Microsoft Edge Add-ons Verified

SWEN

by SWEN
00cbdb43-168a-5a86-8b6c-48f656026509 | v0.0.5
61/ 100
MEDIUM risk
Analyst verdict
Needs follow up

From the RiskyPlugins AI security review of the observed evidence.

Analysis record

Analysed
6 months ago
Version
v0.0.5
Source
Findings (non-IoC)

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

43 detail rows

YARA Rule Matches

10 rules
SeverityRuleHitsFilesMetadata
HIGHpostinstall crypto operations

Cryptographic operations detected

3
scripts/list-fake-news.jsscripts/list-swen.js_metadata/verified_contents.json
Risky Plugins Authors FP 30%
HIGHpostinstall network communication

Network communication detected

3
scripts/list-fake-news.jsscripts/list-swen.jsscripts/vendor/browser-polyfill.js
Risky Plugins Authors FP 30%
HIGHpostinstall file manipulation

File system manipulation detected

4
scripts/popup.jsscripts/background.jsscripts/list-swen.js +1 more
Risky Plugins Authors FP 20%
HIGHpostinstall environment access

Environment variable access detected

1
scripts/list-swen.js
Risky Plugins Authors FP 40%
HIGHpostinstall persistence mechanism

Persistence mechanism detected

1
scripts/list-swen.js
Risky Plugins Authors FP 20%
HIGHpostinstall system command

System command execution detected

5
scripts/list-swen.jsscripts/vendor/browser-polyfill.jsstylesheets/vendor/bootstrap.min.css +2 more
Risky Plugins Authors FP 10%
HIGHpostinstall file download

File download activity detected

3
scripts/list-swen.jsscripts/vendor/browser-polyfill.jsscripts/article-list.js
Risky Plugins Authors FP 30%
HIGHpostinstall obfuscation

Code obfuscation techniques detected

3
scripts/list-fake-news.jsscripts/list-swen.jsscripts/vendor/browser-polyfill.js
Risky Plugins Authors FP 20%
HIGHcredential steam data

Steam application data path detected

1
scripts/list-swen.js
Risky Plugins Authors FP 20%
HIGHcredential env files

Environment configuration file path detected

1
scripts/list-swen.js
Risky Plugins Authors FP 10%

Network Indicators

Concrete URLs, domains, IPs, emails, and hashes extracted from the analyzed artifact.

11,211 total
...

Network indicators are queued for lazy loading

Scroll this section into view to load the detailed rows.

Publisher Evidence

Limited evidence

SWEN

Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.

Edge does not expose the same publisher verification data as IDE stores, so this score is deliberately conservative.

28
Noisy-finding weight
x1.00
Publisher domain
getswen.com
Observed
Store verification signal
Limited signal
Limited
Extension portfolio
1
Portfolio

13 evidence rows available.

Finding Categories

25
Malware Signatures
2
Network
11,211
IoC Indicators

YARA Rules Matched

10 rules(25 hits)
postinstall crypto operations postinstall network communication postinstall file manipulation postinstall environment access postinstall persistence mechanism postinstall system command postinstall file download postinstall obfuscation credential steam data credential env files

AI Security Report

AI Security Review

Evidence context: threat category unknown malware; evidence quality moderate.

The SWEN extension presents a mixed threat profile. The extension's description ('Stop reading the News!') and the 11,213 IoC findings are consistent with a legitimate news/content blocker that embeds domain blocklists. Sample domains like onenewspage.com, ontopmag.com, and opensecrets.org appear to be legitimate news and information sites, which would be expected in a news-blocking extension. The network findings in scripts/list-swen.js:798 (axios) and scripts/article-list.js:14 (fetch) are standard for extensions that fetch or update content lists.

However, the 25 high-severity malware signatures cannot be dismissed as noise. Unlike code-smell findings (which are classified as low severity and are documented false positives), malware signatures represent actual malware family matches. The evidence bundle shows malware-signature count of 25 with high severity, but does not specify which malware families were detected. This is the critical unknown.

Additional concerns include: version is 'unknown' (prevents verification against known releases), user count is 0 (no community validation), and developer name 'SWEN' matches the extension name with no additional attribution. These factors reduce confidence in the extension's legitimacy.

The strongest counterargument for a false positive verdict is that the extension's stated purpose (news blocking) perfectly explains the domain list and network calls, and the malware signatures could be false positives from bundled dependencies or blocklist content. However, malware signatures are distinct from code-smell and IoC noise—the decision framework explicitly states malware signatures co-located with suspicious behavior warrant investigation. Without knowing which specific malware families triggered these 25 high-severity matches, I cannot determine if this is a legitimate extension with false positive matches or a malicious extension disguised as a news blocker.

Runtime analysis is required to: (1) identify which malware families triggered the signatures, (2) observe actual network behavior to confirm domains are used for blocking rather than data exfiltration, and (3) verify the extension's version against any known releases.

Key Reasons

  • 25 high-severity malware signatures require investigation
  • Version is unknown preventing release verification
  • Zero user count provides no community validation
  • IoC volume consistent with news blocker functionality
  • Anonymous developer attribution (SWEN matches extension name)

False Positive Considerations

  • IoC volume from embedded blocklist
  • Network calls consistent with content updater functionality

Reviewed 2026-04-27; recommended action: runtime analysis; model confidence 65%.

Frequently Asked Questions