EPUB READER
From the RiskyPlugins AI security review of the observed evidence.
Analysis record
- Analysed
- 6 months ago
- Version
- v1.0.3
- Source
- Findings (non-IoC)
Evidence ledger
Ranked by severity · findings with a source location link to the code viewer
YARA Rule Matches
15 rules| Severity | Rule | Hits | Files | Metadata |
|---|---|---|---|---|
| HIGH | OriginsNotVerified Browsers allow message exchanges between Window objects of different origins. Because any window can send / receive messages from other window it is important to verify the sender's / receiver's identity: When sending message with postMessage method, the identity's receiver should be defined (the wildcard keyword (*) should not be used).\nWhen receiving message with message event, the sender's identity should be verified using the origin and possibly source properties. For more information checkout the OWASP A2:2017 (https://owasp.org/www-project-top-ten/2017/A2_2017-Broken_Authentication) and (https://developer.mozilla.org/en-US/docs/Web/API/Window/postMessage) advisory. | 2 | js/jszip.min.jsdist/reader.js | FP 15% |
| HIGH | UntrustedContentShouldNotBeIncluded Including content in your site from an untrusted source can expose your users to attackers and even compromise your own site. For that reason, this rule raises an issue for each non-relative URL. For more information checkout the OWASP A1:2017 (https://owasp.org/www-project-top-ten/2017/A1_2017-Injection.html) advisory. | 2 | js/epub.jsdist/reader.js | FP 20% |
| HIGH | postinstall crypto operations Cryptographic operations detected | 7 | js/jquery.min.js.git/hooks/pre-commit.samplejs/epub.js +4 more | Risky Plugins Authors FP 30% |
| HIGH | postinstall file manipulation File system manipulation detected | 10 | js/epub.jspackage-lock.json.git/hooks/pre-push.sample +7 more | Risky Plugins Authors FP 20% |
| HIGH | postinstall system command System command execution detected | 14 | .git/hooks/pre-receive.samplejs/jquery.min.js.git/hooks/prepare-commit-msg.sample +11 more | Risky Plugins Authors FP 10% |
| HIGH | NoUseWeakRandom When software generates predictable values in a context requiring unpredictability, it may be possible for an attacker to guess the next value that will be generated, and use this guess to impersonate another user or access sensitive information. As the Math.random() function relies on a weak pseudorandom number generator, this function should not be used for security-critical applications or for protecting sensitive data. In such context, a cryptographically strong pseudorandom number generator (CSPRNG) should be used instead. For more information checkout the CWE-338 (https://cwe.mitre.org/data/definitions/338.html) advisory. | 3 | js/jquery.min.jsjs/epub.jsdist/reader.js | FP 5% |
| HIGH | postinstall network communication Network communication detected | 3 | js/jquery.min.jsjs/epub.jsdist/reader.js | Risky Plugins Authors FP 30% |
| HIGH | postinstall persistence mechanism Persistence mechanism detected | 2 | dist/reader.jsjs/jszip.min.js | Risky Plugins Authors FP 20% |
| HIGH | postinstall environment access Environment variable access detected | 1 | webpack.config.js | Risky Plugins Authors FP 40% |
| HIGH | credential env files Environment configuration file path detected | 2 | dist/reader.jswebpack.config.js | Risky Plugins Authors FP 10% |
| HIGH | postinstall file download File download activity detected | 2 | .git/configdist/reader.js | Risky Plugins Authors FP 30% |
| HIGH | SQLInjection SQL queries often need to use a hardcoded SQL string with a dynamic parameter coming from a user request. Formatting a string to add those parameters to the request is a bad practice as it can result in an SQL injection. The safe way to add parameters to a SQL query is to use SQL binding mechanisms. For more information checkout the CWE-564 (https://cwe.mitre.org/data/definitions/564.html) and OWASP A1:2017 (https://owasp.org/www-project-top-ten/2017/A1_2017-Injection.html) advisory. | 2 | dist/reader.jsjs/jquery.min.js | FP 10% |
| HIGH | postinstall registry modification Windows registry modification detected | 1 | package-lock.json | Risky Plugins Authors FP 30% |
| HIGH | LocalStorageShouldNotBeUsed Session storage and local storage are HTML 5 features which allow developers to easily store megabytes of data client-side, as opposed to the 4Kb cookies can accommodate. While useful to speed applications up on the client side, it can be dangerous to store sensitive information this way because the data is not encrypted by default and any script on the page may access it. This rule raises an issue when the localStorage and sessionStorage API's are used. For more information checkout the OWSAP A3:2017 (https://owasp.org/www-project-top-ten/2017/A3_2017-Sensitive_Data_Exposure.html) advisory. | 1 | dist/reader.js | FP 5% |
| HIGH | postinstall obfuscation Code obfuscation techniques detected | 9 | manifest.jsonjs/jszip.min.js.git/hooks/pre-receive.sample +6 more | Risky Plugins Authors FP 20% |
Publisher Evidence
Limited evidenceEPUB Reader
Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.
Edge does not expose the same publisher verification data as IDE stores, so this score is deliberately conservative.
13 evidence rows available.
Finding Categories
YARA Rules Matched
15 rules(61 hits)AI Security Report
AI Security Review
Evidence context: threat category unknown malware; evidence quality moderate.
The EPUB READER extension presents a mixed security profile requiring further investigation. The extension claims to read EPUB files and contains js/epub.js, a legitimate open-source library for parsing EPUB documents. The single network finding NET-XMLHTTPREQUEST-js/epub.js-3423 in js/epub.js:3423 represents standard XMLHttpRequest usage expected from a document reader library.
However, the findings summary reports 61 high-severity malware-signature detections. This is the critical unknown in this analysis. The evidence bundle does not specify what malware families or signatures were matched. If these signatures are from bundled dependencies (common in extensions with multiple npm packages), they could represent false positives. However, 61 high-severity matches exceeds typical false-positive volumes from legitimate code.
Additional concerning signals include: the version is listed as "unknown" (unusual for a published extension), the user count is 0 (no adoption), and the developer name "EPUB Reader" exactly matches the extension name with no distinct attribution. The .git/ directory findings (e.g., .git/objects/92/f50aecb3dbcd6bb437f714616a9ffd4afbb2a7) are benign metadata hashes from version control artifacts.
The strongest counterargument to a malicious verdict is that epub.js is a well-known legitimate library, the network activity is standard for document readers, and there are zero IoCs or obfuscation findings. However, this counterargument cannot explain 61 high-severity malware signatures. Without visibility into the specific signature titles and what code they matched, I cannot determine if this represents actual malware or false positives from bundled dependencies. The combination of unknown version, zero users, and high malware signature count warrants runtime analysis to examine what the signatures are actually detecting.
Key Reasons
- 61 high-severity malware signatures detected but specific signature names not provided in evidence
- Extension version listed as 'unknown' which is atypical for published extensions
- Zero user count suggests either newly published or abandoned extension
- No IoCs, obfuscation, or code-smell findings to corroborate or explain malware signatures
- Legitimate epub.js library present with expected network behavior
False Positive Considerations
- Bundled dependencies may trigger malware signatures in dist/ or library files
- Git repository artifacts (.git/ directory) generate metadata hash findings
- Standard library code may match overly broad malware family signatures
Reviewed 2026-04-28; recommended action: runtime analysis; model confidence 65%.
Source Code Not Available
Source code is not available for this version of the extension.
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace