From the RiskyPlugins AI security review of the observed evidence.
Analysis record
- Analysed
- 6 months ago
- Version
- v0.0.5
- Source
- Findings (non-IoC)
Evidence ledger
Ranked by severity · findings with a source location link to the code viewer
YARA Rule Matches
10 rules| Severity | Rule | Hits | Files | Metadata |
|---|---|---|---|---|
| HIGH | postinstall crypto operations Cryptographic operations detected | 3 | scripts/list-fake-news.jsscripts/list-swen.js_metadata/verified_contents.json | Risky Plugins Authors FP 30% |
| HIGH | postinstall network communication Network communication detected | 3 | scripts/list-fake-news.jsscripts/list-swen.jsscripts/vendor/browser-polyfill.js | Risky Plugins Authors FP 30% |
| HIGH | postinstall file manipulation File system manipulation detected | 4 | scripts/popup.jsscripts/background.jsscripts/list-swen.js +1 more | Risky Plugins Authors FP 20% |
| HIGH | postinstall environment access Environment variable access detected | 1 | scripts/list-swen.js | Risky Plugins Authors FP 40% |
| HIGH | postinstall persistence mechanism Persistence mechanism detected | 1 | scripts/list-swen.js | Risky Plugins Authors FP 20% |
| HIGH | postinstall system command System command execution detected | 5 | scripts/list-swen.jsscripts/vendor/browser-polyfill.jsstylesheets/vendor/bootstrap.min.css +2 more | Risky Plugins Authors FP 10% |
| HIGH | postinstall file download File download activity detected | 3 | scripts/list-swen.jsscripts/vendor/browser-polyfill.jsscripts/article-list.js | Risky Plugins Authors FP 30% |
| HIGH | postinstall obfuscation Code obfuscation techniques detected | 3 | scripts/list-fake-news.jsscripts/list-swen.jsscripts/vendor/browser-polyfill.js | Risky Plugins Authors FP 20% |
| HIGH | credential steam data Steam application data path detected | 1 | scripts/list-swen.js | Risky Plugins Authors FP 20% |
| HIGH | credential env files Environment configuration file path detected | 1 | scripts/list-swen.js | Risky Plugins Authors FP 10% |
Network Indicators
Concrete URLs, domains, IPs, emails, and hashes extracted from the analyzed artifact.
Network indicators are queued for lazy loading
Scroll this section into view to load the detailed rows.
Publisher Evidence
Limited evidenceSWEN
Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.
Edge does not expose the same publisher verification data as IDE stores, so this score is deliberately conservative.
13 evidence rows available.
Finding Categories
YARA Rules Matched
10 rules(25 hits)AI Security Report
AI Security Review
Evidence context: threat category unknown malware; evidence quality moderate.
The SWEN extension presents a mixed threat profile. The extension's description ('Stop reading the News!') and the 11,213 IoC findings are consistent with a legitimate news/content blocker that embeds domain blocklists. Sample domains like onenewspage.com, ontopmag.com, and opensecrets.org appear to be legitimate news and information sites, which would be expected in a news-blocking extension. The network findings in scripts/list-swen.js:798 (axios) and scripts/article-list.js:14 (fetch) are standard for extensions that fetch or update content lists.
However, the 25 high-severity malware signatures cannot be dismissed as noise. Unlike code-smell findings (which are classified as low severity and are documented false positives), malware signatures represent actual malware family matches. The evidence bundle shows malware-signature count of 25 with high severity, but does not specify which malware families were detected. This is the critical unknown.
Additional concerns include: version is 'unknown' (prevents verification against known releases), user count is 0 (no community validation), and developer name 'SWEN' matches the extension name with no additional attribution. These factors reduce confidence in the extension's legitimacy.
The strongest counterargument for a false positive verdict is that the extension's stated purpose (news blocking) perfectly explains the domain list and network calls, and the malware signatures could be false positives from bundled dependencies or blocklist content. However, malware signatures are distinct from code-smell and IoC noise—the decision framework explicitly states malware signatures co-located with suspicious behavior warrant investigation. Without knowing which specific malware families triggered these 25 high-severity matches, I cannot determine if this is a legitimate extension with false positive matches or a malicious extension disguised as a news blocker.
Runtime analysis is required to: (1) identify which malware families triggered the signatures, (2) observe actual network behavior to confirm domains are used for blocking rather than data exfiltration, and (3) verify the extension's version against any known releases.
Key Reasons
- 25 high-severity malware signatures require investigation
- Version is unknown preventing release verification
- Zero user count provides no community validation
- IoC volume consistent with news blocker functionality
- Anonymous developer attribution (SWEN matches extension name)
False Positive Considerations
- IoC volume from embedded blocklist
- Network calls consistent with content updater functionality
Reviewed 2026-04-27; recommended action: runtime analysis; model confidence 65%.
Source Code Not Available
Source code is not available for this version of the extension.
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace