Is "42FM" on Firefox Add-ons Safe to Install?

loczek · firefox · v0.2.0

42FM allows you to listen to music on Twitch with synchronization between users that use this extension. Available commands: - "!fm <youtube link here>"

Risk Assessment

Analyzed
80.48
out of 100
HIGH

258 security findings detected across all analyzers

Firefox extension requesting 4 permissions

Severity Breakdown

0
Critical
22
High
236
Medium
0
Low
0
Info

Finding Categories

22
Malware Signatures
228
IoC Indicators

YARA Rules Matched

11 rules(22 hits)
postinstall obfuscation postinstall file manipulation postinstall network communication postinstall file download postinstall system command UntrustedContentShouldNotBeIncluded ServerHostnameNotVerified LocalStorageShouldNotBeUsed SQLInjection postinstall crypto operations NoUseWeakRandom

Requested Permissions

4 permissions
scripting
Low
*://twitch.tv/*
Low
*://www.twitch.tv/*
Low
*://*.twitch.tv/*
Low

About This Extension

42FM allows you to listen to music on Twitch with synchronization between users that use this extension. Available commands: - "!fm <youtube link here>"

Detailed Findings

22 total

YARA Rule Matches

11 rules

Indicators of Compromise

Network indicators, suspicious strings, and potential IoCs extracted during analysis

URLs
21
IP Addresses
4
Domains
198
Strings
228

All Indicators · 228

Domain
detected Domain: t.open

XIOC detected Domain: t.open

extracted_from_files

Domain
detected Domain: this.options.target

XIOC detected Domain: this.options.target

extracted_from_files

URL
detected URL: https://react.dev/errors/

XIOC detected URL: https://react.dev/errors/

extracted_from_files

URL
detected URL: http://www.w3.org/2000/svg

XIOC detected URL: http://www.w3.org/2000/svg

extracted_from_files

URL
detected URL: http://www.w3.org/1998/Math/MathML

XIOC detected URL: http://www.w3.org/1998/Math/MathML

extracted_from_files

URL
detected URL: http://www.w3.org/1999/xlink

XIOC detected URL: http://www.w3.org/1999/xlink

extracted_from_files

URL
detected URL: https://ezgif.com/resize

XIOC detected URL: https://ezgif.com/resize

extracted_from_files

URL
detected URL: http://www.w3.org/1999/02/22-rdf-syntax-ns#

XIOC detected URL: http://www.w3.org/1999/02/22-rdf-syntax-ns#

extracted_from_files

URL
detected URL: http://ns.adobe.com/xap/1.0/

XIOC detected URL: http://ns.adobe.com/xap/1.0/

extracted_from_files

URL
detected URL: http://ns.adobe.com/xap/1.0/mm/

XIOC detected URL: http://ns.adobe.com/xap/1.0/mm/

extracted_from_files

URL
detected URL: http://ns.adobe.com/xap/1.0/sType/ResourceRef#

XIOC detected URL: http://ns.adobe.com/xap/1.0/sType/ResourceRef#

extracted_from_files

URL
detected URL: https://www.twitch.tv

XIOC detected URL: https://www.twitch.tv

extracted_from_files

URL
detected URL: http://fb.me/use-check-prop-types

XIOC detected URL: http://fb.me/use-check-prop-types

extracted_from_files

Domain
detected Domain: r.top

XIOC detected Domain: r.top

extracted_from_files

Domain
detected Domain: this.g.id

XIOC detected Domain: this.g.id

extracted_from_files

Domain
detected Domain: n.search

XIOC detected Domain: n.search

extracted_from_files

Domain
detected Domain: r.search

XIOC detected Domain: r.search

extracted_from_files

Domain
detected Domain: t.channel

XIOC detected Domain: t.channel

extracted_from_files

URL
detected URL: http://addons.mozilla.org/ca/crl.pem0N

XIOC detected URL: http://addons.mozilla.org/ca/crl.pem0N

extracted_from_files

Domain
detected Domain: tw.r.l.call

XIOC detected Domain: tw.r.l.call

extracted_from_files

Domain
detected Domain: t.g.map

XIOC detected Domain: t.g.map

extracted_from_files

Domain
detected Domain: tp.yt

XIOC detected Domain: tp.yt

extracted_from_files

Domain
detected Domain: www.youtube.com

XIOC detected Domain: www.youtube.com

extracted_from_files

Domain
detected Domain: window.top

XIOC detected Domain: window.top

extracted_from_files

Domain
detected Domain: window.location.host

XIOC detected Domain: window.location.host

extracted_from_files

Domain
detected Domain: e.search

XIOC detected Domain: e.search

extracted_from_files

Domain
detected Domain: array.prototype.foreach.call

XIOC detected Domain: array.prototype.foreach.call

extracted_from_files

Domain
detected Domain: this.h.next

XIOC detected Domain: this.h.next

extracted_from_files

Domain
detected Domain: this.g.next

XIOC detected Domain: this.g.next

extracted_from_files

Domain
detected Domain: t.g.call

XIOC detected Domain: t.g.call

extracted_from_files

Domain
detected Domain: error.call

XIOC detected Domain: error.call

extracted_from_files

Domain
detected Domain: j.call

XIOC detected Domain: j.call

extracted_from_files

Domain
detected Domain: array.prototype.splice.call

XIOC detected Domain: array.prototype.splice.call

extracted_from_files

Domain
detected Domain: f.next

XIOC detected Domain: f.next

extracted_from_files

Domain
detected Domain: developers.google.com

XIOC detected Domain: developers.google.com

extracted_from_files

Domain
detected Domain: t.g.j.next

XIOC detected Domain: t.g.j.next

extracted_from_files

Domain
detected Domain: previous.next

XIOC detected Domain: previous.next

extracted_from_files

Domain
detected Domain: t.entry.previous.next

XIOC detected Domain: t.entry.previous.next

extracted_from_files

Domain
detected Domain: t.entry.next

XIOC detected Domain: t.entry.next

extracted_from_files

Domain
detected Domain: array.prototype.indexof.call

XIOC detected Domain: array.prototype.indexof.call

extracted_from_files

Domain
detected Domain: api.42fm.app

XIOC detected Domain: api.42fm.app

extracted_from_files

Domain
detected Domain: aa.off

XIOC detected Domain: aa.off

extracted_from_files

Domain
detected Domain: e.room

XIOC detected Domain: e.room

extracted_from_files

Domain
detected Domain: e.current.yt

XIOC detected Domain: e.current.yt

extracted_from_files

Domain
detected Domain: c.yt

XIOC detected Domain: c.yt

extracted_from_files

Domain
detected Domain: twitch.tv

XIOC detected Domain: twitch.tv

extracted_from_files

Domain
detected Domain: window.yt

XIOC detected Domain: window.yt

extracted_from_files

Domain
detected Domain: this.io.open

XIOC detected Domain: this.io.open

extracted_from_files

Domain
detected Domain: e.data.pid

XIOC detected Domain: e.data.pid

extracted_from_files

Domain
detected Domain: e.data.data

XIOC detected Domain: e.data.data

extracted_from_files

Domain
detected Domain: this.ms

XIOC detected Domain: this.ms

extracted_from_files

Domain
detected Domain: e.open

XIOC detected Domain: e.open

extracted_from_files

Domain
detected Domain: r.host

XIOC detected Domain: r.host

extracted_from_files

Domain
detected Domain: r.id

XIOC detected Domain: r.id

extracted_from_files

Domain
detected Domain: engine.io

XIOC detected Domain: engine.io

extracted_from_files

Domain
detected Domain: e.target

XIOC detected Domain: e.target

extracted_from_files

Domain
detected Domain: this.transport.name

XIOC detected Domain: this.transport.name

extracted_from_files

Domain
detected Domain: an.call

XIOC detected Domain: an.call

extracted_from_files

Domain
detected Domain: e.off

XIOC detected Domain: e.off

extracted_from_files

Domain
detected Domain: this.io

XIOC detected Domain: this.io

extracted_from_files

Domain
detected Domain: this.open

XIOC detected Domain: this.open

extracted_from_files

Domain
detected Domain: this.ws

XIOC detected Domain: this.ws

extracted_from_files

Domain
detected Domain: c.read

XIOC detected Domain: c.read

extracted_from_files

Domain
detected Domain: p.data

XIOC detected Domain: p.data

extracted_from_files

Domain
detected Domain: u.host

XIOC detected Domain: u.host

extracted_from_files

Domain
detected Domain: t.secure

XIOC detected Domain: t.secure

extracted_from_files

Domain
detected Domain: this.secure

XIOC detected Domain: this.secure

extracted_from_files

Domain
detected Domain: e.prototype.name

XIOC detected Domain: e.prototype.name

extracted_from_files

Domain
detected Domain: i.map

XIOC detected Domain: i.map

extracted_from_files

Domain
detected Domain: iy.open

XIOC detected Domain: iy.open

extracted_from_files

Domain
detected Domain: iy.ping

XIOC detected Domain: iy.ping

extracted_from_files

Domain
detected Domain: this.off

XIOC detected Domain: this.off

extracted_from_files

Domain
detected Domain: id.prototype.off

XIOC detected Domain: id.prototype.off

extracted_from_files

Domain
detected Domain: this.opts.secure

XIOC detected Domain: this.opts.secure

extracted_from_files

Domain
detected Domain: n.data

XIOC detected Domain: n.data

extracted_from_files

Domain
detected Domain: n.open

XIOC detected Domain: n.open

extracted_from_files

Domain
detected Domain: s.map

XIOC detected Domain: s.map

extracted_from_files

Domain
detected Domain: tw.select

XIOC detected Domain: tw.select

extracted_from_files

Domain
detected Domain: window.open

XIOC detected Domain: window.open

extracted_from_files

Domain
detected Domain: tw.hr

XIOC detected Domain: tw.hr

extracted_from_files

Domain
detected Domain: e.yt

XIOC detected Domain: e.yt

extracted_from_files

Domain
detected Domain: a.map

XIOC detected Domain: a.map

extracted_from_files

Domain
detected Domain: hasownproperty.call

XIOC detected Domain: hasownproperty.call

extracted_from_files

Domain
detected Domain: e.map

XIOC detected Domain: e.map

extracted_from_files

Domain
detected Domain: r.call

XIOC detected Domain: r.call

extracted_from_files

Domain
detected Domain: f.map

XIOC detected Domain: f.map

extracted_from_files

Domain
detected Domain: i.off

XIOC detected Domain: i.off

extracted_from_files

Domain
detected Domain: o.off

XIOC detected Domain: o.off

extracted_from_files

Domain
detected Domain: t.brands.map

XIOC detected Domain: t.brands.map

extracted_from_files

Domain
detected Domain: g.top-b.top

XIOC detected Domain: g.top-b.top

extracted_from_files

Domain
detected Domain: h.top

XIOC detected Domain: h.top

extracted_from_files

Domain
detected Domain: i.top

XIOC detected Domain: i.top

extracted_from_files

Domain
detected Domain: t.top

XIOC detected Domain: t.top

extracted_from_files

Domain
detected Domain: n.top

XIOC detected Domain: n.top

extracted_from_files

Domain
detected Domain: a.top

XIOC detected Domain: a.top

extracted_from_files

Domain
detected Domain: r.target

XIOC detected Domain: r.target

extracted_from_files

Domain
detected Domain: o.style

XIOC detected Domain: o.style

extracted_from_files

Domain
detected Domain: y.as

XIOC detected Domain: y.as

extracted_from_files

Domain
detected Domain: a.as

XIOC detected Domain: a.as

extracted_from_files

Domain
detected Domain: e.host

XIOC detected Domain: e.host

extracted_from_files

Domain
detected Domain: t.host

XIOC detected Domain: t.host

extracted_from_files

Domain
detected Domain: n.host

XIOC detected Domain: n.host

extracted_from_files

Domain
detected Domain: r.open

XIOC detected Domain: r.open

extracted_from_files

Domain
detected Domain: e.options.target

XIOC detected Domain: e.options.target

extracted_from_files

Hash
detected MD5 Hash: E6EEB53C840711E89A388844EE40A2E7

XIOC detected MD5 Hash: E6EEB53C840711E89A388844EE40A2E7

extracted_from_files

URL
detected URL: https://youtube.com/watch?v=

XIOC detected URL: https://youtube.com/watch?v=

extracted_from_files

Hash
detected MD5 Hash: E6EEB53D840711E89A388844EE40A2E7

XIOC detected MD5 Hash: E6EEB53D840711E89A388844EE40A2E7

extracted_from_files

Domain
detected Domain: t.props.map

XIOC detected Domain: t.props.map

extracted_from_files

Domain
detected Domain: this.name

XIOC detected Domain: this.name

extracted_from_files

Domain
detected Domain: this.id

XIOC detected Domain: this.id

extracted_from_files

Domain
detected Domain: x.call

XIOC detected Domain: x.call

extracted_from_files

Domain
detected Domain: o.nc

XIOC detected Domain: o.nc

extracted_from_files

Domain
detected Domain: array.prototype.slice.call

XIOC detected Domain: array.prototype.slice.call

extracted_from_files

Domain
detected Domain: o.map

XIOC detected Domain: o.map

extracted_from_files

URL
detected URL: https://socket.io/docs/v3/migrating-from-2-x-to-3-0/)

XIOC detected URL: https://socket.io/docs/v3/migrating-from-2-x-to-3-0/)

extracted_from_files

Domain
detected Domain: e.constructor.name

XIOC detected Domain: e.constructor.name

extracted_from_files

Domain
detected Domain: object.name

XIOC detected Domain: object.name

extracted_from_files

Domain
detected Domain: t.media

XIOC detected Domain: t.media

extracted_from_files

Domain
detected Domain: e.id-t.id

XIOC detected Domain: e.id-t.id

extracted_from_files

Domain
detected Domain: performance.now

XIOC detected Domain: performance.now

extracted_from_files

Domain
detected Domain: l.now

XIOC detected Domain: l.now

extracted_from_files

Domain
detected Domain: s.now

XIOC detected Domain: s.now

extracted_from_files

Domain
detected Domain: g.call

XIOC detected Domain: g.call

extracted_from_files

Domain
detected Domain: t.call

XIOC detected Domain: t.call

extracted_from_files

Domain
detected Domain: o.target

XIOC detected Domain: o.target

extracted_from_files

Domain
detected Domain: r.data

XIOC detected Domain: r.data

extracted_from_files

Domain
detected Domain: t.as

XIOC detected Domain: t.as

extracted_from_files

Domain
detected Domain: n.media

XIOC detected Domain: n.media

extracted_from_files

Domain
detected Domain: u6.call

XIOC detected Domain: u6.call

extracted_from_files

Domain
detected Domain: this.next

XIOC detected Domain: this.next

extracted_from_files

Domain
detected Domain: e.info

XIOC detected Domain: e.info

extracted_from_files

Domain
detected Domain: r.is

XIOC detected Domain: r.is

extracted_from_files

Domain
detected Domain: e.events

XIOC detected Domain: e.events

extracted_from_files

Domain
detected Domain: b.top

XIOC detected Domain: b.top

extracted_from_files

Domain
detected Domain: sj.next

XIOC detected Domain: sj.next

extracted_from_files

Domain
detected Domain: e.id

XIOC detected Domain: e.id

extracted_from_files

Domain
detected Domain: w.data

XIOC detected Domain: w.data

extracted_from_files

Domain
detected Domain: b.data

XIOC detected Domain: b.data

extracted_from_files

Domain
detected Domain: t.name

XIOC detected Domain: t.name

extracted_from_files

Domain
detected Domain: s.data

XIOC detected Domain: s.data

extracted_from_files

Domain
detected Domain: n.property

XIOC detected Domain: n.property

extracted_from_files

Domain
detected Domain: i.style

XIOC detected Domain: i.style

extracted_from_files

Domain
detected Domain: u.memoizedprops.style

XIOC detected Domain: u.memoizedprops.style

extracted_from_files

Domain
detected Domain: i.id

XIOC detected Domain: i.id

extracted_from_files

Domain
detected Domain: r.media

XIOC detected Domain: r.media

extracted_from_files

Domain
detected Domain: r.data.map

XIOC detected Domain: r.data.map

extracted_from_files

Domain
detected Domain: t.data

XIOC detected Domain: t.data

extracted_from_files

Domain
detected Domain: u.next

XIOC detected Domain: u.next

extracted_from_files

Domain
detected Domain: r.next

XIOC detected Domain: r.next

extracted_from_files

Domain
detected Domain: o.data

XIOC detected Domain: o.data

extracted_from_files

Domain
detected Domain: r.events

XIOC detected Domain: r.events

extracted_from_files

Domain
detected Domain: n.compare

XIOC detected Domain: n.compare

extracted_from_files

Domain
detected Domain: l.next

XIOC detected Domain: l.next

extracted_from_files

Domain
detected Domain: c.next

XIOC detected Domain: c.next

extracted_from_files

Domain
detected Domain: m.call

XIOC detected Domain: m.call

extracted_from_files

Domain
detected Domain: h.next

XIOC detected Domain: h.next

extracted_from_files

Domain
detected Domain: oj.next

XIOC detected Domain: oj.next

extracted_from_files

Domain
detected Domain: i.events

XIOC detected Domain: i.events

extracted_from_files

Domain
detected Domain: oq.next

XIOC detected Domain: oq.next

extracted_from_files

Domain
detected Domain: e.next

XIOC detected Domain: e.next

extracted_from_files

Domain
detected Domain: rj.next

XIOC detected Domain: rj.next

extracted_from_files

Domain
detected Domain: object.prototype.tostring.call

XIOC detected Domain: object.prototype.tostring.call

extracted_from_files

Domain
detected Domain: a.call

XIOC detected Domain: a.call

extracted_from_files

Domain
detected Domain: t.next

XIOC detected Domain: t.next

extracted_from_files

Domain
detected Domain: i.next

XIOC detected Domain: i.next

extracted_from_files

Domain
detected Domain: n.next

XIOC detected Domain: n.next

extracted_from_files

Domain
detected Domain: object.is

XIOC detected Domain: object.is

extracted_from_files

Domain
detected Domain: t.target

XIOC detected Domain: t.target

extracted_from_files

Domain
detected Domain: o.next

XIOC detected Domain: o.next

extracted_from_files

Domain
detected Domain: a.next

XIOC detected Domain: a.next

extracted_from_files

Domain
detected Domain: t.id

XIOC detected Domain: t.id

extracted_from_files

Domain
detected Domain: r.name

XIOC detected Domain: r.name

extracted_from_files

Domain
detected Domain: s.next

XIOC detected Domain: s.next

extracted_from_files

Domain
detected Domain: e.style

XIOC detected Domain: e.style

extracted_from_files

Domain
detected Domain: errors.md

XIOC detected Domain: errors.md

extracted_from_files

Domain
detected Domain: n.name

XIOC detected Domain: n.name

extracted_from_files

Domain
detected Domain: o.name

XIOC detected Domain: o.name

extracted_from_files

Domain
detected Domain: this.target

XIOC detected Domain: this.target

extracted_from_files

Domain
detected Domain: date.now

XIOC detected Domain: date.now

extracted_from_files

Domain
detected Domain: e.data

XIOC detected Domain: e.data

extracted_from_files

Domain
detected Domain: socket.io

XIOC detected Domain: socket.io

extracted_from_files

Domain
detected Domain: l.name

XIOC detected Domain: l.name

extracted_from_files

Domain
detected Domain: n.call

XIOC detected Domain: n.call

extracted_from_files

Domain
detected Domain: e.call

XIOC detected Domain: e.call

extracted_from_files

Domain
detected Domain: e.name

XIOC detected Domain: e.name

extracted_from_files

Domain
detected Domain: o.call

XIOC detected Domain: o.call

extracted_from_files

Domain
detected Domain: i.call

XIOC detected Domain: i.call

extracted_from_files

Domain
detected Domain: r.tab.id

XIOC detected Domain: r.tab.id

extracted_from_files

Domain
detected Domain: n.id

XIOC detected Domain: n.id

extracted_from_files

Domain
detected Domain: www.twitch.tv

XIOC detected Domain: www.twitch.tv

extracted_from_files

Domain
detected Domain: fb.me

XIOC detected Domain: fb.me

extracted_from_files

Domain
detected Domain: react.dev

XIOC detected Domain: react.dev

extracted_from_files

Domain
detected Domain: github.com

XIOC detected Domain: github.com

extracted_from_files

Domain
detected Domain: youtube.com

XIOC detected Domain: youtube.com

extracted_from_files

Domain
detected Domain: globalthis.chrome

XIOC detected Domain: globalthis.chrome

extracted_from_files

Domain
detected Domain: globalthis.chrome.runtime.id

XIOC detected Domain: globalthis.chrome.runtime.id

extracted_from_files

Domain
detected Domain: globalthis.browser.runtime.id

XIOC detected Domain: globalthis.browser.runtime.id

extracted_from_files

Domain
detected Domain: s.call

XIOC detected Domain: s.call

extracted_from_files

Domain
detected Domain: object.prototype.hasownproperty.call

XIOC detected Domain: object.prototype.hasownproperty.call

extracted_from_files

Domain
detected Domain: r.tab

XIOC detected Domain: r.tab

extracted_from_files

Domain
detected Domain: s.id

XIOC detected Domain: s.id

extracted_from_files

Domain
detected Domain: t9fc376f2a289b1f0bf6ac17133f8bbad.40599b6053ce1e988dae7e63cab9ca07.addons.mozilla.org

XIOC detected Domain: t9fc376f2a289b1f0bf6ac17133f8bbad.40599b6053ce1e988dae7e63cab9ca07.addons.mozilla.org

extracted_from_files

Domain
detected Domain: ԟ.eg

XIOC detected Domain: ԟ.eg

extracted_from_files

Domain
detected Domain: www.w3.org

XIOC detected Domain: www.w3.org

extracted_from_files

Domain
detected Domain: ezgif.com

XIOC detected Domain: ezgif.com

extracted_from_files

Domain
detected Domain: b6on.dj

XIOC detected Domain: b6on.dj

extracted_from_files

Domain
detected Domain: pḉ.ai

XIOC detected Domain: pḉ.ai

extracted_from_files

Domain
detected Domain: ns.adobe.com

XIOC detected Domain: ns.adobe.com

extracted_from_files

IP
detected IP: ::af

XIOC detected IP: ::af

extracted_from_files

IP
detected IP: 1.76.47.26

XIOC detected IP: 1.76.47.26

extracted_from_files

IP
detected IP: ::bef

XIOC detected IP: ::bef

extracted_from_files

Domain
detected Domain: signingca1.addons.mozilla.org

XIOC detected Domain: signingca1.addons.mozilla.org

extracted_from_files

Domain
detected Domain: mozilla.com

XIOC detected Domain: mozilla.com

extracted_from_files

Domain
detected Domain: addons.mozilla.org

XIOC detected Domain: addons.mozilla.org

extracted_from_files

Domain
detected Domain: content-signature.mozilla.org

XIOC detected Domain: content-signature.mozilla.org

extracted_from_files

URL
detected URL: https://github.com/42fm

XIOC detected URL: https://github.com/42fm

extracted_from_files

URL
detected URL: https://github.com/styled-components/styled-components/blob/main/packages/styled-components/src/utils/errors.md#

XIOC detected URL: https://github.com/styled-components/styled-components/blob/main/packages/styled-components/src/utils/errors.md#

extracted_from_files

Hash
detected MD5 Hash: 40599b6053ce1e988dae7e63cab9ca07

XIOC detected MD5 Hash: 40599b6053ce1e988dae7e63cab9ca07

extracted_from_files

URL
detected URL: https://developers.google.com/youtube/iframe_api_reference#Events

XIOC detected URL: https://developers.google.com/youtube/iframe_api_reference#Events

extracted_from_files

URL
detected URL: http://

XIOC detected URL: http://

extracted_from_files

URL
detected URL: https://www.youtube.com

XIOC detected URL: https://www.youtube.com

extracted_from_files

URL
detected URL: https://api.42fm.app

XIOC detected URL: https://api.42fm.app

extracted_from_files

URL
detected URL: https://

XIOC detected URL: https://

extracted_from_files

Hash
detected MD5 Hash: E6EEB53B840711E89A388844EE40A2E7

XIOC detected MD5 Hash: E6EEB53B840711E89A388844EE40A2E7

extracted_from_files

Hash
detected MD5 Hash: E6EEB53A840711E89A388844EE40A2E7

XIOC detected MD5 Hash: E6EEB53A840711E89A388844EE40A2E7

extracted_from_files

Domain
detected Domain: t.map

XIOC detected Domain: t.map

extracted_from_files

Domain
detected Domain: this.gs

XIOC detected Domain: this.gs

extracted_from_files

IP
detected IP: ::

XIOC detected IP: ::

extracted_from_files

Security Analysis Summary

Security Analysis Overview

42FM is a Firefox Add-ons extension published by loczek. Version 0.2.0 has been analyzed by the Risky Plugins security platform, receiving a risk score of 80.48/100 (HIGH risk) based on 258 security findings.

Risk Assessment

This extension presents critical security risk. Severe issues were detected, potentially including malware indicators, exposed secrets, or dangerous behaviors. Installation is strongly discouraged until these issues are addressed.

Findings Breakdown

  • High: 22 finding(s)
  • Medium: 236 finding(s)

What Was Analyzed

The security assessment covers multiple analysis categories:

  • Malware Detection: YARA rule matching against 2,400+ malware signatures
  • Secret Detection: Scanning for exposed API keys, tokens, and credentials
  • Static Analysis: Code-level security analysis for common vulnerability patterns
  • Network Analysis: Detection of suspicious network communications and endpoints
  • Obfuscation Detection: Identification of code obfuscation techniques

Developer Information

42FM is published by loczek on the Firefox Add-ons marketplace. The extension has approximately 125 users.

Recommendation

This extension is not recommended for installation without thorough manual review. Consider alternatives with lower risk scores, or contact the developer to address the identified security concerns.

Frequently Asked Questions