Chrome Web Store

たぬきのかくちょう

by [email protected] · 21 users
000108c9-2a42-56a7-ad00-7176f41cc524 | v1.0.5
50/ 100
MEDIUM risk
Analyst verdict
Review before use

The AI review rates the findings as likely false positive, but the risk score (50/100) still counts them.

Analysis record

Analysed
7 months ago
Version
v1.0.5
Artifact
SHA256 18F…296
Source
Findings (non-IoC)

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

22 detail rows

YARA Rule Matches

9 rules
SeverityRuleHitsFilesMetadata
HIGHpostinstall crypto operations

Cryptographic operations detected

3
js/jquery-ui.js_metadata/verified_contents.jsonjs/jquery.js
Risky Plugins Authors FP 30%
HIGHNoUseWeakRandom

When software generates predictable values in a context requiring unpredictability, it may be possible for an attacker to guess the next value that will be generated, and use this guess to impersonate another user or access sensitive information. As the Math.random() function relies on a weak pseudorandom number generator, this function should not be used for security-critical applications or for protecting sensitive data. In such context, a cryptographically strong pseudorandom number generator (CSPRNG) should be used instead. For more information checkout the CWE-338 (https://cwe.mitre.org/data/definitions/338.html) advisory.

1
js/jquery.js
FP 5%
HIGHpostinstall network communication

Network communication detected

2
js/jquery-ui.jsjs/jquery.js
Risky Plugins Authors FP 30%
HIGHpostinstall file manipulation

File system manipulation detected

4
js/jquery-ui.jsjs/content.jscss/jquery-ui.css +1 more
Risky Plugins Authors FP 20%
HIGHpostinstall system command

System command execution detected

2
js/jquery-ui.jsjs/jquery.js
Risky Plugins Authors FP 10%
HIGHpostinstall file download

File download activity detected

1
js/jquery-ui.js
Risky Plugins Authors FP 30%
HIGHpostinstall obfuscation

Code obfuscation techniques detected

3
js/jquery-ui.jscss/jquery-ui.cssjs/jquery.js
Risky Plugins Authors FP 20%
HIGHLocalStorageShouldNotBeUsed

Session storage and local storage are HTML 5 features which allow developers to easily store megabytes of data client-side, as opposed to the 4Kb cookies can accommodate. While useful to speed applications up on the client side, it can be dangerous to store sensitive information this way because the data is not encrypted by default and any script on the page may access it. This rule raises an issue when the localStorage and sessionStorage API's are used. For more information checkout the OWSAP A3:2017 (https://owasp.org/www-project-top-ten/2017/A3_2017-Sensitive_Data_Exposure.html) advisory.

1
js/content.js
FP 5%
HIGHSQLInjection

SQL queries often need to use a hardcoded SQL string with a dynamic parameter coming from a user request. Formatting a string to add those parameters to the request is a bad practice as it can result in an SQL injection. The safe way to add parameters to a SQL query is to use SQL binding mechanisms. For more information checkout the CWE-564 (https://cwe.mitre.org/data/definitions/564.html) and OWASP A1:2017 (https://owasp.org/www-project-top-ten/2017/A1_2017-Injection.html) advisory.

2
js/jquery-ui.jsjs/jquery.js
FP 10%

Publisher Evidence

Limited evidence

[email protected]

Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.

Chrome does not expose the same publisher verification data as IDE stores, so this score is deliberately conservative.

24
Noisy-finding weight
x1.00
Publisher domain
No domain
Missing
Store verification signal
Limited signal
Limited
Extension portfolio
1
Portfolio

13 evidence rows available.

Finding Categories

19
Malware Signatures
3
Network

YARA Rules Matched

9 rules(19 hits)
postinstall crypto operations NoUseWeakRandom postinstall network communication postinstall file manipulation postinstall system command postinstall file download postinstall obfuscation LocalStorageShouldNotBeUsed SQLInjection

Requested Permissions

1 permission
storage
Low

AI Security Report

AI Security Review

Evidence context: threat category none; evidence quality moderate.

This extension, "たぬきのかくちょう" (Tanuki's Memo), shows 22 total findings but none indicate actual malicious behavior. The 19 high-severity findings in the malware-signature category are all code-smell rules that fire on standard library code, not malware signatures. Specifically, YARA--postinstall_obfuscation, YARA--postinstall_file_manipulation, YARA--postinstall_network_communication, YARA--postinstall_system_command, and YARA--postinstall_crypto_operations all match in /tmp/extract-18fb4480d85df9acb209ec4ece5bd2516aaa904cde85d15d4611ba3038f63296-1555076887/js/jquery.js and css/jquery-ui.css. Per CVEQ's known false-positive patterns, postinstall_* rules match basic Node.js patterns (fetch, exec, fs, crypto, process.env) and are classified as code-smell/low severity noise, not malware.

The 3 network findings (NET-JQUERY_AJAX-js/jquery-ui.js-3080, NET-JQUERY_AJAX-js/jquery-ui.js-15883, NET-JQUERY_AJAX-js/jquery-ui.js-15887) are legitimate jQuery AJAX calls in the bundled jQuery UI library, not suspicious network activity to unknown domains. The findings_summary confirms 0 actual malware-signature findings and 19 code-smell findings, despite the display showing high severity.

The extension targets a Japanese community site (Zantan Tanuki) with only 23 users and an anonymous developer ([email protected]). While the developer is not verified and the user count is low, the code itself contains no evidence of credential theft, browser hijacking, proxyware, or data exfiltration. The extension description states it improves readability and usability for the site, which is consistent with the presence of jQuery libraries for DOM manipulation.

Counterargument: A skeptic might argue the anonymous developer and low user count warrant concern, especially with 19 high-severity findings. However, the severity labels are misleading—these are code-smell findings on bundled jQuery code, not actual malware. The findings_summary explicitly shows "malware-signature":"0" and "code-smell":"19", confirming the nature of these detections. Without actual malware signatures, suspicious IoCs, obfuscation in non-locale files, or behavioral evidence of harm, the extension does not meet the threshold for confirmed_malicious or confirmed_risk. The findings are entirely explained by known false-positive patterns in CVEQ's detection system.

Key Reasons

  • All malware-signature findings are postinstall_* code-smell rules matching bundled jQuery library code
  • Network findings are legitimate jQuery AJAX calls, not suspicious domains
  • findings_summary shows 0 actual malware-signature findings, 19 code-smell findings
  • No obfuscation, IoCs, or behavioral evidence of malicious activity
  • Extension purpose (readability enhancement) matches jQuery library presence

False Positive Considerations

  • postinstall_* YARA rules matching Node.js patterns in bundled jQuery
  • Code-smell rules (SQLInjection, NoUseWeakRandom) on standard library code
  • Bundled dependency files triggering multiplicative false positives
  • Severity inflation on code-smell findings

Reviewed 2026-04-30; recommended action: suppress false positive; model confidence 85%.

About This Extension

文字サイズが手軽に変更可能になる等、レスの可読性が向上します。

Frequently Asked Questions