Công cụ đặt hàng Trung Quốc Nhaphangchina.vn
From the RiskyPlugins AI security review of the observed evidence.
Analysis record
- Analysed
- 2 weeks ago
- Version
- v2.8.13.10
- Artifact
- SHA256 629…955
- Source
- Findings (non-IoC)
Evidence ledger
Ranked by severity · findings with a source location link to the code viewer
YARA Rule Matches
12 rules| Severity | Rule | Hits | Files | Metadata |
|---|---|---|---|---|
| LOW | NoUseEval | 1 | content.js | - |
| LOW | postinstall file download | 2 | content.jsbackground.js | - |
| LOW | SQLInjection | 2 | content.jsjs/jquery.js | - |
| LOW | NoUseWeakRandom | 1 | js/jquery.js | - |
| LOW | LocalStorageShouldNotBeUsed | 1 | content.js | - |
| LOW | DebuggerStatementsShouldNotBeUsed | 1 | content.js | - |
| LOW | postinstall crypto operations | 3 | content.jsjs/jquery.js_metadata/verified_contents.json | - |
| LOW | postinstall file manipulation | 2 | content.jsjs/jquery.js | - |
| LOW | AlertStatementsShouldNotBeUsed | 1 | content.js | - |
| LOW | postinstall obfuscation | 2 | content.jsjs/jquery.js | - |
| LOW | postinstall network communication | 3 | content.jsjs/jquery.jsbackground.js | - |
| LOW | postinstall system command | 2 | content.jsjs/jquery.js | - |
Network Indicators
Concrete URLs, domains, IPs, emails, and hashes extracted from the analyzed artifact.
Network indicators are queued for lazy loading
Scroll this section into view to load the detailed rows.
Publisher Evidence
Limited evidencePublisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.
Chrome does not expose the same publisher verification data as IDE stores, so this score is deliberately conservative.
13 evidence rows available.
Finding Categories
YARA Rules Matched
12 rules(21 hits)Requested Permissions
14 permissionsAI Security Report
AI Security Review
Evidence context: threat category pup; evidence quality moderate.
This Vietnamese-language extension ("Công cụ đặt hàng Trung Quốc Nhaphangchina.vn") is designed to help users order from Chinese e-commerce platforms like Taobao. The extension has 10,000 users and version 2.8.13.08.
What the code does: The extension makes network calls in background.js:5, background.js:6, and multiple locations in content.js (lines 292, 1903, 4327, 5097, 1843) using fetch and XMLHttpRequest APIs. These are standard patterns for browser extensions that need to interact with web pages. The IoC findings show the extension communicates with https://muahang.nhaphangchina.vn/extension/ (its own service domain) and various Taobao subdomains (item.lp.taobao.com, item.beta.taobao.com, auction.taobao.com) — all legitimate e-commerce sites the tool is designed to work with.
Key concern: The domain c.top appears in the IoC findings. This is a short, generic domain without clear attribution to the extension's developer. Short TLDs like .top are frequently used by ad networks, tracking services, and affiliate programs. For a shopping assistant extension, this domain could be used for affiliate tracking, ad injection, or data collection beyond the extension's stated purpose.
Positive signals: Zero malware signatures were detected, and there are no obfuscation findings. The code-smell findings (21 total) are classified as low severity and typically match benign patterns like basic API usage. The extension's functionality aligns with its description — it interacts with Taobao domains as expected for a shopping tool.
Developer transparency: The developer is listed as [email protected], a generic Gmail account rather than a verified company or organization. While not definitive proof of malicious intent, anonymous developers combined with questionable domain usage warrant scrutiny.
Counterargument: A skeptic might argue this is a false positive because the extension serves a legitimate purpose (helping Vietnamese users shop on Taobao), has no malware signatures, and the c.top domain could be a legitimate CDN or service provider. However, the combination of an anonymous developer, a suspicious short domain with no clear attribution, and the high volume of IoC findings (205 total) creates enough concern to classify this as a potential PUP. The extension functions as advertised but may engage in tracking or affiliate activities that users should be aware of.
Recommendation: Users should understand this extension may collect data beyond its core shopping assistance functionality. The c.top domain usage should be investigated further to determine its purpose.
Key Reasons
- Suspicious short domain c.top with no clear attribution to developer
- Anonymous developer using generic Gmail account ([email protected])
- No malware signatures or obfuscation detected
- Legitimate functionality for Taobao shopping assistance
- 205 IoC findings driven by e-commerce domain interactions
False Positive Considerations
- Taobao domain interactions are legitimate for shopping assistant
- Code-smell findings are low severity and match benign patterns
- Network calls in background.js and content.js are standard extension behavior
Reviewed 2026-05-23; recommended action: monitor; model confidence 75%.
Chrome version history
Risk trend by version
3 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.
Pick any point on the chart to explore that version's code below.
Source Code Not Available
Source code is not available for this version of the extension.
About This Extension
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace
Edge Translate - Browser Translator | PDF Translation | MV3 | Open Source
[email protected]
Intelbras Cloud
[email protected]
SlingPlayer for DISH Anywhere
Unknown Developer
My Jobscore
[email protected]
种草星球-TikTok爆单神器,商品自动提报采集邀评【永久免费】
[email protected]
Kindredly - A safer, private web for families
[email protected]