Ship Xanh copy sản phẩm, nhân bản shop, hiển thị % phí sàn, lượt bán tháng
The AI review rates the findings as likely false positive, but the risk score (53/100) still counts them.
Analysis record
- Analysed
- 3 days ago
- Version
- v3.2.62
- Artifact
- SHA256 C1C…A41
- Source
- Findings (non-IoC)
Is Ship Xanh copy sản phẩm, nhân bản shop, hiển thị % phí sàn, lượt bán tháng safe?
The listing describes product copying and shop-management tools for marketplaces such as Shopee and Lazada. This extension declares no special permissions, and the supplied endpoint list is empty. Its bundled code still contains fetch activity in assets/chunk-3cfb730f.js:1:0 and assets/chunk-ea756fd5.js:3:0, plus Socket.IO activity in assets/chunk-77e9fb52.js:38:0 and :40:0, so the app can exchange data with a service even though no destination is named.
The finding titles NET-FETCH-assets/chunk-3cfb730f.js-1 and NET-SOCKET_IO-assets/chunk-77e9fb52.js-38 describe network functions. If those calls reached a harmful or unexpected service, the missing endpoint details would make that hard to see from this page. The listed paths contain no malware signature, obfuscation finding, credential-theft indicator, or suspicious domain finding.
The scanner was triggered by common fetch and Socket.IO code in the bundled files, which fits the product and shop features named in the listing. With no special permissions, no named endpoints, and no malware-related match tied to assets/chunk-3cfb730f.js:1:0, assets/chunk-ea756fd5.js:3:0, or assets/chunk-77e9fb52.js:38:0, the recorded alerts do not show harmful behavior.
Evidence ledger
Ranked by severity · findings with a source location link to the code viewer
Publisher Evidence
Limited evidencePublisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.
Chrome does not expose the same publisher verification data as IDE stores, so this score is deliberately conservative.
12 evidence rows available.
Finding Categories
Requested Permissions
7 permissionsAccess and modify data on every website you visit
Intercept, modify, and block all network requests
AI Security Report
AI Security Review
Evidence context: threat category none; evidence quality moderate.
The extension listing describes tools for copying products and managing shops across Shopee, TikTok, Lazada, 1688, and Taobao. The code paths tied to the findings are assets/chunk-3cfb730f.js:1:0, assets/chunk-ea756fd5.js:3:0, and assets/chunk-77e9fb52.js:38:0 through :40:0. Their titles identify fetch and Socket.IO activity, which fits a web tool that exchanges product, stock, order, or shop data with a service. The supplied endpoint list is empty, so these findings identify network behavior without naming a destination domain.
The strongest signal in the supplied material is NET-SOCKET_IO-assets/chunk-77e9fb52.js-38 and NET-SOCKET_IO-assets/chunk-77e9fb52.js-40. Socket.IO supports persistent client-server updates, which can fit live inventory or order status features described by the listing. NET-FETCH-assets/chunk-3cfb730f.js-1 and NET-FETCH-assets/chunk-ea756fd5.js-3 identify ordinary request code in bundled JavaScript. These titles do not identify credential collection, cookie access, search replacement, injected advertising, proxy routing, or data sent to a suspicious domain.
The absence of a destination domain limits what can be confirmed about the network calls. Still, the listed paths contain no IoC finding, malware signature, obfuscation finding, secret finding, or tool-poisoning finding. assets/chunk-3cfb730f.js:1:0, assets/chunk-ea756fd5.js:3:0, and assets/chunk-77e9fb52.js:38:0 therefore provide evidence of application communications, rather than evidence of a harmful payload. The empty permissions list also gives the extension no declared special browser permission in the supplied metadata.
A skeptic could argue that Socket.IO activity in assets/chunk-77e9fb52.js:38:0 and :40:0 might support hidden tracking or remote control. That concern cannot be resolved from these titles alone because the endpoint list is empty and the finding descriptions contain no destination or payload detail. It also lacks support from the other recorded indicators: NET-FETCH-assets/chunk-3cfb730f.js-1 and NET-FETCH-assets/chunk-ea756fd5.js-3 are generic fetch detections, while no IoC, malware, obfuscation, or secret finding is recorded. Runtime URL inspection would be needed to establish a harmful destination.
The available evidence therefore supports treating these findings as bundled application network behavior. The remaining uncertainty comes from the missing endpoint details, rather than from a concrete malicious indicator in the cited files.
Key Reasons
NET-FETCH-assets/chunk-3cfb730f.js-1andNET-FETCH-assets/chunk-ea756fd5.js-3identify generic fetch code in bundled application files.NET-SOCKET_IO-assets/chunk-77e9fb52.js-38andNET-SOCKET_IO-assets/chunk-77e9fb52.js-40fit live shop or inventory communication.- The supplied endpoint list and permissions list are empty.
- No malware, obfuscation, IoC, secret, or tool-poisoning finding is tied to the cited paths.
False Positive Considerations
- Generic fetch detections in
assets/chunk-3cfb730f.js:1:0andassets/chunk-ea756fd5.js:3:0. - Socket.IO detections in bundled code at
assets/chunk-77e9fb52.js:38:0and:40:0. - The network endpoint list is empty, so the scanner supplies no suspicious destination domain.
- No malware or obfuscation finding is associated with the cited JavaScript paths.
Reviewed 2026-09-30; recommended action: suppress false positive; model confidence 88%.
Chrome version history
Risk trend by version
10 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.
Pick any point on the chart to explore that version's code below.
Source Code Not Available
Source code is not available for this version of the extension.
About This Extension
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace
Canned replies, canned responses, canned messages for any website
[email protected]
Edge Translate - Browser Translator | PDF Translation | MV3 | Open Source
[email protected]
Intelbras Cloud
[email protected]
SlingPlayer for DISH Anywhere
Unknown Developer
My Jobscore
[email protected]
种草星球-TikTok爆单神器,商品自动提报采集邀评【永久免费】
[email protected]