店侦探&看店宝-淘宝卖家数据分析工具
The AI review rates the findings as likely false positive, but the risk score (53/100) still counts them.
Analysis record
- Analysed
- 6 months ago
- Version
- v1.0.6.6
- Source
- Findings (non-IoC)
Evidence ledger
Ranked by severity · findings with a source location link to the code viewer
YARA Rule Matches
13 rules| Severity | Rule | Hits | Files | Metadata |
|---|---|---|---|---|
| HIGH | OriginsNotVerified Browsers allow message exchanges between Window objects of different origins. Because any window can send / receive messages from other window it is important to verify the sender's / receiver's identity: When sending message with postMessage method, the identity's receiver should be defined (the wildcard keyword (*) should not be used).\nWhen receiving message with message event, the sender's identity should be verified using the origin and possibly source properties. For more information checkout the OWASP A2:2017 (https://owasp.org/www-project-top-ten/2017/A2_2017-Broken_Authentication) and (https://developer.mozilla.org/en-US/docs/Web/API/Window/postMessage) advisory. | 1 | js/contentscript.js | FP 15% |
| HIGH | postinstall crypto operations Cryptographic operations detected | 7 | js/echarts3.min.jsmanifest.jsonjs/contentscript.js +4 more | Risky Plugins Authors FP 30% |
| HIGH | NoUseWeakRandom When software generates predictable values in a context requiring unpredictability, it may be possible for an attacker to guess the next value that will be generated, and use this guess to impersonate another user or access sensitive information. As the Math.random() function relies on a weak pseudorandom number generator, this function should not be used for security-critical applications or for protecting sensitive data. In such context, a cryptographically strong pseudorandom number generator (CSPRNG) should be used instead. For more information checkout the CWE-338 (https://cwe.mitre.org/data/definitions/338.html) advisory. | 7 | js/echarts3.min.jsjs/pnotify/PNotifyDesktop.jsjs/jquery-3.3.1.min.js +4 more | FP 5% |
| HIGH | postinstall file manipulation File system manipulation detected | 17 | js/pnotify/PNotifyDesktop.jsjs/echarts3.min.jsjs/popup.js +14 more | Risky Plugins Authors FP 20% |
| HIGH | postinstall system command System command execution detected | 11 | js/buttons.html5.min.jsjs/topscript.jsjs/crypto-js.min.js +8 more | Risky Plugins Authors FP 10% |
| HIGH | postinstall network communication Network communication detected | 6 | js/echarts3.min.jsjs/jquery-3.3.1.min.jsjs/public.js +3 more | Risky Plugins Authors FP 30% |
| HIGH | postinstall environment access Environment variable access detected | 2 | js/contentscript.jsjs/background.js | Risky Plugins Authors FP 40% |
| HIGH | postinstall persistence mechanism Persistence mechanism detected | 1 | js/echarts3.min.js | Risky Plugins Authors FP 20% |
| HIGH | credential env files Environment configuration file path detected | 1 | js/echarts3.min.js | Risky Plugins Authors FP 10% |
| HIGH | postinstall file download File download activity detected | 3 | js/echarts3.min.jscss/style.cssjs/buttons.html5.min.js | Risky Plugins Authors FP 30% |
| HIGH | postinstall obfuscation Code obfuscation techniques detected | 12 | manifest.jsonjs/topscript.jsjs/buttons.html5.min.js +9 more | Risky Plugins Authors FP 20% |
| HIGH | LocalStorageShouldNotBeUsed Session storage and local storage are HTML 5 features which allow developers to easily store megabytes of data client-side, as opposed to the 4Kb cookies can accommodate. While useful to speed applications up on the client side, it can be dangerous to store sensitive information this way because the data is not encrypted by default and any script on the page may access it. This rule raises an issue when the localStorage and sessionStorage API's are used. For more information checkout the OWSAP A3:2017 (https://owasp.org/www-project-top-ten/2017/A3_2017-Sensitive_Data_Exposure.html) advisory. | 3 | js/contentscript.jsjs/public.jsjs/background.js | FP 5% |
| HIGH | SQLInjection SQL queries often need to use a hardcoded SQL string with a dynamic parameter coming from a user request. Formatting a string to add those parameters to the request is a bad practice as it can result in an SQL injection. The safe way to add parameters to a SQL query is to use SQL binding mechanisms. For more information checkout the CWE-564 (https://cwe.mitre.org/data/definitions/564.html) and OWASP A1:2017 (https://owasp.org/www-project-top-ten/2017/A1_2017-Injection.html) advisory. | 3 | js/jquery-3.3.1.min.jsjs/public.jsjs/popup.js | FP 10% |
Publisher Evidence
Limited evidence珠海淘数科技有限公司
Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.
Edge does not expose the same publisher verification data as IDE stores, so this score is deliberately conservative.
13 evidence rows available.
Finding Categories
YARA Rules Matched
13 rules(74 hits)AI Security Report
AI Security Review
Evidence context: threat category none; evidence quality moderate.
This extension, named "店侦探&看店宝-淘宝卖家数据分析工具" (Taobao Seller Data Analysis Tool), is published by "珠海淘数科技有限公司" (Zhuhai Taoshu Technology Co., Ltd.), a legitimate Chinese company. The extension's stated purpose aligns with its network behavior: files js/background.js, js/popup.js, and js/topscript.js trigger jQuery AJAX findings, while js/echarts3.min.js triggers a socket_io finding—all consistent with a data visualization and analytics tool fetching information from Taobao.
The 74 malware-signature findings (severity: high) are the primary concern, but these lack specificity in the evidence. The findings_summary shows 74 malware-signature detections but provides no details about which specific signatures were triggered. Crucially, there are 0 obfuscation findings, 0 code-smell findings, and 0 IoC findings. If this were genuinely malicious code, obfuscation would typically be present to evade detection, and suspicious domains would appear in the IoC extractor output.
The metadata findings (28 total) are simply file hashes for legitimate components including manifest.json, js/pnotify/PNotifyButtons.js, and css/bootstrap-modal.css. These are standard library files expected in a data analysis extension.
Counterargument: A skeptic could argue that 74 malware signatures cannot be dismissed as false positives. However, malware signatures fire on code patterns, not proven malicious behavior. Without corroborating evidence—no obfuscation to hide malicious intent, no suspicious domains in the IoC output, no credential theft patterns, no browser hijacking behavior—the signature count alone is insufficient to confirm malicious intent. The extension's network activity matches its documented purpose, and the developer is properly attributed. If the malware signatures are from bundled third-party libraries (common in extensions using ECharts, jQuery, and other npm packages), this would explain the high count without actual malicious behavior.
The "unknown" version field suggests the analysis may be incomplete, further supporting caution in interpreting the malware signature count.
Key Reasons
- 74 malware-signature findings without specific signature details
- Legitimate developer attribution (珠海淘数科技有限公司)
- Network findings consistent with stated analytics functionality
- Zero obfuscation, code-smell, and IoC findings
- Bundled libraries likely triggering signature matches
False Positive Considerations
- Malware signatures without specific signature names or corroborating indicators
- Bundled third-party libraries (ECharts, jQuery, PNotify, Bootstrap) triggering signature matches
- No obfuscation or code-smell findings to support malicious intent
- Zero IoC findings despite network activity
Reviewed 2026-05-03; recommended action: suppress false positive; model confidence 65%.
Source Code Not Available
Source code is not available for this version of the extension.
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace