Chrome Web Store
10Versions
1Code reviewed

Caution required

Suspicious in code review

Our reviewer found behaviour consistent with malware, but not enough to confirm it. Treat this extension as untrusted until it has been re-reviewed.

What our analysis found

Rugby Rush is rated caution by Extension Auditor. Our code review reported 3 findings (1 high, 2 medium), led by other. It comes from a publisher with 28 extensions and was last updated in April 2026.

Key findings

  • high· other —The bundled manifest requests no permissions and no host_permissions, but the live Chrome Web Store listing for this extension declares `permissions: ["identity"]` and `host_permissions: [" ", " "]`. `identity` plus ` ` is precisely the capability pair needed to mint a Google OAuth access token via chrome.identity.getAuthToken and call Google APIs with it, and `wheel.cloudapi.stream` gives a destination on the domain named as C2 in the Socket 108-extension session-theft campaign — none of which a self-contained canvas rugby game, which in this build touches only localStorage, has any use for. The divergence between the archived package and the published manifest means the shipped build carries privileges absent from the code available for review, which is the signature of a staged / delayed-malicious update.
  • medium· other —`externally_connectable` is opened to `<all_urls>`, which lets script on any website in the world call into this extension's service worker. It is inert in this specific build — grep across,, and finds no `onMessageExternal` or `onConnectExternal` handler — but it is a deliberate, functionless widening of the extension's attack surface in a game that never communicates with a web page, and paired with the live manifest's `identity` permission it is the standard shape for letting an attacker-controlled page ask the extension to hand over a Google OAuth token.
  • medium· other —Every install, every auto-update and every uninstall opens a top-level browser tab at ` /`, a domain the publisher controls and the domain recorded as the C2 for the Socket 108-extension data-exfiltration campaign. The payload itself (install reason + extension id) is not sensitive, but handing a campaign-controlled origin an attacker-timed, first-party top-level navigation on every silent background update — in a game with no account, no backend and no network code anywhere else in the bundle — is a remote-controlled delivery channel, not install analytics, and the extension's CWS disclosure declares no data collection at all. The same domain hosts the publisher's only privacy policy, so the first-party-destination exemption cannot be used to clear it.

The game code in this bundle is a clean, unmodified CodeThisLab 'Rugby Rush' HTML5 template ( is + CreateJS game logic; is the stock template glue; /* is stock Bootstrap 5.3.7 and is not even loaded by), and the bundled manifest declares zero permissions and zero host_permissions. The incriminating evidence is the mismatch with the live CWS manifest, which declares `identity` plus host_permissions ` and ` — i.e. the shipped extension holds Google OAuth-token capability and a channel to a cloudapi.stream subdomain that nothing in this archived game build needs or uses — combined with:16-22 opening top-level tabs at `cloudapi.stream` on every install, update and uninstall. cloudapi.stream is the C2 named in the Socket 108-extension data-exfiltration / session-theft campaign, and it is also the domain hosting this publisher's entire 'privacy policy', so the usual first-party-destination exemption does not clear it; the malicious sibling extensions corroborate but are not my basis. Confidence is medium, not high, because the code that would use `identity` is not in what I was given: this extraction is badly incomplete (15 files versus the 5,191 / 15-JS the ML features were computed over; loads jquery-3.2.1, createjs, screenfull, sprintf, howler and CLang., none of which are present, and there is no `_locales/` despite the manifest's `__MSG_` placeholders), so I could read no code that exercises the live manifest's privileges.

Rugby Rush

Rugby Rush Chrome extension security report

ID: cpnfioldnmhaihohppoaebillnambcgn

Supported Languages

🇸🇦Arabic
🇧🇬Bulgarian
🇨🇳Chinese (Simplified)
🇹🇼Chinese (Traditional)
🇭🇷Croatian
🇨🇿Czech
🇩🇰Danish
🇳🇱Dutch
🇺🇸English
🇪🇪Estonian
🇵🇭Filipino
🇫🇮Finnish
🇫🇷French
🇩🇪German
🇬🇷Greek
🇮🇱Hebrew
🇭🇺Hungarian
🇮🇩Indonesian
🇮🇹Italian
🇯🇵Japanese
🇰🇷Korean
🇱🇻Latvian
🇱🇹Lithuanian
🇳🇴Norwegian
🇮🇷Persian
🇵🇱Polish
🇷🇴Romanian
🇷🇺Russian
🇷🇸Serbian
🇸🇰Slovak
🇸🇮Slovenian
🇪🇸Spanish
🇸🇪Swedish
🇹🇭Thai
🇹🇷Turkish
🇺🇦Ukrainian
🇻🇳Vietnamese

Extension Info & Metadata

Status
Active
Version
1.5.5
Size
138.00 MB
Rating
5.0/5
Reviews
3
Users
353
Type
Extension
Updated
Apr 16, 2026
Category
Games
Price
Free
Featured
No
Visibility
Listed
Mature
No
By Google
No
Trusted
No
This publisherTrack record
28extensions
10 no longer listed

Publisher Contextual Analysis

Author
YanaProject
MX records exist
Yes
Domain exists
Yes
Is disposable
No
Is role-based
No
Mailbox exists
Yes
Website
Visit
Extensions
28
Active
18
Obsolete
10
Listed
28
Unlisted
0
Users
5,113

Screenshots & videos

Screenshot 1

Install growth

This extension requests no permissions and has no recorded risk factors.

  • 1 high
  • 2 medium

The file, code excerpt and explanation behind each finding are part of the full report. No conclusion has been withheld — only the evidence. The verdict above already reflects everything found here.

Gain full insight into all external connections.

Upgrade for full visibility.

About this extension

Rugby Rush: Chrome extension game

Read the publisher’s full description

Run the field and pass all the defenders as you rush to the try zone. Score to complete each level in this fun online rugby running game. You can collect power ups and bonuses to become stronger and get more points!

User reviews

Extension files

Browse and explore files within this extension package

Gain full insight into all external connections.

Upgrade for full visibility.

No network indicators were extracted from this version.

Version
Size
Verdict
Findings
Permhash
1.5.5
Latest
138.00 MBCaution0N/A
1.5.4
138.00 MBCaution—
689f6a627384c7dcb2dcc1487e540223e77bdf9dcd0d8be8a326eda65b0ce9a4
1.5.0
139.00 MBCaution—
689f6a627384c7dcb2dcc1487e540223e77bdf9dcd0d8be8a326eda65b0ce9a4
1.4.2
134.93 MBCaution—N/A
1.4.1
134.93 MBCaution—N/A
1.4.0
134.93 MBCaution—N/A
1.2.0
77.47 MBCaution—N/A
1.0.0
75.76 MBCaution—N/A
1.4.3
135.00 MBCaution—N/A
1.3.0
135.00 MBCaution—N/A
Showing 1 to 10 of 10 rows
Rows per page:

Code Diff

Compare extension code between any two versions.

0 changed files detected

No comparable text files found between these versions.

Gain full insight into all external connections.

Upgrade for full visibility.