": [ "topSites", "favicon", "search" ], "optional_permissions": [ "history", "bookmarks" ]}The extension fetches its configuration from m.instantsearch.net, a third-party commercial search platform, passing user-specific tracking parameters including rtag='rlvll' and jsv (JS version) with credentials included. This is not first-party (publisher domain is brandturbo.vip / realvalladolid.es) and is not disclosed in the CWS data-collection declaration. The 'credentials: include' flag means any cookies the user has at instantsearch.net are transmitted.
v = (0, qt.Gy)("https://m.instantsearch.net/config", Zt(Zt( Zt({}, c), l), {}, { id: p, rtag: y, rsrc: h, draft: m, jsv: Ke.Y3 })), t.n = 2, (0, qt.u9)(v, { mode: "cors", credentials: "include", redirect: "follow", method: "GET" }User interaction events (history clicks, settings changes, background rotations) are sent to the searchturbo analytics endpoint via navigator.sendBeacon with a persistent user-tracking tag (rtag) and session timing. The destination is the searchturbo platform, a third party unrelated to Real Valladolid CF, and this data collection is not disclosed in the CWS listing (declared: none).
navigator.sendBeacon ? n(navigator.sendBeacon(e, JSON.stringify(t))) : n(!1)// payload built above:var i = h(h({}, n), {}, { t: e.type, val: e.value, rtag: t.rtag, rsrc: "e", jsv: u.Y3, te: Math.floor((Date.now() - b) / 1e3)});By severity
Versions scanned
Showing 1 of 2 scanned versions with more than one unique finding. Counts are unique findings that include each version.
| Extension Version | Code Review Findings |
|---|---|
| 4.1.1 | 4 |
Files with findings
2 distinct paths — top paths by unique finding count:
- startpage.js3
- manifest.json1
URLs
View the external URLs this extension communicates with to understand its network activity and data interactions.
Gain full insight into all external connections.
Upgrade for full visibility.
Gain full insight into all external connections.
Upgrade for full visibility.
Code Diff
Compare extension code between any two versions.
No comparable text files found between these versions.
Browse and explore files within this extension package
Gain full insight into all external connections.
Upgrade for full visibility.
