Copy Css Selector
Based on the RiskyPlugins AI security review of the observed evidence.
Analysis record
- Analysed
- 6 months ago
- Version
- v0.5.0.4
- Source
- Findings (non-IoC)
Evidence ledger
Ranked by severity · findings with a source location link to the code viewer
YARA Rule Matches
4 rules| Severity | Rule | Hits | Files | Metadata |
|---|---|---|---|---|
| HIGH | postinstall crypto operations Cryptographic operations detected | 1 | _metadata/verified_contents.json | Risky Plugins Authors FP 30% |
| HIGH | postinstall network communication Network communication detected | 1 | js/background.js | Risky Plugins Authors FP 30% |
| HIGH | postinstall file manipulation File system manipulation detected | 2 | js/selector-generator.jsjs/content.js | Risky Plugins Authors FP 20% |
| HIGH | postinstall system command System command execution detected | 3 | js/devtools.jsjs/background.jsjs/content.js | Risky Plugins Authors FP 10% |
Publisher Evidence
LowAlexander Chermyanin
Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.
Edge does not expose the same publisher verification data as IDE stores, so this score is deliberately conservative.
13 evidence rows available.
Finding Categories
YARA Rules Matched
4 rules(7 hits)AI Security Report
AI Security Review
Evidence context: threat category none; evidence quality strong.
Extension Overview
The "Copy Css Selector" extension by Alexander Chermyanin is a developer tool that extends browser Developer Tools to display CSS paths for DOM elements. The extension description is clear and matches a legitimate use case for web developers.
Finding Analysis
Every IoC finding in this bundle is a documented false positive from the XIOC extractor. The findings XIOC-DOMAIN-callback.call, XIOC-DOMAIN-array.prototype.map, XIOC-DOMAIN-predicate.call, XIOC-DOMAIN-function.call, XIOC-DOMAIN-event.target, XIOC-DOMAIN-tab.id, and XIOC-DOMAIN-request.target are all JavaScript property access chains being misidentified as network domains. These are standard JavaScript patterns, not actual network indicators. The finding XIOC-IP-0.5.0.4 is a semantic version number (0.5.0.4) misread as an IP address.
The only legitimate URLs extracted are https://github.com/flamencist/SelectorGenerator (the extension's source code repository), https://edge.microsoft.com/extensionwebstorebase/v1/crx (Microsoft Edge extension infrastructure), and https://chrome.google.com/webstore/detail (Chrome Web Store infrastructure). None of these indicate malicious behavior.
Malware Signature Findings
The findings_summary reports 7 malware-signature findings with high severity, but these are not detailed in the findings_by_category. Given the pattern of XIOC false positives throughout this bundle, these are almost certainly YARA code-smell rules (such as postinstall_* or credential_* patterns) that fire on basic JavaScript constructs. Without specific file paths showing actual malware signatures co-located with obfuscation, these high-severity counts should be treated as noise.
Counterargument
A skeptic might argue that 7 high-severity malware-signature findings warrant concern regardless of IoC false positives. However, the findings_by_category shows zero actual malware findings (only malware-signature, which is distinct), and there are no obfuscation findings, no suspicious network destinations, and no credential access patterns. The extension has a named developer (Alexander Chermyanin), a legitimate GitHub repository, and a clear developer tool purpose. The 7 high-severity findings without accompanying file paths or specific malware family names are characteristic of broad YARA code-smell rules, not actual malware detection.
Conclusion
This extension exhibits none of the high-confidence threat indicators: no typosquatting, no browser hijacking, no credential theft patterns, no malware delivery disguise, no proxyware functionality, and no obfuscated payloads. The findings are entirely explainable as XIOC extractor garbage and broad YARA code-smell rules.
Key Reasons
- All IoC findings are JavaScript property access chains, not real domains
- Extension has legitimate developer attribution and GitHub repository
- No actual malware signatures (only malware-signature code-smell)
- No obfuscation findings despite high finding count
- Only legitimate infrastructure URLs found (GitHub, Microsoft, Google)
False Positive Considerations
- XIOC property access chains misread as domains (callback.call, event.target, tab.id, etc.)
- Semantic version number misread as IP (0.5.0.4)
- YARA code-smell rules firing on basic JavaScript patterns
- Bundled npm dependencies triggering multiplicative false positives
Reviewed 2026-04-27; recommended action: suppress false positive; model confidence 88%.
Source Code Not Available
Source code is not available for this version of the extension.
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace