Is "NetAcad Genius" on Chrome Web Store Safe to Install?

[email protected] · chrome · v1.0.0

NetAcad Genius: Your Intelligent Learning Assistant for Cisco NetAcad Supercharge your learning experience on Cisco NetAcad with NetAcad Genius, a Chrome extension designed to help students understand networking concepts more effectively and efficiently. What NetAcad Genius offers: Smart Content Assistance: Helps analyze learning materials from NetAcad activities to support better understanding of questions, options, and visuals in an interactive way. AI-Powered Learning Support: Integrates advanced AI models (GPT-4o, DeepSeek) to provide explanations, clarifications, and conceptual guidance. Custom Learning Modes: Guided Mode: Get structured help while solving exercises. Explanatory Mode: Understand the reasoning behind networking concepts. Hint Mode: Receive conceptual hints to support your learning process without revealing direct answers. Seamless Interface: Works directly inside your learning environment with a clean and intuitive user experience. Advanced Compatibility: Supports complex web layouts and modern UI components used in NetAcad courses.

Risk Assessment

Analyzed
62.46
out of 100
MEDIUM

88 security findings detected across all analyzers

Chrome extension requesting 7 permissions

Severity Breakdown

0
Critical
0
High
72
Medium
16
Low
0
Info

Finding Categories

2
Network
70
IoC Indicators

YARA Rules Matched

7 rules(16 hits)
postinstall file manipulation postinstall network communication postinstall file download postinstall system command postinstall obfuscation postinstall environment access postinstall crypto operations

Requested Permissions

7 permissions
webRequest

Intercept, modify, and block all network requests

High
storage
Low
https://netacad.com/*
Low
https://www.netacad.com/*
Low
https://api.openai.com/*
Low
https://api.deepseek.com/*
Low
https://generativelanguage.googleapis.com/*
Low

About This Extension

NetAcad Genius: Your Intelligent Learning Assistant for Cisco NetAcad Supercharge your learning experience on Cisco NetAcad with NetAcad Genius, a Chrome extension designed to help students understand networking concepts more effectively and efficiently. What NetAcad Genius offers: Smart Content Assistance: Helps analyze learning materials from NetAcad activities to support better understanding of questions, options, and visuals in an interactive way. AI-Powered Learning Support: Integrates advanced AI models (GPT-4o, DeepSeek) to provide explanations, clarifications, and conceptual guidance. Custom Learning Modes: Guided Mode: Get structured help while solving exercises. Explanatory Mode: Understand the reasoning behind networking concepts. Hint Mode: Receive conceptual hints to support your learning process without revealing direct answers. Seamless Interface: Works directly inside your learning environment with a clean and intuitive user experience. Advanced Compatibility: Supports complex web layouts and modern UI components used in NetAcad courses.

Detailed Findings

18 total

YARA Rule Matches

7 rules

Indicators of Compromise

Network indicators, suspicious strings, and potential IoCs extracted during analysis

URLs
17
IP Addresses
4
Domains
49
Strings
70

All Indicators · 70

IP
detected IP: ::bef

XIOC detected IP: ::bef

extracted_from_files

Domain
detected Domain: yesbutton.click

XIOC detected Domain: yesbutton.click

extracted_from_files

URL
detected URL: https://generativelanguage.googleapis.com/*

XIOC detected URL: https://generativelanguage.googleapis.com/*

extracted_from_files

URL
detected URL: https://*.netacad.com/*

XIOC detected URL: https://*.netacad.com/*

extracted_from_files

URL
detected URL: https://*.netacad.net/*

XIOC detected URL: https://*.netacad.net/*

extracted_from_files

URL
detected URL: https://fonts.googleapis.com/css2?family=Outfit:wght@300;400;600&family=Inter:wght@400;500;700&display=swap');

XIOC detected URL: https://fonts.googleapis.com/css2?family=Outfit:wght@300;400;600&family=Inter:wght@400;500;700&display=swap');

extracted_from_files

Hash
detected MD5 Hash: 4d76993c11374083829fec95af541640

XIOC detected MD5 Hash: 4d76993c11374083829fec95af541640

extracted_from_files

URL
detected URL: http://d1uadn0pjsih8m.cloudfront.net/crl/0a0aa452-9f27-4863-aeda-ed976f20d8bb.crl0

XIOC detected URL: http://d1uadn0pjsih8m.cloudfront.net/crl/0a0aa452-9f27-4863-aeda-ed976f20d8bb.crl0

extracted_from_files

URL
detected URL: http://ns.attribution.com/ads/1.0/'

XIOC detected URL: http://ns.attribution.com/ads/1.0/'

extracted_from_files

URL
detected URL: https://canva.com/export'

XIOC detected URL: https://canva.com/export'

extracted_from_files

URL
detected URL: https://clients2.google.com/service/update2/crx

XIOC detected URL: https://clients2.google.com/service/update2/crx

extracted_from_files

URL
detected URL: https://netacad.com/*

XIOC detected URL: https://netacad.com/*

extracted_from_files

URL
detected URL: https://www.netacad.com/*

XIOC detected URL: https://www.netacad.com/*

extracted_from_files

URL
detected URL: https://api.openai.com/*

XIOC detected URL: https://api.openai.com/*

extracted_from_files

Domain
detected Domain: model.id

XIOC detected Domain: model.id

extracted_from_files

Domain
detected Domain: model.name

XIOC detected Domain: model.name

extracted_from_files

URL
detected URL: https://api.openai.com/v1/chat/completions',

XIOC detected URL: https://api.openai.com/v1/chat/completions',

extracted_from_files

URL
detected URL: https://api.deepseek.com/v1/chat/completions',

XIOC detected URL: https://api.deepseek.com/v1/chat/completions',

extracted_from_files

Domain
detected Domain: t.id

XIOC detected Domain: t.id

extracted_from_files

URL
detected URL: https://*.netacad.com/*/components.json']

XIOC detected URL: https://*.netacad.com/*/components.json']

extracted_from_files

URL
detected URL: https://pki.canva-internal.com/v1/pki/canva-prod/l1/signing/ocsp0w

XIOC detected URL: https://pki.canva-internal.com/v1/pki/canva-prod/l1/signing/ocsp0w

extracted_from_files

Domain
detected Domain: ns.adobe.com

XIOC detected Domain: ns.adobe.com

extracted_from_files

IP
detected Domain: cv.iptc.org

XIOC detected Domain: cv.iptc.org

extracted_from_files

Domain
detected Domain: c2pa.hash.data

XIOC detected Domain: c2pa.hash.data

extracted_from_files

Domain
detected Domain: pki.canva-internal.com

XIOC detected Domain: pki.canva-internal.com

extracted_from_files

Domain
detected Domain: www.netacad.com

XIOC detected Domain: www.netacad.com

extracted_from_files

Domain
detected Domain: netacad.net

XIOC detected Domain: netacad.net

extracted_from_files

Domain
detected Domain: settings-overlay.open

XIOC detected Domain: settings-overlay.open

extracted_from_files

Domain
detected Domain: next.host

XIOC detected Domain: next.host

extracted_from_files

Domain
detected Domain: imgs.map

XIOC detected Domain: imgs.map

extracted_from_files

Domain
detected Domain: wrapper.id

XIOC detected Domain: wrapper.id

extracted_from_files

Domain
detected Domain: wrapper.style.top

XIOC detected Domain: wrapper.style.top

extracted_from_files

Domain
detected Domain: potentialanchors.map

XIOC detected Domain: potentialanchors.map

extracted_from_files

Domain
detected Domain: d1uadn0pjsih8m.cloudfront.net

XIOC detected Domain: d1uadn0pjsih8m.cloudfront.net

extracted_from_files

Domain
detected Domain: ns.attribution.com

XIOC detected Domain: ns.attribution.com

extracted_from_files

Domain
detected Domain: actionsdiv.id

XIOC detected Domain: actionsdiv.id

extracted_from_files

Domain
detected Domain: window.meowtoaster.show

XIOC detected Domain: window.meowtoaster.show

extracted_from_files

Domain
detected Domain: question.items.map

XIOC detected Domain: question.items.map

extracted_from_files

Domain
detected Domain: cats.map

XIOC detected Domain: cats.map

extracted_from_files

Domain
detected Domain: opts.map

XIOC detected Domain: opts.map

extracted_from_files

Domain
detected Domain: itemelements.map

XIOC detected Domain: itemelements.map

extracted_from_files

Domain
detected Domain: container.host

XIOC detected Domain: container.host

extracted_from_files

Domain
detected Domain: question.questiondiv.click

XIOC detected Domain: question.questiondiv.click

extracted_from_files

Domain
detected Domain: input.click

XIOC detected Domain: input.click

extracted_from_files

Domain
detected Domain: dropdownitem.click

XIOC detected Domain: dropdownitem.click

extracted_from_files

Domain
detected Domain: optionelement.click

XIOC detected Domain: optionelement.click

extracted_from_files

Domain
detected Domain: label.click

XIOC detected Domain: label.click

extracted_from_files

Domain
detected Domain: optionel.click

XIOC detected Domain: optionel.click

extracted_from_files

Domain
detected Domain: element.map

XIOC detected Domain: element.map

extracted_from_files

Domain
detected Domain: components.map

XIOC detected Domain: components.map

extracted_from_files

Domain
detected Domain: questions.map

XIOC detected Domain: questions.map

extracted_from_files

Domain
detected Domain: question.id

XIOC detected Domain: question.id

extracted_from_files

Domain
detected Domain: e.target

XIOC detected Domain: e.target

extracted_from_files

URL
detected URL: https://generativelanguage.googleapis.com/v1beta/models/gemini-pro:generateContent'

XIOC detected URL: https://generativelanguage.googleapis.com/v1beta/models/gemini-pro:generateContent'

extracted_from_files

Domain
detected Domain: nobutton.click

XIOC detected Domain: nobutton.click

extracted_from_files

Domain
detected Domain: button.click

XIOC detected Domain: button.click

extracted_from_files

Domain
detected Domain: netacad.com

XIOC detected Domain: netacad.com

extracted_from_files

Domain
detected Domain: details.requestheaders.map

XIOC detected Domain: details.requestheaders.map

extracted_from_files

Domain
detected Domain: style.id

XIOC detected Domain: style.id

extracted_from_files

Domain
detected Domain: toast.id

XIOC detected Domain: toast.id

extracted_from_files

Domain
detected Domain: toast.style

XIOC detected Domain: toast.style

extracted_from_files

Domain
detected Domain: rect.top

XIOC detected Domain: rect.top

extracted_from_files

Domain
detected Domain: el.style.top

XIOC detected Domain: el.style.top

extracted_from_files

IP
detected IP: ::af

XIOC detected IP: ::af

extracted_from_files

IP
detected IP: e::af

XIOC detected IP: e::af

extracted_from_files

Domain
detected Domain: api.openai.com

XIOC detected Domain: api.openai.com

extracted_from_files

Domain
detected Domain: api.deepseek.com

XIOC detected Domain: api.deepseek.com

extracted_from_files

Domain
detected Domain: generativelanguage.googleapis.com

XIOC detected Domain: generativelanguage.googleapis.com

extracted_from_files

Domain
detected Domain: tab.id

XIOC detected Domain: tab.id

extracted_from_files

URL
detected URL: https://api.deepseek.com/*

XIOC detected URL: https://api.deepseek.com/*

extracted_from_files

AI Security Report

AI Security Review

Risky Plugins reviewed this extension with an AI-assisted security workflow on 2026-04-21. The review verdict is likely false positive with 65% confidence.

Recommended action: no action.
Risk context: MEDIUM risk, score 62/100.
Evidence context: threat category none; evidence quality weak.

Security Analysis: NetAcad Genius

The CVEQ analysis of this extension returned zero security findings across all categories. The findings_by_category bucket is completely empty, indicating no malware signatures, no suspicious IoCs (domains/IPs), no code-smell detections, and no obfuscation markers were identified.

Extension Metadata

  • Name: NetAcad Genius
  • Description: AI-powered assistant to help NetAcad Students understand course content and improve learning
  • Developer: [email protected] (personal Gmail account)
  • User Count: 0
  • Version: 1.0.0
  • Store: Chrome Web Store

Security Assessment

With no findings in any category, there is no evidence of malicious behavior. The extension does not trigger any YARA rules for credential theft, browser hijacking, proxyware, or malware delivery. No external domains are referenced in the code that would indicate data exfiltration or command-and-control communication.

The developer attribution uses a personal Gmail address rather than an official Cisco domain (NetAcad is Cisco's networking education program). While this is not inherently malicious, it means the extension is not officially affiliated with Cisco. Users should verify whether this extension is endorsed by Cisco NetAcad before installing.

Counterargument

A skeptic might argue that the empty findings bucket indicates incomplete analysis rather than a clean result. However, the metadata is complete (name, description, version, developer, store all populated), suggesting the extension was successfully scraped and analyzed. The version is '1.0.0' (not 'unknown'), and the UUID is valid. If the analysis had failed entirely, we would expect missing metadata fields or version 'unknown'. The most likely explanation is that the analysis ran and found no security issues.

Recommendation

This extension shows no signs of malicious behavior. The zero user count and personal developer email suggest it is either very new or has not gained traction. Users should verify the extension's legitimacy with Cisco NetAcad before installation, but there is no security reason to block it based on this analysis.

Key Reasons

  • Zero security findings across all categories
  • No malware signatures or suspicious IoCs detected
  • No code-smell or obfuscation markers
  • Complete metadata suggests analysis ran successfully

False Positive Considerations

  • No findings to evaluate - clean analysis
  • Personal Gmail developer address (not malicious, just unverified)

Frequently Asked Questions