Chrome Web Store

Công cụ đặt hàng Trung Quốc Nhaphangchina.vn

by [email protected] · 10.0K users · 4.8 rating
00014374-7ff2-5d62-a68d-a74863ed19f1 | v2.8.13.10
56/ 100
MEDIUM risk
-1 since v2.8.13.08
Analyst verdict
Confirmed risk

From the RiskyPlugins AI security review of the observed evidence.

Analysis record

Analysed
2 weeks ago
Version
v2.8.13.10
Artifact
SHA256 629…955
Source
Findings (non-IoC)

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

29 detail rows

YARA Rule Matches

12 rules
SeverityRuleHitsFilesMetadata
LOWNoUseEval 1
content.js
-
LOWpostinstall file download 2
content.jsbackground.js
-
LOWSQLInjection 2
content.jsjs/jquery.js
-
LOWNoUseWeakRandom 1
js/jquery.js
-
LOWLocalStorageShouldNotBeUsed 1
content.js
-
LOWDebuggerStatementsShouldNotBeUsed 1
content.js
-
LOWpostinstall crypto operations 3
content.jsjs/jquery.js_metadata/verified_contents.json
-
LOWpostinstall file manipulation 2
content.jsjs/jquery.js
-
LOWAlertStatementsShouldNotBeUsed 1
content.js
-
LOWpostinstall obfuscation 2
content.jsjs/jquery.js
-
LOWpostinstall network communication 3
content.jsjs/jquery.jsbackground.js
-
LOWpostinstall system command 2
content.jsjs/jquery.js
-

Network Indicators

Concrete URLs, domains, IPs, emails, and hashes extracted from the analyzed artifact.

84 total
...

Network indicators are queued for lazy loading

Scroll this section into view to load the detailed rows.

Publisher Evidence

Limited evidence

[email protected]

Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.

Chrome does not expose the same publisher verification data as IDE stores, so this score is deliberately conservative.

30
Noisy-finding weight
x1.00
Publisher domain
No domain
Missing
Store verification signal
Limited signal
Limited
Extension portfolio
1
Portfolio

13 evidence rows available.

Finding Categories

8
Network
84
IoC Indicators

YARA Rules Matched

12 rules(21 hits)
NoUseEval postinstall file download SQLInjection NoUseWeakRandom LocalStorageShouldNotBeUsed DebuggerStatementsShouldNotBeUsed postinstall crypto operations postinstall file manipulation AlertStatementsShouldNotBeUsed postinstall obfuscation postinstall network communication postinstall system command

Requested Permissions

14 permissions
https://*.nhaphangchina.vn/*
Low
http://*.1688.com/*
Low
*://*.google.com/*
Low
https://*.1688.com/*
Low
http://*.taobao.com/*
Low
https://*.taobao.com/*
Low
http://*.tmall.com/*
Low
https://*.tmall.com/*
Low
http://*.tmall.hk/*
Low
https://*.tmall.hk/*
Low
http://*.vip.com/*
Low
https://*.vip.com/*
Low
http://*.vipshop.com/*
Low
https://*.vipshop.com/*
Low

AI Security Report

AI Security Review

Evidence context: threat category pup; evidence quality moderate.

This Vietnamese-language extension ("Công cụ đặt hàng Trung Quốc Nhaphangchina.vn") is designed to help users order from Chinese e-commerce platforms like Taobao. The extension has 10,000 users and version 2.8.13.08.

What the code does: The extension makes network calls in background.js:5, background.js:6, and multiple locations in content.js (lines 292, 1903, 4327, 5097, 1843) using fetch and XMLHttpRequest APIs. These are standard patterns for browser extensions that need to interact with web pages. The IoC findings show the extension communicates with https://muahang.nhaphangchina.vn/extension/ (its own service domain) and various Taobao subdomains (item.lp.taobao.com, item.beta.taobao.com, auction.taobao.com) — all legitimate e-commerce sites the tool is designed to work with.

Key concern: The domain c.top appears in the IoC findings. This is a short, generic domain without clear attribution to the extension's developer. Short TLDs like .top are frequently used by ad networks, tracking services, and affiliate programs. For a shopping assistant extension, this domain could be used for affiliate tracking, ad injection, or data collection beyond the extension's stated purpose.

Positive signals: Zero malware signatures were detected, and there are no obfuscation findings. The code-smell findings (21 total) are classified as low severity and typically match benign patterns like basic API usage. The extension's functionality aligns with its description — it interacts with Taobao domains as expected for a shopping tool.

Developer transparency: The developer is listed as [email protected], a generic Gmail account rather than a verified company or organization. While not definitive proof of malicious intent, anonymous developers combined with questionable domain usage warrant scrutiny.

Counterargument: A skeptic might argue this is a false positive because the extension serves a legitimate purpose (helping Vietnamese users shop on Taobao), has no malware signatures, and the c.top domain could be a legitimate CDN or service provider. However, the combination of an anonymous developer, a suspicious short domain with no clear attribution, and the high volume of IoC findings (205 total) creates enough concern to classify this as a potential PUP. The extension functions as advertised but may engage in tracking or affiliate activities that users should be aware of.

Recommendation: Users should understand this extension may collect data beyond its core shopping assistance functionality. The c.top domain usage should be investigated further to determine its purpose.

Key Reasons

  • Suspicious short domain c.top with no clear attribution to developer
  • Anonymous developer using generic Gmail account ([email protected])
  • No malware signatures or obfuscation detected
  • Legitimate functionality for Taobao shopping assistance
  • 205 IoC findings driven by e-commerce domain interactions

False Positive Considerations

  • Taobao domain interactions are legitimate for shopping assistant
  • Code-smell findings are low severity and match benign patterns
  • Network calls in background.js and content.js are standard extension behavior

Reviewed 2026-05-23; recommended action: monitor; model confidence 75%.

Chrome version history

Risk trend by version

3 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.

Selected
56
Change since first
-1
Change from previous
-1
Versions:
First analyzed version
2.8.13.07
Apr 7, 2026
Risk range
56 to 57
Across analyzed versions
Latest analyzed version
2.8.13.10
Jul 21, 2026
Selected version
medium
Version
v2.8.13.10
2 months ago
Risk score
56
Findings
113
Change vs previous
-1

Pick any point on the chart to explore that version's code below.

About This Extension

Công cụ đặt hàng Nhập Hàng China trên trình duyệt Chrome & Cờ rôm+ Mô tả: Công cụ được tích hợp vào trình duyệt Chrome và Cốc Cốc nhằm giúp đỡ khách hàng sử dụng máy tính dễ dàng tìm kiếm sản phẩm bằng từ khóa Tiếng Việt. Tính năng: Các tính năng chính của Công cụ đặt hàng Trung Quốc như sau - Tính năng tìm kiếm theo từ khóa Tiếng Việt, địa chỉ shop Trung Quốc theo tỉnh thành nhằm tìm kiếm shop gần kho của Nhaphangchina.vn để tối ưu về phí nội địa. - Tìm kiếm từ khóa theo sản phẩm hoặc theo shop - Quy đổi giá sản phẩm từ NDT sang VNĐ - Thêm hàng vào giỏ hàng hệ thống đặt hàng của Nhaphangchina.vn

Frequently Asked Questions