Marketplace listing not found
Our last marketplace check could not find this listing in Microsoft Edge. It may have been removed or delisted. Existing installs may still run, but verify the publisher and package source before installing or updating.
From the RiskyPlugins AI security review of the observed evidence.
Analysis record
- Analysed
- 6 months ago
- Version
- v7.0
- Source
- Findings (non-IoC)
Evidence ledger
Ranked by severity · findings with a source location link to the code viewer
YARA Rule Matches
16 rules| Severity | Rule | Hits | Files | Metadata |
|---|---|---|---|---|
| HIGH | postinstall network communication Network communication detected | 66 | web_accessible_resources/59fb24a2d12455d15bea20980e8a6801.jsLICENSE.txtjs/asset-viewer.js +63 more | Risky Plugins Authors FP 30% |
| HIGH | postinstall system command System command execution detected | 56 | _metadata/verified_contents.jsonjs/scriptlets/element-picker.jslib/codemirror/lib/codemirror.js +53 more | Risky Plugins Authors FP 10% |
| HIGH | NoUseWeakRandom When software generates predictable values in a context requiring unpredictability, it may be possible for an attacker to guess the next value that will be generated, and use this guess to impersonate another user or access sensitive information. As the Math.random() function relies on a weak pseudorandom number generator, this function should not be used for security-critical applications or for protecting sensitive data. In such context, a cryptographically strong pseudorandom number generator (CSPRNG) should be used instead. For more information checkout the CWE-338 (https://cwe.mitre.org/data/definitions/338.html) advisory. | 6 | js/vapi-client.jsjs/vapi-background.jsjs/cosmetic-filtering.js +3 more | FP 5% |
| HIGH | postinstall file manipulation File system manipulation detected | 94 | lib/codemirror/addon/scroll/annotatescrollbar.jsjs/vapi.jsweb_accessible_resources/c2c7eb5240aa19439b7ebbf38d6789e5.js +91 more | Risky Plugins Authors FP 20% |
| HIGH | credential skype data Skype data path detected | 3 | assets/ublock/filters.txtassets/thirdparties/easylist-downloads.adblockplus.org/easyprivacy.txtassets/thirdparties/mirror1.malwaredomains.com/files/justdomains | Risky Plugins Authors FP 20% |
| HIGH | postinstall environment access Environment variable access detected | 2 | css/fonts/OFL.txtassets/thirdparties/mirror1.malwaredomains.com/files/justdomains | Risky Plugins Authors FP 40% |
| HIGH | postinstall persistence mechanism Persistence mechanism detected | 9 | js/storage.jsassets/thirdparties/mirror1.malwaredomains.com/files/justdomainscss/fonts/Lato-300.ttf +6 more | Risky Plugins Authors FP 20% |
| HIGH | postinstall obfuscation Code obfuscation techniques detected | 47 | assets/thirdparties/easylist-downloads.adblockplus.org/easylist.txtassets/ublock/resource-abuse.txtassets/ublock/unbreak.txt +44 more | Risky Plugins Authors FP 20% |
| HIGH | credential env files Environment configuration file path detected | 2 | assets/thirdparties/mirror1.malwaredomains.com/files/justdomainsassets/thirdparties/easylist-downloads.adblockplus.org/easylist.txt | Risky Plugins Authors FP 10% |
| HIGH | postinstall registry modification Windows registry modification detected | 5 | assets/thirdparties/mirror1.malwaredomains.com/files/justdomainsassets/thirdparties/easylist-downloads.adblockplus.org/easyprivacy.txtassets/thirdparties/publicsuffix.org/list/effective_tld_names.dat +2 more | Risky Plugins Authors FP 30% |
| HIGH | NoUseEval The eval function is extremely dangerous. Because if any user input is not handled correctly and passed to it, it will be possible to execute code remotely in the context of your application (RCE - Remote Code Executuion). For more information checkout the CWE-94 (https://cwe.mitre.org/data/definitions/94.html) advisory. | 1 | assets/ublock/resources.txt | FP 10% |
| HIGH | LocalStorageShouldNotBeUsed Session storage and local storage are HTML 5 features which allow developers to easily store megabytes of data client-side, as opposed to the 4Kb cookies can accommodate. While useful to speed applications up on the client side, it can be dangerous to store sensitive information this way because the data is not encrypted by default and any script on the page may access it. This rule raises an issue when the localStorage and sessionStorage API's are used. For more information checkout the OWSAP A3:2017 (https://owasp.org/www-project-top-ten/2017/A3_2017-Sensitive_Data_Exposure.html) advisory. | 8 | assets/ublock/resources.txtjs/popup.jsjs/vapi-background.js +5 more | FP 5% |
| HIGH | credential steam data Steam application data path detected | 2 | assets/thirdparties/mirror1.malwaredomains.com/files/justdomainsassets/thirdparties/easylist-downloads.adblockplus.org/easylist.txt | Risky Plugins Authors FP 20% |
| HIGH | postinstall file download File download activity detected | 54 | js/url-net-filtering.jsjs/rpcreceiver.jsjs/settings.js +51 more | Risky Plugins Authors FP 30% |
| HIGH | postinstall crypto operations Cryptographic operations detected | 32 | web_accessible_resources/to-import.txt_metadata/verified_contents.jsonjs/scriptlet-filtering.js +29 more | Risky Plugins Authors FP 30% |
| HIGH | DebuggerStatementsShouldNotBeUsed The debugger statement can be placed anywhere in procedures to suspend execution. Using the debugger statement is similar to setting a breakpoint in the code. By definition such statement must absolutely be removed from the source code to prevent any unexpected behavior or added vulnerability to attacks in production. For more information checkout the CWE-489 (https://cwe.mitre.org/data/definitions/489.html) advisory. | 1 | js/scriptlet-filtering.js | FP 10% |
Publisher Evidence
Limited evidenceAdblocking
Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.
Edge does not expose the same publisher verification data as IDE stores, so this score is deliberately conservative.
12 evidence rows available.
Finding Categories
YARA Rules Matched
16 rules(388 hits)AI Security Report
AI Security Review
Evidence context: threat category unknown malware; evidence quality moderate.
The extension "Adblock 2024" by developer "Adblocking" presents conflicting signals that prevent a definitive verdict. The findings_summary reports 388 malware-signature findings at high severity, which is a significant volume that cannot be dismissed. However, the findings_by_category section does not list specific file paths for these malware signatures, only metadata hashes and network findings. This gap in detail prevents determination of whether signatures originate from malicious code or bundled dependencies.
The four network findings are all generic xmlhttprequest detections: js/assets.js:90, js/messaging.js:572, js/cloud-ui.js:191, and js/jquery-3.3.1.js:9460. These represent standard HTTP request patterns and do not reference suspicious domains, custom search engines, or credential-exfiltration endpoints. The jQuery finding is from a bundled library, which is expected behavior.
Two obfuscation findings exist but lack file path details in the provided evidence. The extension has zero users and an unknown version, which are data quality concerns that reduce confidence in any verdict. The developer name "Adblocking" is generic without verification, and the description contains a typo ("suepr" instead of "super"), suggesting low-quality publishing.
The strongest counterargument to this verdict is that 388 high-severity malware signatures should warrant a confirmed_malicious verdict regardless of missing file paths. However, the known false-positive patterns for CVEQ include bundled dependencies triggering multiplicative signatures—50 libraries × 20 signatures each equals 1000 findings. Without file paths showing these signatures are in core extension logic versus bundled libraries, declaring confirmed_malicious would be premature. Runtime analysis or reanalysis with detailed malware signature file paths is required to distinguish between bundled code noise and actual malicious payloads.
Key Reasons
- 388 malware-signature findings at high severity lack file path details
- Zero user count and unknown version indicate data quality issues
- Network findings are generic xmlhttprequest calls without suspicious domains
- Generic developer name without verification
- No evidence of credential theft, browser hijacking, or typosquatting
False Positive Considerations
- Bundled dependencies may trigger multiplicative malware signatures
- Generic xmlhttprequest network findings are common in legitimate extensions
- Ad blockers commonly bundle large blocklists that trigger signatures
Reviewed 2026-04-27; recommended action: reanalyze; model confidence 55%.
Source Code Not Available
Source code is not available for this version of the extension.
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace