Chrome Web Store
43Versions
1Code reviewed

Do not install

Code review: critical (v3.4.14)

Our reviewer read version 3.4.14 of this extension and confirmed malicious behaviour. 5 security findings documented below. Do not install it. Remove it if you already have it.

What our analysis found

Stylish - Custom themes for any website, used by 2,000,000 people, is rated malicious by Extension Auditor. Our code review reported 5 findings (4 critical, 1 high), led by network interception. Its permissions mean it can read and change data on all websites, can inject scripts into pages and can observe network requests.

Key findings

  • critical· network interception —The extension overwrites XMLHttpRequest.open and.send to intercept all XHR traffic, capturing request URLs, response text, and uploaded file data. It then dispatches custom events ('antifork') to feed intercepted data to its rule engine. This is far outside the scope of a CSS-theming extension and constitutes unauthorized network monitoring.
  • critical· network interception —The extension intercepts all fetch traffic, cloning and reading response bodies, even when they contain binary streams. It captures request and response data, including file uploads, and dispatches them. This is unnecessary for a theme app and clearly designed for data harvesting.
  • critical· network interception —The extension overwrites the WebSocket constructor to intercept all WebSocket messages, forwarding them to its internal system. This further expands its surveillance capability beyond the extension's advertised function.
  • critical· unauthorized data collection —This function, part of the 'EqualsSign' module, sends extracted data (scraps) to the background service worker via chrome.runtime.sendMessage. The data includes DOM-scraped content and intercepted network payloads, as processed by the dynamic rule engine. This is the exfiltration point for collected information.
  • high· obfuscation —The 'EmitStop' module decodes obfuscated rule configurations from chrome.storage.local (BufferEquals) using a transposition cipher and base64. This obfuscation hides the true nature of the data collection rules and indicates an intent to conceal functionality from reviewers.

The extension contains extensive, unauthorized data-collection functionality that is unrelated to its stated purpose of applying custom CSS themes. It monkey-patches XMLHttpRequest, fetch, and WebSocket to intercept all network traffic, extracts DOM content via a dynamic rule engine, and exfiltrates data via chrome.runtime.sendMessage. The rules are obfuscated and remotely updatable, a hallmark of spyware. The privacy disclosure mentions only 'Web history', which does not cover the granular page content, ad details, and request payloads collected. The publisher historically engaged in similar tracking with a previous version of Stylish.

Stylish - Custom themes for any website

Stylish - Custom themes for any website

ID: fjnbnpbmkenffdnngjfgmeleoegfcffe

Supported Languages

🇧🇷Brazilian Portuguese
🇺🇸English
🇷🇺Russian
🇪🇸Spanish

Extension Info & Metadata

Status
Active
Version
3.5.2
Size
1.52 MB
Rating
4.3/5
Reviews
22,300
Users
2,000,000
Type
Extension
Updated
Sep 22, 2026
Category
Just for fun
Price
Free
Featured
Yes
Visibility
Listed
Mature
No
By Google
No
Trusted
Yes
This publisherTrack record
1extension
All still listed

Publisher Contextual Analysis

Trusted
Author
Similarweb LTDView Profile
MX records exist
Yes
Domain exists
Yes
Is disposable
No
Is role-based
Yes
Mailbox exists
Yes
Website
Visit
Extensions
1
Active
1
Obsolete
0
Listed
1
Unlisted
0
Users
2,000,000

Screenshots & videos

Screenshot 2
Screenshot 3
Screenshot 4
Screenshot 5
Screenshot 6

Install growth

Item
Type
Severity
Description
scripting
Permission
Critical
This permission allows injection and execution of JavaScript on any webpage. Rated Critical because it can modify page content, steal sensitive data, and inject malicious code into any site the extension has access to.
webRequest
Permission
Critical
This permission enables the extension to monitor and analyze all web requests made by the browser. Rated Critical because it can observe all network traffic including sensitive data, track browsing behavior, and gather authentication tokens.
*://*/*
Host
Critical
Broad host access — the extension can read/modify content on every website.
<all_urls>
Risk Factor
Critical
This permission grants access to all websites without restriction. Rated High because it can access any web content, monitor all web activity, and potentially steal sensitive data across all sites.
Dangerous Permission Combination: scripting,<all_urls>,webRequest
Risk Factor
Critical
Enables sophisticated data theft through script injection and traffic monitoring
webNavigation
Permission
High
This permission enables monitoring of all browser navigation events and transitions. Rated High because it can track every page visit, navigation method, and browsing pattern, potentially exposing sensitive browsing behavior and user activities.
Contextual Risk Factors
Risk Factor
High
The following context increases the overall risk:• 10% increase: Early script execution enables pre-emptive content manipulation• 10% increase: About:blank access enables potential sandbox escape vectors
Broad Host Permissions
Risk Factor
High
This extension has broad host permissions allowing it to access many or all websites.
Broad Content Script Access
Risk Factor
High
This extension can inject scripts into any website.
storage
Permission
Medium
This permission allows storing data locally in the browser. Rated Medium because it can persist sensitive user data, track user activities over time, and potentially store malicious payloads.
tabs
Permission
Medium
This permission enables tab management and monitoring. Rated Medium because it can track open tabs, access tab metadata, and monitor user browsing patterns.
Early Content Script Execution
Risk Factor
Medium
This extension runs content scripts at document_start.
About:blank Access
Risk Factor
Medium
This extension can run content scripts in about:blank pages.
alarms
Permission
Low
This permission schedules periodic tasks. Rated Low because it can only trigger events at specified times without access to sensitive data.
contextMenus
Permission
Low
This permission adds items to browser context menus. Rated Medium because it only modifies right-click menus without access to page content.

Gain full insight into all external connections.

Upgrade for full visibility.

About this extension

With hundreds of thousands of themes, skins & free backgrounds, you can customize any website with your own color scheme in a click.

Read the publisher’s full description

Style the web your way – with just one click. Stylish gives you access to over 500,000 free website themes, skins, and backgrounds created by a vibrant community. Stylish makes your internet experience uniquely yours-no coding needed. 🌐 Customize your favorite websites instantly - Browse the largest library of custom website themes for top sites like Roblox, Discord, YouTube, Facebook, Google, and more - Change backgrounds, color schemes, fonts, buttons, and even add animations to any site - Choose from trending aesthetic styles, dark modes, rainbow effects, anime themes, and more - Enable, disable, edit, or delete styles at any time with ease 🎨 Make your own custom themes Want a truly personalized theme? Stylish lets you go beyond: - Use our built-in CSS editor to create your own styles - Share your work with millions via userstyles.org - Get help and guidance in our coding help center - https://userstyles.org/help/coding Whether you're customizing your favorite social media site or building the best Chrome themes, Stylish makes it simple. 👥 Join the Stylish community - Over 3 million users already use Stylish to customize websites their way - Trusted and actively maintained by one of the largest website theme-sharing communities online - Stay inspired and explore new looks every day Important notes: ★ We care about your privacy it’s important for us that you understand our data practices: Stylish provides you with suggestions and access to relevant styles for pages you visit, as well as the number of times each style has been installed. To enable this service, we collect anonymous browsing data as described in our privacy policy https://userstyles.org/privacy-policy, including: All Host, tabs, webNavigation, webRequest, context Menus, and storage. The collected data is not used to identify individual users, and you can always turn this automatic data collection off on the add-on option page. ★ Currently, Global themes are not supported in the ‘Style Library’ tab. You can reach them through the Website Library.

User reviews

Extension files

Browse and explore files within this extension package

Gain full insight into all external connections.

Upgrade for full visibility.

URLs
142

URLs

View the external URLs this extension communicates with to understand its network activity and data interactions.

No URLs found
No IP addresses found

Gain full insight into all external connections.

Upgrade for full visibility.

Showing 1 to 10 of 50 rows
Rows per page:

Code Diff

Compare extension code between any two versions.

0 changed files detected

No comparable text files found between these versions.

Gain full insight into all external connections.

Upgrade for full visibility.

Popular in Just for Fun