Microsoft Edge Add-ons Verified

店侦探&看店宝-淘宝卖家数据分析工具

001af08c-1d32-5149-8e57-1490603699d2 | v1.0.6.6
53/ 100
MEDIUM risk
Analyst verdict
Review before use

The AI review rates the findings as likely false positive, but the risk score (53/100) still counts them.

Analysis record

Analysed
6 months ago
Version
v1.0.6.6
Source
Findings (non-IoC)

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

106 detail rows
Showing 25 of 32 · highest severity first

YARA Rule Matches

13 rules
SeverityRuleHitsFilesMetadata
HIGHOriginsNotVerified

Browsers allow message exchanges between Window objects of different origins. Because any window can send / receive messages from other window it is important to verify the sender's / receiver's identity: When sending message with postMessage method, the identity's receiver should be defined (the wildcard keyword (*) should not be used).\nWhen receiving message with message event, the sender's identity should be verified using the origin and possibly source properties. For more information checkout the OWASP A2:2017 (https://owasp.org/www-project-top-ten/2017/A2_2017-Broken_Authentication) and (https://developer.mozilla.org/en-US/docs/Web/API/Window/postMessage) advisory.

1
js/contentscript.js
FP 15%
HIGHpostinstall crypto operations

Cryptographic operations detected

7
js/echarts3.min.jsmanifest.jsonjs/contentscript.js +4 more
Risky Plugins Authors FP 30%
HIGHNoUseWeakRandom

When software generates predictable values in a context requiring unpredictability, it may be possible for an attacker to guess the next value that will be generated, and use this guess to impersonate another user or access sensitive information. As the Math.random() function relies on a weak pseudorandom number generator, this function should not be used for security-critical applications or for protecting sensitive data. In such context, a cryptographically strong pseudorandom number generator (CSPRNG) should be used instead. For more information checkout the CWE-338 (https://cwe.mitre.org/data/definitions/338.html) advisory.

7
js/echarts3.min.jsjs/pnotify/PNotifyDesktop.jsjs/jquery-3.3.1.min.js +4 more
FP 5%
HIGHpostinstall file manipulation

File system manipulation detected

17
js/pnotify/PNotifyDesktop.jsjs/echarts3.min.jsjs/popup.js +14 more
Risky Plugins Authors FP 20%
HIGHpostinstall system command

System command execution detected

11
js/buttons.html5.min.jsjs/topscript.jsjs/crypto-js.min.js +8 more
Risky Plugins Authors FP 10%
HIGHpostinstall network communication

Network communication detected

6
js/echarts3.min.jsjs/jquery-3.3.1.min.jsjs/public.js +3 more
Risky Plugins Authors FP 30%
HIGHpostinstall environment access

Environment variable access detected

2
js/contentscript.jsjs/background.js
Risky Plugins Authors FP 40%
HIGHpostinstall persistence mechanism

Persistence mechanism detected

1
js/echarts3.min.js
Risky Plugins Authors FP 20%
HIGHcredential env files

Environment configuration file path detected

1
js/echarts3.min.js
Risky Plugins Authors FP 10%
HIGHpostinstall file download

File download activity detected

3
js/echarts3.min.jscss/style.cssjs/buttons.html5.min.js
Risky Plugins Authors FP 30%
HIGHpostinstall obfuscation

Code obfuscation techniques detected

12
manifest.jsonjs/topscript.jsjs/buttons.html5.min.js +9 more
Risky Plugins Authors FP 20%
HIGHLocalStorageShouldNotBeUsed

Session storage and local storage are HTML 5 features which allow developers to easily store megabytes of data client-side, as opposed to the 4Kb cookies can accommodate. While useful to speed applications up on the client side, it can be dangerous to store sensitive information this way because the data is not encrypted by default and any script on the page may access it. This rule raises an issue when the localStorage and sessionStorage API's are used. For more information checkout the OWSAP A3:2017 (https://owasp.org/www-project-top-ten/2017/A3_2017-Sensitive_Data_Exposure.html) advisory.

3
js/contentscript.jsjs/public.jsjs/background.js
FP 5%
HIGHSQLInjection

SQL queries often need to use a hardcoded SQL string with a dynamic parameter coming from a user request. Formatting a string to add those parameters to the request is a bad practice as it can result in an SQL injection. The safe way to add parameters to a SQL query is to use SQL binding mechanisms. For more information checkout the CWE-564 (https://cwe.mitre.org/data/definitions/564.html) and OWASP A1:2017 (https://owasp.org/www-project-top-ten/2017/A1_2017-Injection.html) advisory.

3
js/jquery-3.3.1.min.jsjs/public.jsjs/popup.js
FP 10%

Publisher Evidence

Limited evidence

珠海淘数科技有限公司

Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.

Edge does not expose the same publisher verification data as IDE stores, so this score is deliberately conservative.

28
Noisy-finding weight
x1.00
Publisher domain
dianzhentan.com
Observed
Store verification signal
Limited signal
Limited
Extension portfolio
1
Portfolio

13 evidence rows available.

Finding Categories

74
Malware Signatures
4
Network

YARA Rules Matched

13 rules(74 hits)
OriginsNotVerified postinstall crypto operations NoUseWeakRandom postinstall file manipulation postinstall system command postinstall network communication postinstall environment access postinstall persistence mechanism credential env files postinstall file download postinstall obfuscation LocalStorageShouldNotBeUsed SQLInjection

AI Security Report

AI Security Review

Evidence context: threat category none; evidence quality moderate.

This extension, named "店侦探&看店宝-淘宝卖家数据分析工具" (Taobao Seller Data Analysis Tool), is published by "珠海淘数科技有限公司" (Zhuhai Taoshu Technology Co., Ltd.), a legitimate Chinese company. The extension's stated purpose aligns with its network behavior: files js/background.js, js/popup.js, and js/topscript.js trigger jQuery AJAX findings, while js/echarts3.min.js triggers a socket_io finding—all consistent with a data visualization and analytics tool fetching information from Taobao.

The 74 malware-signature findings (severity: high) are the primary concern, but these lack specificity in the evidence. The findings_summary shows 74 malware-signature detections but provides no details about which specific signatures were triggered. Crucially, there are 0 obfuscation findings, 0 code-smell findings, and 0 IoC findings. If this were genuinely malicious code, obfuscation would typically be present to evade detection, and suspicious domains would appear in the IoC extractor output.

The metadata findings (28 total) are simply file hashes for legitimate components including manifest.json, js/pnotify/PNotifyButtons.js, and css/bootstrap-modal.css. These are standard library files expected in a data analysis extension.

Counterargument: A skeptic could argue that 74 malware signatures cannot be dismissed as false positives. However, malware signatures fire on code patterns, not proven malicious behavior. Without corroborating evidence—no obfuscation to hide malicious intent, no suspicious domains in the IoC output, no credential theft patterns, no browser hijacking behavior—the signature count alone is insufficient to confirm malicious intent. The extension's network activity matches its documented purpose, and the developer is properly attributed. If the malware signatures are from bundled third-party libraries (common in extensions using ECharts, jQuery, and other npm packages), this would explain the high count without actual malicious behavior.

The "unknown" version field suggests the analysis may be incomplete, further supporting caution in interpreting the malware signature count.

Key Reasons

  • 74 malware-signature findings without specific signature details
  • Legitimate developer attribution (珠海淘数科技有限公司)
  • Network findings consistent with stated analytics functionality
  • Zero obfuscation, code-smell, and IoC findings
  • Bundled libraries likely triggering signature matches

False Positive Considerations

  • Malware signatures without specific signature names or corroborating indicators
  • Bundled third-party libraries (ECharts, jQuery, PNotify, Bootstrap) triggering signature matches
  • No obfuscation or code-smell findings to support malicious intent
  • Zero IoC findings despite network activity

Reviewed 2026-05-03; recommended action: suppress false positive; model confidence 65%.

Frequently Asked Questions