Security Alert: Confirmed Malware
RoSE Extension
ID: bdimfdbofjdbpjgpadkcoffiolffblal
Extension Info & Metadata
Publisher Contextual Analysis
- Author
- service.enterprise.extensionsView Profile
- Privacy
- Privacy Policy
- Country
- CH
- MX records exist
- Yes
- Domain exists
- Yes
- Is disposable
- No
- Is role-based
- No
- Mailbox exists
- Yes
- Address
- Grenzacherstrasse 124 Basel 4058 CH
Roche Service Experience Extension
Redirection to the Roche Service Experience portal (RoSE) URL
'unsafe-eval' in the CSP is a hygiene issue inherited from older jQuery builds; it permits eval() inside the extension popup. With zero permissions this is exploitable only via XSS inside the popup itself, which has no external input surface. Low risk in practice but should be replaced with a stricter CSP in any future version.
{ "content_security_policy": "script-src 'self' 'unsafe-eval'; object-src 'self'"}By severity
Versions scanned
None of the 1 scanned version has more than one unique code-review finding. Counts are unique findings that include each version.
| Extension Version | Code Review Findings |
|---|---|
| No versions with multiple unique findings. | |
Files with findings
1 distinct path — top paths by unique finding count:
- manifest.json1
URLs
View the external URLs this extension communicates with to understand its network activity and data interactions.
Gain full insight into all external connections.
Upgrade for full visibility.
Gain full insight into all external connections.
Upgrade for full visibility.
Browse and explore files within this extension package
Gain full insight into all external connections.
Upgrade for full visibility.