Microsoft Edge Add-ons Verified

EPUB READER

00443724-c8f4-592e-9743-dabeeaba11a0 | v1.0.3
46/ 100
MEDIUM risk
Analyst verdict
Needs follow up

From the RiskyPlugins AI security review of the observed evidence.

Analysis record

Analysed
6 months ago
Version
v1.0.3
Source
Findings (non-IoC)

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

238 detail rows
Showing 25 of 177 · highest severity first

YARA Rule Matches

15 rules
SeverityRuleHitsFilesMetadata
HIGHOriginsNotVerified

Browsers allow message exchanges between Window objects of different origins. Because any window can send / receive messages from other window it is important to verify the sender's / receiver's identity: When sending message with postMessage method, the identity's receiver should be defined (the wildcard keyword (*) should not be used).\nWhen receiving message with message event, the sender's identity should be verified using the origin and possibly source properties. For more information checkout the OWASP A2:2017 (https://owasp.org/www-project-top-ten/2017/A2_2017-Broken_Authentication) and (https://developer.mozilla.org/en-US/docs/Web/API/Window/postMessage) advisory.

2
js/jszip.min.jsdist/reader.js
FP 15%
HIGHUntrustedContentShouldNotBeIncluded

Including content in your site from an untrusted source can expose your users to attackers and even compromise your own site. For that reason, this rule raises an issue for each non-relative URL. For more information checkout the OWASP A1:2017 (https://owasp.org/www-project-top-ten/2017/A1_2017-Injection.html) advisory.

2
js/epub.jsdist/reader.js
FP 20%
HIGHpostinstall crypto operations

Cryptographic operations detected

7
js/jquery.min.js.git/hooks/pre-commit.samplejs/epub.js +4 more
Risky Plugins Authors FP 30%
HIGHpostinstall file manipulation

File system manipulation detected

10
js/epub.jspackage-lock.json.git/hooks/pre-push.sample +7 more
Risky Plugins Authors FP 20%
HIGHpostinstall system command

System command execution detected

14
.git/hooks/pre-receive.samplejs/jquery.min.js.git/hooks/prepare-commit-msg.sample +11 more
Risky Plugins Authors FP 10%
HIGHNoUseWeakRandom

When software generates predictable values in a context requiring unpredictability, it may be possible for an attacker to guess the next value that will be generated, and use this guess to impersonate another user or access sensitive information. As the Math.random() function relies on a weak pseudorandom number generator, this function should not be used for security-critical applications or for protecting sensitive data. In such context, a cryptographically strong pseudorandom number generator (CSPRNG) should be used instead. For more information checkout the CWE-338 (https://cwe.mitre.org/data/definitions/338.html) advisory.

3
js/jquery.min.jsjs/epub.jsdist/reader.js
FP 5%
HIGHpostinstall network communication

Network communication detected

3
js/jquery.min.jsjs/epub.jsdist/reader.js
Risky Plugins Authors FP 30%
HIGHpostinstall persistence mechanism

Persistence mechanism detected

2
dist/reader.jsjs/jszip.min.js
Risky Plugins Authors FP 20%
HIGHpostinstall environment access

Environment variable access detected

1
webpack.config.js
Risky Plugins Authors FP 40%
HIGHcredential env files

Environment configuration file path detected

2
dist/reader.jswebpack.config.js
Risky Plugins Authors FP 10%
HIGHpostinstall file download

File download activity detected

2
.git/configdist/reader.js
Risky Plugins Authors FP 30%
HIGHSQLInjection

SQL queries often need to use a hardcoded SQL string with a dynamic parameter coming from a user request. Formatting a string to add those parameters to the request is a bad practice as it can result in an SQL injection. The safe way to add parameters to a SQL query is to use SQL binding mechanisms. For more information checkout the CWE-564 (https://cwe.mitre.org/data/definitions/564.html) and OWASP A1:2017 (https://owasp.org/www-project-top-ten/2017/A1_2017-Injection.html) advisory.

2
dist/reader.jsjs/jquery.min.js
FP 10%
HIGHpostinstall registry modification

Windows registry modification detected

1
package-lock.json
Risky Plugins Authors FP 30%
HIGHLocalStorageShouldNotBeUsed

Session storage and local storage are HTML 5 features which allow developers to easily store megabytes of data client-side, as opposed to the 4Kb cookies can accommodate. While useful to speed applications up on the client side, it can be dangerous to store sensitive information this way because the data is not encrypted by default and any script on the page may access it. This rule raises an issue when the localStorage and sessionStorage API's are used. For more information checkout the OWSAP A3:2017 (https://owasp.org/www-project-top-ten/2017/A3_2017-Sensitive_Data_Exposure.html) advisory.

1
dist/reader.js
FP 5%
HIGHpostinstall obfuscation

Code obfuscation techniques detected

9
manifest.jsonjs/jszip.min.js.git/hooks/pre-receive.sample +6 more
Risky Plugins Authors FP 20%

Publisher Evidence

Limited evidence

EPUB Reader

Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.

Edge does not expose the same publisher verification data as IDE stores, so this score is deliberately conservative.

28
Noisy-finding weight
x1.00
Publisher domain
neat-reader.com
Observed
Store verification signal
Limited signal
Limited
Extension portfolio
1
Portfolio

13 evidence rows available.

Finding Categories

61
Malware Signatures
1
Network

YARA Rules Matched

15 rules(61 hits)
OriginsNotVerified UntrustedContentShouldNotBeIncluded postinstall crypto operations postinstall file manipulation postinstall system command NoUseWeakRandom postinstall network communication postinstall persistence mechanism postinstall environment access credential env files postinstall file download SQLInjection postinstall registry modification LocalStorageShouldNotBeUsed postinstall obfuscation

AI Security Report

AI Security Review

Evidence context: threat category unknown malware; evidence quality moderate.

The EPUB READER extension presents a mixed security profile requiring further investigation. The extension claims to read EPUB files and contains js/epub.js, a legitimate open-source library for parsing EPUB documents. The single network finding NET-XMLHTTPREQUEST-js/epub.js-3423 in js/epub.js:3423 represents standard XMLHttpRequest usage expected from a document reader library.

However, the findings summary reports 61 high-severity malware-signature detections. This is the critical unknown in this analysis. The evidence bundle does not specify what malware families or signatures were matched. If these signatures are from bundled dependencies (common in extensions with multiple npm packages), they could represent false positives. However, 61 high-severity matches exceeds typical false-positive volumes from legitimate code.

Additional concerning signals include: the version is listed as "unknown" (unusual for a published extension), the user count is 0 (no adoption), and the developer name "EPUB Reader" exactly matches the extension name with no distinct attribution. The .git/ directory findings (e.g., .git/objects/92/f50aecb3dbcd6bb437f714616a9ffd4afbb2a7) are benign metadata hashes from version control artifacts.

The strongest counterargument to a malicious verdict is that epub.js is a well-known legitimate library, the network activity is standard for document readers, and there are zero IoCs or obfuscation findings. However, this counterargument cannot explain 61 high-severity malware signatures. Without visibility into the specific signature titles and what code they matched, I cannot determine if this represents actual malware or false positives from bundled dependencies. The combination of unknown version, zero users, and high malware signature count warrants runtime analysis to examine what the signatures are actually detecting.

Key Reasons

  • 61 high-severity malware signatures detected but specific signature names not provided in evidence
  • Extension version listed as 'unknown' which is atypical for published extensions
  • Zero user count suggests either newly published or abandoned extension
  • No IoCs, obfuscation, or code-smell findings to corroborate or explain malware signatures
  • Legitimate epub.js library present with expected network behavior

False Positive Considerations

  • Bundled dependencies may trigger malware signatures in dist/ or library files
  • Git repository artifacts (.git/ directory) generate metadata hash findings
  • Standard library code may match overly broad malware family signatures

Reviewed 2026-04-28; recommended action: runtime analysis; model confidence 65%.

Frequently Asked Questions