PC Protect Password Vault Assistant
Score-based assessment (medium risk, 53/100). Last analyst review covers version unknown.
Analysis record
- Analysed
- 6 months ago
- Version
- v1.4.66
- Source
- Findings (non-IoC)
Evidence ledger
Ranked by severity · findings with a source location link to the code viewer
YARA Rule Matches
7 rules| Severity | Rule | Hits | Files | Metadata |
|---|---|---|---|---|
| HIGH | postinstall crypto operations Cryptographic operations detected | 2 | shared/js/jquery-3.5.0.js_metadata/verified_contents.json | Risky Plugins Authors FP 30% |
| HIGH | NoUseWeakRandom When software generates predictable values in a context requiring unpredictability, it may be possible for an attacker to guess the next value that will be generated, and use this guess to impersonate another user or access sensitive information. As the Math.random() function relies on a weak pseudorandom number generator, this function should not be used for security-critical applications or for protecting sensitive data. In such context, a cryptographically strong pseudorandom number generator (CSPRNG) should be used instead. For more information checkout the CWE-338 (https://cwe.mitre.org/data/definitions/338.html) advisory. | 2 | shared/js/jquery-3.5.0.jsshared/js/content-script.js | FP 5% |
| HIGH | postinstall network communication Network communication detected | 3 | shared/js/jquery-3.5.0.jsshared/js/service-worker.jsshared/js/content-script.js | Risky Plugins Authors FP 30% |
| HIGH | postinstall file manipulation File system manipulation detected | 2 | shared/js/jquery-3.5.0.jsshared/js/content-script.js | Risky Plugins Authors FP 20% |
| HIGH | postinstall system command System command execution detected | 1 | shared/js/jquery-3.5.0.js | Risky Plugins Authors FP 10% |
| HIGH | postinstall obfuscation Code obfuscation techniques detected | 2 | shared/js/jquery-3.5.0.jsshared/js/content-script.js | Risky Plugins Authors FP 20% |
| HIGH | SQLInjection SQL queries often need to use a hardcoded SQL string with a dynamic parameter coming from a user request. Formatting a string to add those parameters to the request is a bad practice as it can result in an SQL injection. The safe way to add parameters to a SQL query is to use SQL binding mechanisms. For more information checkout the CWE-564 (https://cwe.mitre.org/data/definitions/564.html) and OWASP A1:2017 (https://owasp.org/www-project-top-ten/2017/A1_2017-Injection.html) advisory. | 1 | shared/js/jquery-3.5.0.js | FP 10% |
Network Indicators
Concrete URLs, domains, IPs, emails, and hashes extracted from the analyzed artifact.
Network indicators are queued for lazy loading
Scroll this section into view to load the detailed rows.
Publisher Evidence
Limited evidencePC Protect
Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.
Edge does not expose the same publisher verification data as IDE stores, so this score is deliberately conservative.
12 evidence rows available.
Finding Categories
YARA Rules Matched
7 rules(13 hits)AI Security Report
AI Security Review
Evidence context: threat category none; evidence quality strong.
This extension appears to be a legitimate password management component associated with the PC Protect antivirus suite. It explicitly claims functionality to access and generate passwords via the 'Password Vault', which requires standard credential API access (permissions often flagged as 'high-risk' by automated scanners).
The triage is based on the complete absence of suspicious findings (zero malware signatures, zero IoCs, and zero code-smell detections). While the user count is reported as zero (often an artifact for offline or pre-installed security tools in enterprise environments), the publisher identity ('PC Protect') is clearly attributed, distinguishing this from anonymous or impersonating malware.
Password managers inherently access sensitive data to function correctly; however, this specific analysis shows no evidence of external data transmission, browser hijacking, or obfuscation commonly seen in credential theft variants. The findings are consistent with a benign utility from a known security vendor.
Key Reasons
- Zero findings across all detection categories (Malware, IoCs, Code-smell).
- Attributed developer 'PC Protect' matches the extension branding.
- Functionality (password generation/retrieval) explains permissions without malicious indicators.
False Positive Considerations
- High-risk permissions (credentials) are inherent functionality for password managers.
- Zero user count likely reflects an offline/internal deployment status rather than malware stealth.
- Publisher is clearly attributed (PC Protect), ruling out typosquatting.
Reviewed 2026-04-13; recommended action: no action; model confidence 90%.
Source Code Not Available
Source code is not available for this version of the extension.
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace