Microsoft Edge Add-ons

Adblock 2024

001ab028-5db6-5780-a40d-6a26678b1ec2 | v7.0

Marketplace listing not found

Our last marketplace check could not find this listing in Microsoft Edge. It may have been removed or delisted. Existing installs may still run, but verify the publisher and package source before installing or updating.

Not found on 3 weeks ago
61/ 100
MEDIUM risk
Analyst verdict
Needs follow up

From the RiskyPlugins AI security review of the observed evidence.

Analysis record

Analysed
6 months ago
Version
v7.0
Source
Findings (non-IoC)

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

586 detail rows
Showing 25 of 198 · highest severity first

YARA Rule Matches

16 rules
SeverityRuleHitsFilesMetadata
HIGHpostinstall network communication

Network communication detected

66
web_accessible_resources/59fb24a2d12455d15bea20980e8a6801.jsLICENSE.txtjs/asset-viewer.js +63 more
Risky Plugins Authors FP 30%
HIGHpostinstall system command

System command execution detected

56
_metadata/verified_contents.jsonjs/scriptlets/element-picker.jslib/codemirror/lib/codemirror.js +53 more
Risky Plugins Authors FP 10%
HIGHNoUseWeakRandom

When software generates predictable values in a context requiring unpredictability, it may be possible for an attacker to guess the next value that will be generated, and use this guess to impersonate another user or access sensitive information. As the Math.random() function relies on a weak pseudorandom number generator, this function should not be used for security-critical applications or for protecting sensitive data. In such context, a cryptographically strong pseudorandom number generator (CSPRNG) should be used instead. For more information checkout the CWE-338 (https://cwe.mitre.org/data/definitions/338.html) advisory.

6
js/vapi-client.jsjs/vapi-background.jsjs/cosmetic-filtering.js +3 more
FP 5%
HIGHpostinstall file manipulation

File system manipulation detected

94
lib/codemirror/addon/scroll/annotatescrollbar.jsjs/vapi.jsweb_accessible_resources/c2c7eb5240aa19439b7ebbf38d6789e5.js +91 more
Risky Plugins Authors FP 20%
HIGHcredential skype data

Skype data path detected

3
assets/ublock/filters.txtassets/thirdparties/easylist-downloads.adblockplus.org/easyprivacy.txtassets/thirdparties/mirror1.malwaredomains.com/files/justdomains
Risky Plugins Authors FP 20%
HIGHpostinstall environment access

Environment variable access detected

2
css/fonts/OFL.txtassets/thirdparties/mirror1.malwaredomains.com/files/justdomains
Risky Plugins Authors FP 40%
HIGHpostinstall persistence mechanism

Persistence mechanism detected

9
js/storage.jsassets/thirdparties/mirror1.malwaredomains.com/files/justdomainscss/fonts/Lato-300.ttf +6 more
Risky Plugins Authors FP 20%
HIGHpostinstall obfuscation

Code obfuscation techniques detected

47
assets/thirdparties/easylist-downloads.adblockplus.org/easylist.txtassets/ublock/resource-abuse.txtassets/ublock/unbreak.txt +44 more
Risky Plugins Authors FP 20%
HIGHcredential env files

Environment configuration file path detected

2
assets/thirdparties/mirror1.malwaredomains.com/files/justdomainsassets/thirdparties/easylist-downloads.adblockplus.org/easylist.txt
Risky Plugins Authors FP 10%
HIGHpostinstall registry modification

Windows registry modification detected

5
assets/thirdparties/mirror1.malwaredomains.com/files/justdomainsassets/thirdparties/easylist-downloads.adblockplus.org/easyprivacy.txtassets/thirdparties/publicsuffix.org/list/effective_tld_names.dat +2 more
Risky Plugins Authors FP 30%
HIGHNoUseEval

The eval function is extremely dangerous. Because if any user input is not handled correctly and passed to it, it will be possible to execute code remotely in the context of your application (RCE - Remote Code Executuion). For more information checkout the CWE-94 (https://cwe.mitre.org/data/definitions/94.html) advisory.

1
assets/ublock/resources.txt
FP 10%
HIGHLocalStorageShouldNotBeUsed

Session storage and local storage are HTML 5 features which allow developers to easily store megabytes of data client-side, as opposed to the 4Kb cookies can accommodate. While useful to speed applications up on the client side, it can be dangerous to store sensitive information this way because the data is not encrypted by default and any script on the page may access it. This rule raises an issue when the localStorage and sessionStorage API's are used. For more information checkout the OWSAP A3:2017 (https://owasp.org/www-project-top-ten/2017/A3_2017-Sensitive_Data_Exposure.html) advisory.

8
assets/ublock/resources.txtjs/popup.jsjs/vapi-background.js +5 more
FP 5%
HIGHcredential steam data

Steam application data path detected

2
assets/thirdparties/mirror1.malwaredomains.com/files/justdomainsassets/thirdparties/easylist-downloads.adblockplus.org/easylist.txt
Risky Plugins Authors FP 20%
HIGHpostinstall file download

File download activity detected

54
js/url-net-filtering.jsjs/rpcreceiver.jsjs/settings.js +51 more
Risky Plugins Authors FP 30%
HIGHpostinstall crypto operations

Cryptographic operations detected

32
web_accessible_resources/to-import.txt_metadata/verified_contents.jsonjs/scriptlet-filtering.js +29 more
Risky Plugins Authors FP 30%
HIGHDebuggerStatementsShouldNotBeUsed

The debugger statement can be placed anywhere in procedures to suspend execution. Using the debugger statement is similar to setting a breakpoint in the code. By definition such statement must absolutely be removed from the source code to prevent any unexpected behavior or added vulnerability to attacks in production. For more information checkout the CWE-489 (https://cwe.mitre.org/data/definitions/489.html) advisory.

1
js/scriptlet-filtering.js
FP 10%

Publisher Evidence

Limited evidence

Adblocking

Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.

Edge does not expose the same publisher verification data as IDE stores, so this score is deliberately conservative.

34
Noisy-finding weight
x1.00
Publisher domain
No domain
Missing
Store verification signal
Limited signal
Limited
Extension portfolio
3
Portfolio

12 evidence rows available.

Finding Categories

388
Malware Signatures
2
Obfuscation
4
Network

YARA Rules Matched

16 rules(388 hits)
postinstall network communication postinstall system command NoUseWeakRandom postinstall file manipulation credential skype data postinstall environment access postinstall persistence mechanism postinstall obfuscation credential env files postinstall registry modification NoUseEval LocalStorageShouldNotBeUsed credential steam data postinstall file download postinstall crypto operations DebuggerStatementsShouldNotBeUsed

AI Security Report

AI Security Review

Evidence context: threat category unknown malware; evidence quality moderate.

The extension "Adblock 2024" by developer "Adblocking" presents conflicting signals that prevent a definitive verdict. The findings_summary reports 388 malware-signature findings at high severity, which is a significant volume that cannot be dismissed. However, the findings_by_category section does not list specific file paths for these malware signatures, only metadata hashes and network findings. This gap in detail prevents determination of whether signatures originate from malicious code or bundled dependencies.

The four network findings are all generic xmlhttprequest detections: js/assets.js:90, js/messaging.js:572, js/cloud-ui.js:191, and js/jquery-3.3.1.js:9460. These represent standard HTTP request patterns and do not reference suspicious domains, custom search engines, or credential-exfiltration endpoints. The jQuery finding is from a bundled library, which is expected behavior.

Two obfuscation findings exist but lack file path details in the provided evidence. The extension has zero users and an unknown version, which are data quality concerns that reduce confidence in any verdict. The developer name "Adblocking" is generic without verification, and the description contains a typo ("suepr" instead of "super"), suggesting low-quality publishing.

The strongest counterargument to this verdict is that 388 high-severity malware signatures should warrant a confirmed_malicious verdict regardless of missing file paths. However, the known false-positive patterns for CVEQ include bundled dependencies triggering multiplicative signatures—50 libraries × 20 signatures each equals 1000 findings. Without file paths showing these signatures are in core extension logic versus bundled libraries, declaring confirmed_malicious would be premature. Runtime analysis or reanalysis with detailed malware signature file paths is required to distinguish between bundled code noise and actual malicious payloads.

Key Reasons

  • 388 malware-signature findings at high severity lack file path details
  • Zero user count and unknown version indicate data quality issues
  • Network findings are generic xmlhttprequest calls without suspicious domains
  • Generic developer name without verification
  • No evidence of credential theft, browser hijacking, or typosquatting

False Positive Considerations

  • Bundled dependencies may trigger multiplicative malware signatures
  • Generic xmlhttprequest network findings are common in legitimate extensions
  • Ad blockers commonly bundle large blocklists that trigger signatures

Reviewed 2026-04-27; recommended action: reanalyze; model confidence 55%.

Frequently Asked Questions