Is "teleCOG" on Chrome Web Store Safe to Install?

[email protected] · chrome · v1.1.0

teleCOG ––– Access your COGSmachine from afar teleCOG gives you the ability to access key transaction information and perform send and receive actions from your COGSmachine node via a Chrome Extension. Home — see balance, recent transactions at a glance Read your balance and explore transaction history with filtering options. Filter by peer, by action (send, receive, or all), if the transaction has a message, and by date window/range. Have control to delete old or unwanted messages from your node. Balance Chart – see balance, cold balance, number of total transactions, and balance trends Click on the balance in the Home view to open the balance chart. See trends (delta and percent changes) within specified timeframes, cold balance, and the total number of transactions. Receive – see your COGSmachine node identifiers, access faucet and fortify services Display node identifiers to share with others. Receive tokens by utilizing the faucet and fortify services. Send — transfer tokens Send tokens to any peer on the network with the ability to include an optional message. Further protect this action by requiring a PIN beforehand. Preferences / Settings — connect teleCOG to your node Securely connect your teleCOG extension to your COGSmachine node / access the teleCOG API. Numeric or alphanumeric PIN to protect access to the teleCOG extension and encrypt teleCOG configuration. Optionally set Require PIN on Send to make the user enter the PIN whenever sending tokens. Side panel and optional pop-out window Access teleCOG in the Chrome side panel or in a pop-out window for a larger or custom view. teleCOG is for COGSmachine users and operators who: Already run or use a node and want a browser-native control surface. Want balance and transaction history visibility without leaving the browser. For questions about COGSmachine itself (node setup), contact COGSmachine via Twitter/X (https://x.com/COGSmachine). For extension-specific issues, contact the developer via Twitter/X (https://x.com/_mattmew) or email ([email protected]). teleCOG handles sensitive information by design. Read the privacy policy (https://1382.okcomputers.eth.limo/) for additional details.

Risk Assessment

Analyzed
62.95
out of 100
MEDIUM

149 security findings detected across all analyzers

Chrome extension requesting 4 permissions

Severity Breakdown

0
Critical
0
High
135
Medium
14
Low
0
Info

Finding Categories

5
Network
128
IoC Indicators

YARA Rules Matched

7 rules(14 hits)
postinstall network communication postinstall crypto operations postinstall file download postinstall file manipulation postinstall system command postinstall obfuscation NoUseWeakRandom

Requested Permissions

4 permissions
sidePanel
Low
storage
Low
windows
Low
https://cogsmachine.net/*
Low

About This Extension

teleCOG ––– Access your COGSmachine from afar teleCOG gives you the ability to access key transaction information and perform send and receive actions from your COGSmachine node via a Chrome Extension. Home — see balance, recent transactions at a glance Read your balance and explore transaction history with filtering options. Filter by peer, by action (send, receive, or all), if the transaction has a message, and by date window/range. Have control to delete old or unwanted messages from your node. Balance Chart – see balance, cold balance, number of total transactions, and balance trends Click on the balance in the Home view to open the balance chart. See trends (delta and percent changes) within specified timeframes, cold balance, and the total number of transactions. Receive – see your COGSmachine node identifiers, access faucet and fortify services Display node identifiers to share with others. Receive tokens by utilizing the faucet and fortify services. Send — transfer tokens Send tokens to any peer on the network with the ability to include an optional message. Further protect this action by requiring a PIN beforehand. Preferences / Settings — connect teleCOG to your node Securely connect your teleCOG extension to your COGSmachine node / access the teleCOG API. Numeric or alphanumeric PIN to protect access to the teleCOG extension and encrypt teleCOG configuration. Optionally set Require PIN on Send to make the user enter the PIN whenever sending tokens. Side panel and optional pop-out window Access teleCOG in the Chrome side panel or in a pop-out window for a larger or custom view. teleCOG is for COGSmachine users and operators who: Already run or use a node and want a browser-native control surface. Want balance and transaction history visibility without leaving the browser. For questions about COGSmachine itself (node setup), contact COGSmachine via Twitter/X (https://x.com/COGSmachine). For extension-specific issues, contact the developer via Twitter/X (https://x.com/_mattmew) or email ([email protected]). teleCOG handles sensitive information by design. Read the privacy policy (https://1382.okcomputers.eth.limo/) for additional details.

Detailed Findings

19 total

YARA Rule Matches

7 rules

Indicators of Compromise

Network indicators, suspicious strings, and potential IoCs extracted during analysis

URLs
7
IP Addresses
1
Domains
120
Strings
128

All Indicators · 128

Domain
detected Domain: s.map

XIOC detected Domain: s.map

extracted_from_files

Domain
detected Domain: object.prototype.tostring.call

XIOC detected Domain: object.prototype.tostring.call

extracted_from_files

Domain
detected Domain: it.map

XIOC detected Domain: it.map

extracted_from_files

Domain
detected Domain: me.data

XIOC detected Domain: me.data

extracted_from_files

Domain
detected Domain: object.is

XIOC detected Domain: object.is

extracted_from_files

Domain
detected Domain: t.data

XIOC detected Domain: t.data

extracted_from_files

Domain
detected Domain: t.next

XIOC detected Domain: t.next

extracted_from_files

IP
detected IP: ea::

XIOC detected IP: ea::

extracted_from_files

URL
detected URL: https://1382.okcomputers.eth.limo/

XIOC detected URL: https://1382.okcomputers.eth.limo/

extracted_from_files

URL
detected URL: https://clients2.google.com/service/update2/crx

XIOC detected URL: https://clients2.google.com/service/update2/crx

extracted_from_files

URL
detected URL: https://cogsmachine.net/*

XIOC detected URL: https://cogsmachine.net/*

extracted_from_files

Domain
detected Domain: t.mh

XIOC detected Domain: t.mh

extracted_from_files

URL
detected URL: https://fonts.googleapis.com/css2?family=Inter:wght@400;500;600;700&display=swap

XIOC detected URL: https://fonts.googleapis.com/css2?family=Inter:wght@400;500;600;700&display=swap

extracted_from_files

URL
detected URL: https://react.dev/errors/

XIOC detected URL: https://react.dev/errors/

extracted_from_files

URL
detected URL: https://$

XIOC detected URL: https://$

extracted_from_files

URL
detected URL: https://cogsmachine.net/fetchcert/

XIOC detected URL: https://cogsmachine.net/fetchcert/

extracted_from_files

Domain
detected Domain: ve.download

XIOC detected Domain: ve.download

extracted_from_files

Domain
detected Domain: ve.click

XIOC detected Domain: ve.click

extracted_from_files

Domain
detected Domain: chrome.windows

XIOC detected Domain: chrome.windows

extracted_from_files

Domain
detected Domain: w.id

XIOC detected Domain: w.id

extracted_from_files

Domain
detected Domain: ns.adobe.com

XIOC detected Domain: ns.adobe.com

extracted_from_files

Domain
detected Domain: o2.pm

XIOC detected Domain: o2.pm

extracted_from_files

Domain
detected Domain: 2.lv

XIOC detected Domain: 2.lv

extracted_from_files

Domain
detected Domain: b.data.bt

XIOC detected Domain: b.data.bt

extracted_from_files

Domain
detected Domain: k.bt

XIOC detected Domain: k.bt

extracted_from_files

Domain
detected Domain: w.data

XIOC detected Domain: w.data

extracted_from_files

Domain
detected Domain: propertyisenumerable.call

XIOC detected Domain: propertyisenumerable.call

extracted_from_files

Domain
detected Domain: hasownproperty.call

XIOC detected Domain: hasownproperty.call

extracted_from_files

Domain
detected Domain: d.style

XIOC detected Domain: d.style

extracted_from_files

Domain
detected Domain: s.style

XIOC detected Domain: s.style

extracted_from_files

Domain
detected Domain: ee.date

XIOC detected Domain: ee.date

extracted_from_files

Domain
detected Domain: g.media

XIOC detected Domain: g.media

extracted_from_files

Domain
detected Domain: m.map

XIOC detected Domain: m.map

extracted_from_files

Domain
detected Domain: ce.map

XIOC detected Domain: ce.map

extracted_from_files

Domain
detected Domain: n.target

XIOC detected Domain: n.target

extracted_from_files

Domain
detected Domain: object.prototype.hasownproperty.call

XIOC detected Domain: object.prototype.hasownproperty.call

extracted_from_files

Domain
detected Domain: r.date

XIOC detected Domain: r.date

extracted_from_files

Domain
detected Domain: g.target

XIOC detected Domain: g.target

extracted_from_files

Domain
detected Domain: d.date

XIOC detected Domain: d.date

extracted_from_files

Domain
detected Domain: u.target

XIOC detected Domain: u.target

extracted_from_files

Domain
detected Domain: ht.data

XIOC detected Domain: ht.data

extracted_from_files

Domain
detected Domain: ge.date

XIOC detected Domain: ge.date

extracted_from_files

Domain
detected Domain: we.map

XIOC detected Domain: we.map

extracted_from_files

Domain
detected Domain: ht.next

XIOC detected Domain: ht.next

extracted_from_files

Domain
detected Domain: og.map

XIOC detected Domain: og.map

extracted_from_files

Domain
detected Domain: ee.delta

XIOC detected Domain: ee.delta

extracted_from_files

Domain
detected Domain: s.id

XIOC detected Domain: s.id

extracted_from_files

Domain
detected Domain: v.data

XIOC detected Domain: v.data

extracted_from_files

Domain
detected Domain: g.data

XIOC detected Domain: g.data

extracted_from_files

Domain
detected Domain: b.data

XIOC detected Domain: b.data

extracted_from_files

Domain
detected Domain: k.target

XIOC detected Domain: k.target

extracted_from_files

Domain
detected Domain: v.delta

XIOC detected Domain: v.delta

extracted_from_files

Domain
detected Domain: g.cy

XIOC detected Domain: g.cy

extracted_from_files

Domain
detected Domain: g.cx

XIOC detected Domain: g.cx

extracted_from_files

Domain
detected Domain: oe.map

XIOC detected Domain: oe.map

extracted_from_files

Domain
detected Domain: f.tw

XIOC detected Domain: f.tw

extracted_from_files

Domain
detected Domain: f.th

XIOC detected Domain: f.th

extracted_from_files

Domain
detected Domain: pe.map

XIOC detected Domain: pe.map

extracted_from_files

Domain
detected Domain: mu.call

XIOC detected Domain: mu.call

extracted_from_files

Domain
detected Domain: this.next

XIOC detected Domain: this.next

extracted_from_files

Domain
detected Domain: i.info

XIOC detected Domain: i.info

extracted_from_files

Domain
detected Domain: c.map

XIOC detected Domain: c.map

extracted_from_files

Domain
detected Domain: chrome.storage

XIOC detected Domain: chrome.storage

extracted_from_files

Domain
detected Domain: ut.map

XIOC detected Domain: ut.map

extracted_from_files

Domain
detected Domain: b.delta

XIOC detected Domain: b.delta

extracted_from_files

Domain
detected Domain: h.next

XIOC detected Domain: h.next

extracted_from_files

Domain
detected Domain: le.data

XIOC detected Domain: le.data

extracted_from_files

Domain
detected Domain: it.data

XIOC detected Domain: it.data

extracted_from_files

Domain
detected Domain: a.data

XIOC detected Domain: a.data

extracted_from_files

Domain
detected Domain: t.as

XIOC detected Domain: t.as

extracted_from_files

Domain
detected Domain: l.media

XIOC detected Domain: l.media

extracted_from_files

Domain
detected Domain: a.media

XIOC detected Domain: a.media

extracted_from_files

Domain
detected Domain: i.style

XIOC detected Domain: i.style

extracted_from_files

Domain
detected Domain: m.memoizedprops.style

XIOC detected Domain: m.memoizedprops.style

extracted_from_files

Domain
detected Domain: i.id

XIOC detected Domain: i.id

extracted_from_files

Domain
detected Domain: xn.next

XIOC detected Domain: xn.next

extracted_from_files

Domain
detected Domain: e.id

XIOC detected Domain: e.id

extracted_from_files

Domain
detected Domain: j.target

XIOC detected Domain: j.target

extracted_from_files

Domain
detected Domain: de.target

XIOC detected Domain: de.target

extracted_from_files

Domain
detected Domain: a.next

XIOC detected Domain: a.next

extracted_from_files

Domain
detected Domain: n.data

XIOC detected Domain: n.data

extracted_from_files

Domain
detected Domain: t.events

XIOC detected Domain: t.events

extracted_from_files

Domain
detected Domain: l.compare

XIOC detected Domain: l.compare

extracted_from_files

Domain
detected Domain: a.is

XIOC detected Domain: a.is

extracted_from_files

Domain
detected Domain: e.events

XIOC detected Domain: e.events

extracted_from_files

Domain
detected Domain: l.property

XIOC detected Domain: l.property

extracted_from_files

Domain
detected Domain: i.next

XIOC detected Domain: i.next

extracted_from_files

Domain
detected Domain: m.next

XIOC detected Domain: m.next

extracted_from_files

Domain
detected Domain: z.next

XIOC detected Domain: z.next

extracted_from_files

Domain
detected Domain: qe.next

XIOC detected Domain: qe.next

extracted_from_files

Domain
detected Domain: i.events

XIOC detected Domain: i.events

extracted_from_files

Domain
detected Domain: ft.next

XIOC detected Domain: ft.next

extracted_from_files

Domain
detected Domain: a.data.map

XIOC detected Domain: a.data.map

extracted_from_files

Domain
detected Domain: r.next

XIOC detected Domain: r.next

extracted_from_files

Domain
detected Domain: c.now

XIOC detected Domain: c.now

extracted_from_files

Domain
detected Domain: g.as

XIOC detected Domain: g.as

extracted_from_files

Domain
detected Domain: xe.call

XIOC detected Domain: xe.call

extracted_from_files

Domain
detected Domain: w.next

XIOC detected Domain: w.next

extracted_from_files

Domain
detected Domain: se.call

XIOC detected Domain: se.call

extracted_from_files

Domain
detected Domain: 1382.okcomputers.eth.limo

XIOC detected Domain: 1382.okcomputers.eth.limo

extracted_from_files

Domain
detected Domain: cogsmachine.net

XIOC detected Domain: cogsmachine.net

extracted_from_files

Domain
detected Domain: react.dev

XIOC detected Domain: react.dev

extracted_from_files

Domain
detected Domain: t.target

XIOC detected Domain: t.target

extracted_from_files

Domain
detected Domain: n.next

XIOC detected Domain: n.next

extracted_from_files

Domain
detected Domain: u.next

XIOC detected Domain: u.next

extracted_from_files

Domain
detected Domain: t.id

XIOC detected Domain: t.id

extracted_from_files

Domain
detected Domain: a.name

XIOC detected Domain: a.name

extracted_from_files

Domain
detected Domain: e.style

XIOC detected Domain: e.style

extracted_from_files

Domain
detected Domain: e.target

XIOC detected Domain: e.target

extracted_from_files

Domain
detected Domain: l.name

XIOC detected Domain: l.name

extracted_from_files

Domain
detected Domain: n.name

XIOC detected Domain: n.name

extracted_from_files

Domain
detected Domain: this.target

XIOC detected Domain: this.target

extracted_from_files

Domain
detected Domain: date.now

XIOC detected Domain: date.now

extracted_from_files

Domain
detected Domain: e.data

XIOC detected Domain: e.data

extracted_from_files

Domain
detected Domain: e.name

XIOC detected Domain: e.name

extracted_from_files

Domain
detected Domain: t.name

XIOC detected Domain: t.name

extracted_from_files

Domain
detected Domain: d.call

XIOC detected Domain: d.call

extracted_from_files

Domain
detected Domain: e.call

XIOC detected Domain: e.call

extracted_from_files

Domain
detected Domain: zl.call

XIOC detected Domain: zl.call

extracted_from_files

Domain
detected Domain: n.call

XIOC detected Domain: n.call

extracted_from_files

Domain
detected Domain: i.call

XIOC detected Domain: i.call

extracted_from_files

Domain
detected Domain: ne.call

XIOC detected Domain: ne.call

extracted_from_files

Domain
detected Domain: x.id-x.id

XIOC detected Domain: x.id-x.id

extracted_from_files

Domain
detected Domain: performance.now

XIOC detected Domain: performance.now

extracted_from_files

Domain
detected Domain: v.now

XIOC detected Domain: v.now

extracted_from_files

Domain
detected Domain: e.next

XIOC detected Domain: e.next

extracted_from_files

Domain
detected Domain: l.next

XIOC detected Domain: l.next

extracted_from_files

Domain
detected Domain: a.call

XIOC detected Domain: a.call

extracted_from_files

AI Security Report

AI Security Review

Risky Plugins reviewed this extension with an AI-assisted security workflow on 2026-04-22. The review verdict is benign but powerful with 70% confidence.

Recommended action: no action.
Risk context: MEDIUM risk, score 63/100.
Evidence context: threat category none; evidence quality moderate.

The teleCOG extension (version 1.1.0) presents no security findings in the provided evidence bundle, with an empty findings_by_category object indicating no detected malware signatures, suspicious IoCs, or code-smell patterns. The developer is attributed to [email protected], a corporate email address that provides traceability, reducing impersonation risk. The extension's stated purpose—securely accessing a COGSmachine node for token transactions—aligns with legitimate blockchain utility use cases.

No obfuscation, credential theft, or browser hijacking indicators were identified. The absence of findings in findings_by_category suggests either minimal code complexity or a clean security posture. However, the extremely low user count (3) warrants scrutiny, as niche extensions may lack community validation.

Counterargument: A skeptic might argue the low user count implies limited auditability or potential obscurity for malicious actors. However, the identifiable developer email and absence of security findings outweigh this concern. Without evidence of deceptive naming, suspicious domains, or harmful code patterns, the low adoption rate alone does not justify a malicious verdict.

The extension’s functionality requires browser permissions to interact with blockchain nodes, a capability that could theoretically be misused but is standard for legitimate crypto tools. No findings suggest active exploitation of these permissions.

Conclusion: The extension appears benign with no evidence of malicious intent. Its power lies in blockchain integration, not inherent risk. Continued monitoring is prudent due to low visibility, but no immediate action is warranted.

Key Reasons

  • No security findings detected in analysis
  • Identifiable developer email ([email protected])
  • Legitimate blockchain utility use case
  • No obfuscation or suspicious IoCs

Frequently Asked Questions