たぬきのかくちょう
The AI review rates the findings as likely false positive, but the risk score (50/100) still counts them.
Analysis record
- Analysed
- 7 months ago
- Version
- v1.0.5
- Artifact
- SHA256 18F…296
- Source
- Findings (non-IoC)
Evidence ledger
Ranked by severity · findings with a source location link to the code viewer
YARA Rule Matches
9 rules| Severity | Rule | Hits | Files | Metadata |
|---|---|---|---|---|
| HIGH | postinstall crypto operations Cryptographic operations detected | 3 | js/jquery-ui.js_metadata/verified_contents.jsonjs/jquery.js | Risky Plugins Authors FP 30% |
| HIGH | NoUseWeakRandom When software generates predictable values in a context requiring unpredictability, it may be possible for an attacker to guess the next value that will be generated, and use this guess to impersonate another user or access sensitive information. As the Math.random() function relies on a weak pseudorandom number generator, this function should not be used for security-critical applications or for protecting sensitive data. In such context, a cryptographically strong pseudorandom number generator (CSPRNG) should be used instead. For more information checkout the CWE-338 (https://cwe.mitre.org/data/definitions/338.html) advisory. | 1 | js/jquery.js | FP 5% |
| HIGH | postinstall network communication Network communication detected | 2 | js/jquery-ui.jsjs/jquery.js | Risky Plugins Authors FP 30% |
| HIGH | postinstall file manipulation File system manipulation detected | 4 | js/jquery-ui.jsjs/content.jscss/jquery-ui.css +1 more | Risky Plugins Authors FP 20% |
| HIGH | postinstall system command System command execution detected | 2 | js/jquery-ui.jsjs/jquery.js | Risky Plugins Authors FP 10% |
| HIGH | postinstall file download File download activity detected | 1 | js/jquery-ui.js | Risky Plugins Authors FP 30% |
| HIGH | postinstall obfuscation Code obfuscation techniques detected | 3 | js/jquery-ui.jscss/jquery-ui.cssjs/jquery.js | Risky Plugins Authors FP 20% |
| HIGH | LocalStorageShouldNotBeUsed Session storage and local storage are HTML 5 features which allow developers to easily store megabytes of data client-side, as opposed to the 4Kb cookies can accommodate. While useful to speed applications up on the client side, it can be dangerous to store sensitive information this way because the data is not encrypted by default and any script on the page may access it. This rule raises an issue when the localStorage and sessionStorage API's are used. For more information checkout the OWSAP A3:2017 (https://owasp.org/www-project-top-ten/2017/A3_2017-Sensitive_Data_Exposure.html) advisory. | 1 | js/content.js | FP 5% |
| HIGH | SQLInjection SQL queries often need to use a hardcoded SQL string with a dynamic parameter coming from a user request. Formatting a string to add those parameters to the request is a bad practice as it can result in an SQL injection. The safe way to add parameters to a SQL query is to use SQL binding mechanisms. For more information checkout the CWE-564 (https://cwe.mitre.org/data/definitions/564.html) and OWASP A1:2017 (https://owasp.org/www-project-top-ten/2017/A1_2017-Injection.html) advisory. | 2 | js/jquery-ui.jsjs/jquery.js | FP 10% |
Publisher Evidence
Limited evidencePublisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.
Chrome does not expose the same publisher verification data as IDE stores, so this score is deliberately conservative.
13 evidence rows available.
Finding Categories
YARA Rules Matched
9 rules(19 hits)Requested Permissions
1 permissionAI Security Report
AI Security Review
Evidence context: threat category none; evidence quality moderate.
This extension, "たぬきのかくちょう" (Tanuki's Memo), shows 22 total findings but none indicate actual malicious behavior. The 19 high-severity findings in the malware-signature category are all code-smell rules that fire on standard library code, not malware signatures. Specifically, YARA--postinstall_obfuscation, YARA--postinstall_file_manipulation, YARA--postinstall_network_communication, YARA--postinstall_system_command, and YARA--postinstall_crypto_operations all match in /tmp/extract-18fb4480d85df9acb209ec4ece5bd2516aaa904cde85d15d4611ba3038f63296-1555076887/js/jquery.js and css/jquery-ui.css. Per CVEQ's known false-positive patterns, postinstall_* rules match basic Node.js patterns (fetch, exec, fs, crypto, process.env) and are classified as code-smell/low severity noise, not malware.
The 3 network findings (NET-JQUERY_AJAX-js/jquery-ui.js-3080, NET-JQUERY_AJAX-js/jquery-ui.js-15883, NET-JQUERY_AJAX-js/jquery-ui.js-15887) are legitimate jQuery AJAX calls in the bundled jQuery UI library, not suspicious network activity to unknown domains. The findings_summary confirms 0 actual malware-signature findings and 19 code-smell findings, despite the display showing high severity.
The extension targets a Japanese community site (Zantan Tanuki) with only 23 users and an anonymous developer ([email protected]). While the developer is not verified and the user count is low, the code itself contains no evidence of credential theft, browser hijacking, proxyware, or data exfiltration. The extension description states it improves readability and usability for the site, which is consistent with the presence of jQuery libraries for DOM manipulation.
Counterargument: A skeptic might argue the anonymous developer and low user count warrant concern, especially with 19 high-severity findings. However, the severity labels are misleading—these are code-smell findings on bundled jQuery code, not actual malware. The findings_summary explicitly shows "malware-signature":"0" and "code-smell":"19", confirming the nature of these detections. Without actual malware signatures, suspicious IoCs, obfuscation in non-locale files, or behavioral evidence of harm, the extension does not meet the threshold for confirmed_malicious or confirmed_risk. The findings are entirely explained by known false-positive patterns in CVEQ's detection system.
Key Reasons
- All malware-signature findings are postinstall_* code-smell rules matching bundled jQuery library code
- Network findings are legitimate jQuery AJAX calls, not suspicious domains
- findings_summary shows 0 actual malware-signature findings, 19 code-smell findings
- No obfuscation, IoCs, or behavioral evidence of malicious activity
- Extension purpose (readability enhancement) matches jQuery library presence
False Positive Considerations
- postinstall_* YARA rules matching Node.js patterns in bundled jQuery
- Code-smell rules (SQLInjection, NoUseWeakRandom) on standard library code
- Bundled dependency files triggering multiplicative false positives
- Severity inflation on code-smell findings
Reviewed 2026-04-30; recommended action: suppress false positive; model confidence 85%.
Source Code Not Available
Source code is not available for this version of the extension.
About This Extension
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace
Edge Translate - Browser Translator | PDF Translation | MV3 | Open Source
[email protected]
Intelbras Cloud
[email protected]
SlingPlayer for DISH Anywhere
Unknown Developer
My Jobscore
[email protected]
种草星球-TikTok爆单神器,商品自动提报采集邀评【永久免费】
[email protected]
Kindredly - A safer, private web for families
[email protected]