Microsoft Edge Add-ons Verified

Copy Css Selector

00481ee7-d810-5789-b6d2-5709a2a69e78 | v0.5.0.4
36/ 100
LOW risk
Analyst verdict
No high-risk signal observed

Based on the RiskyPlugins AI security review of the observed evidence.

Analysis record

Analysed
6 months ago
Version
v0.5.0.4
Source
Findings (non-IoC)

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

17 detail rows

YARA Rule Matches

4 rules
SeverityRuleHitsFilesMetadata
HIGHpostinstall crypto operations

Cryptographic operations detected

1
_metadata/verified_contents.json
Risky Plugins Authors FP 30%
HIGHpostinstall network communication

Network communication detected

1
js/background.js
Risky Plugins Authors FP 30%
HIGHpostinstall file manipulation

File system manipulation detected

2
js/selector-generator.jsjs/content.js
Risky Plugins Authors FP 20%
HIGHpostinstall system command

System command execution detected

3
js/devtools.jsjs/background.jsjs/content.js
Risky Plugins Authors FP 10%

Publisher Evidence

Low

Alexander Chermyanin

Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.

Edge does not expose the same publisher verification data as IDE stores, so this score is deliberately conservative.

45
Noisy-finding weight
x1.00
Publisher domain
github.com
Trusted match
Store verification signal
Limited signal
Limited
Extension portfolio
1
Portfolio

13 evidence rows available.

Finding Categories

7
Malware Signatures

YARA Rules Matched

4 rules(7 hits)
postinstall crypto operations postinstall network communication postinstall file manipulation postinstall system command

AI Security Report

AI Security Review

Evidence context: threat category none; evidence quality strong.

Extension Overview

The "Copy Css Selector" extension by Alexander Chermyanin is a developer tool that extends browser Developer Tools to display CSS paths for DOM elements. The extension description is clear and matches a legitimate use case for web developers.

Finding Analysis

Every IoC finding in this bundle is a documented false positive from the XIOC extractor. The findings XIOC-DOMAIN-callback.call, XIOC-DOMAIN-array.prototype.map, XIOC-DOMAIN-predicate.call, XIOC-DOMAIN-function.call, XIOC-DOMAIN-event.target, XIOC-DOMAIN-tab.id, and XIOC-DOMAIN-request.target are all JavaScript property access chains being misidentified as network domains. These are standard JavaScript patterns, not actual network indicators. The finding XIOC-IP-0.5.0.4 is a semantic version number (0.5.0.4) misread as an IP address.

The only legitimate URLs extracted are https://github.com/flamencist/SelectorGenerator (the extension's source code repository), https://edge.microsoft.com/extensionwebstorebase/v1/crx (Microsoft Edge extension infrastructure), and https://chrome.google.com/webstore/detail (Chrome Web Store infrastructure). None of these indicate malicious behavior.

Malware Signature Findings

The findings_summary reports 7 malware-signature findings with high severity, but these are not detailed in the findings_by_category. Given the pattern of XIOC false positives throughout this bundle, these are almost certainly YARA code-smell rules (such as postinstall_* or credential_* patterns) that fire on basic JavaScript constructs. Without specific file paths showing actual malware signatures co-located with obfuscation, these high-severity counts should be treated as noise.

Counterargument

A skeptic might argue that 7 high-severity malware-signature findings warrant concern regardless of IoC false positives. However, the findings_by_category shows zero actual malware findings (only malware-signature, which is distinct), and there are no obfuscation findings, no suspicious network destinations, and no credential access patterns. The extension has a named developer (Alexander Chermyanin), a legitimate GitHub repository, and a clear developer tool purpose. The 7 high-severity findings without accompanying file paths or specific malware family names are characteristic of broad YARA code-smell rules, not actual malware detection.

Conclusion

This extension exhibits none of the high-confidence threat indicators: no typosquatting, no browser hijacking, no credential theft patterns, no malware delivery disguise, no proxyware functionality, and no obfuscated payloads. The findings are entirely explainable as XIOC extractor garbage and broad YARA code-smell rules.

Key Reasons

  • All IoC findings are JavaScript property access chains, not real domains
  • Extension has legitimate developer attribution and GitHub repository
  • No actual malware signatures (only malware-signature code-smell)
  • No obfuscation findings despite high finding count
  • Only legitimate infrastructure URLs found (GitHub, Microsoft, Google)

False Positive Considerations

  • XIOC property access chains misread as domains (callback.call, event.target, tab.id, etc.)
  • Semantic version number misread as IP (0.5.0.4)
  • YARA code-smell rules firing on basic JavaScript patterns
  • Bundled npm dependencies triggering multiplicative false positives

Reviewed 2026-04-27; recommended action: suppress false positive; model confidence 88%.

Frequently Asked Questions