Is "Gartic Cellulart for Gartic Phone" on Chrome Web Store Safe to Install?

[email protected] · chrome · v1.7.7

Gartic Cellulart adds the following functions / tools to Gartic Phone: - Timer: A digital timer in the top-right will count down the number of seconds remaining in the phase - Reference Images: A file upload box in the bottom right allows you to upload reference images which can be moved about onscreen - Spotlight: Allows you to download your responses paired with the prompts that inspired them, so you have your performance for that round in one place - Scry: Shows you who hasn't hit the DONE button yet - Satellite: The passcode that unlocks zero or more Red Tools (possibly "unfair", do not use in public lobbies) And a few more. See https://codeberg.org/Kuixz/gartic-cellulart/wiki for detailed usage instructions, along with the most up-to-date edition of the code. Any feedback would be greatly appreciated! Just drop a message to Quixz#0033 or email me at [email protected]. ! Note ! MOST functionalities WILL break if you or another script disable or break the browser's WebSocket ---------------------------------------------------------------- Changelog --- Patch 1.7.7 (23/4/26) --- * Fixed Refdrop and Akasha underlaid images being the wrong size --- Minor 1.7.6 (20/4/26) --- * Updated Snowball, Geom, Akasha, and Spotlight to double precision * Fixed Geom previewing the wrong region * Fixed Spotlight hanging forever if it fails to write a GIF frame --- Patch 1.7.5 (lost) --- * Fixed Spotlight for Firefox users * Fixed dropped screen transitions in Knock-Off mode * Fixed Refdrop RED mode being stuck in front of the drawing zone * Fixed Akasha attaching buttons to the wrong elements when changing timelines * Akasha now indicates when an uploaded image is of the wrong MIME type * Akasha can now capture drawings from the current album that were revealed before you joined So I forgot to release Patch 1.7.5. Oops. ._. --- Minor 1.7.4 (12/2/26) --- * Added support for square canvases across modules * Fixed Spotlight for Chrome users * Akasha now indicates when an upload fails instead of failing silently = Reworked parts of Snowball and Koss for clarity ---------------------------------------------------------------- Contributors A special thanks to everybody who contributed ideas and/or code to Cellulart! codeberg.org/yosoyalexisprado: Upgraded Scry look and function Daniel: Suggested Akasha

Risk Assessment

Analyzed
63
out of 100
MEDIUM

164 security findings detected across all analyzers

Chrome extension requesting 3 permissions

Severity Breakdown

0
Critical
1
High
139
Medium
24
Low
0
Info

Finding Categories

1
Obfuscation
1
Network
138
IoC Indicators

YARA Rules Matched

8 rules(24 hits)
postinstall obfuscation postinstall file manipulation postinstall network communication postinstall file download postinstall system command NoUseWeakRandom postinstall crypto operations OriginsNotVerified

Requested Permissions

3 permissions
storage
Low
https://garticphone.com/*
Low
https://beta.garticphone.com/*
Low

About This Extension

Gartic Cellulart adds the following functions / tools to Gartic Phone: - Timer: A digital timer in the top-right will count down the number of seconds remaining in the phase - Reference Images: A file upload box in the bottom right allows you to upload reference images which can be moved about onscreen - Spotlight: Allows you to download your responses paired with the prompts that inspired them, so you have your performance for that round in one place - Scry: Shows you who hasn't hit the DONE button yet - Satellite: The passcode that unlocks zero or more Red Tools (possibly "unfair", do not use in public lobbies) And a few more. See https://codeberg.org/Kuixz/gartic-cellulart/wiki for detailed usage instructions, along with the most up-to-date edition of the code. Any feedback would be greatly appreciated! Just drop a message to Quixz#0033 or email me at [email protected]. ! Note ! MOST functionalities WILL break if you or another script disable or break the browser's WebSocket ---------------------------------------------------------------- Changelog --- Patch 1.7.7 (23/4/26) --- * Fixed Refdrop and Akasha underlaid images being the wrong size --- Minor 1.7.6 (20/4/26) --- * Updated Snowball, Geom, Akasha, and Spotlight to double precision * Fixed Geom previewing the wrong region * Fixed Spotlight hanging forever if it fails to write a GIF frame --- Patch 1.7.5 (lost) --- * Fixed Spotlight for Firefox users * Fixed dropped screen transitions in Knock-Off mode * Fixed Refdrop RED mode being stuck in front of the drawing zone * Fixed Akasha attaching buttons to the wrong elements when changing timelines * Akasha now indicates when an uploaded image is of the wrong MIME type * Akasha can now capture drawings from the current album that were revealed before you joined So I forgot to release Patch 1.7.5. Oops. ._. --- Minor 1.7.4 (12/2/26) --- * Added support for square canvases across modules * Fixed Spotlight for Chrome users * Akasha now indicates when an upload fails instead of failing silently = Reworked parts of Snowball and Koss for clarity ---------------------------------------------------------------- Contributors A special thanks to everybody who contributed ideas and/or code to Cellulart! codeberg.org/yosoyalexisprado: Upgraded Scry look and function Daniel: Suggested Akasha

Detailed Findings

26 total

YARA Rule Matches

8 rules

Indicators of Compromise

Network indicators, suspicious strings, and potential IoCs extracted during analysis

URLs
8
Domains
128
Strings
138

All Indicators · 138

Domain
detected Domain: o.style.top

XIOC detected Domain: o.style.top

extracted_from_files

Domain
detected Domain: m.fast

XIOC detected Domain: m.fast

extracted_from_files

URL
detected URL: http://samcodes.co.uk/)

XIOC detected URL: http://samcodes.co.uk/)

extracted_from_files

URL
detected URL: https://github.com/fogleman/primitive)

XIOC detected URL: https://github.com/fogleman/primitive)

extracted_from_files

Hash
detected MD5 Hash: 24ffd9981415f12b93ba0f186beb4ec9

XIOC detected MD5 Hash: 24ffd9981415f12b93ba0f186beb4ec9

extracted_from_files

Domain
detected Domain: samcodes.co.uk

XIOC detected Domain: samcodes.co.uk

extracted_from_files

URL
detected URL: https://loading.io

XIOC detected URL: https://loading.io

extracted_from_files

URL
detected URL: https://gist.githubusercontent.com/SillyV/24ffd9981415f12b93ba0f186beb4ec9/raw

XIOC detected URL: https://gist.githubusercontent.com/SillyV/24ffd9981415f12b93ba0f186beb4ec9/raw

extracted_from_files

URL
detected URL: https://github.com/babel/babel/blob/main/packages/babel-helpers/LICENSE

XIOC detected URL: https://github.com/babel/babel/blob/main/packages/babel-helpers/LICENSE

extracted_from_files

URL
detected URL: https://clients2.google.com/service/update2/crx

XIOC detected URL: https://clients2.google.com/service/update2/crx

extracted_from_files

URL
detected URL: https://garticphone.com/*

XIOC detected URL: https://garticphone.com/*

extracted_from_files

URL
detected URL: https://beta.garticphone.com/*

XIOC detected URL: https://beta.garticphone.com/*

extracted_from_files

Domain
detected Domain: t.cy

XIOC detected Domain: t.cy

extracted_from_files

Domain
detected Domain: error.call

XIOC detected Domain: error.call

extracted_from_files

Domain
detected Domain: o.call

XIOC detected Domain: o.call

extracted_from_files

Domain
detected Domain: performance.now

XIOC detected Domain: performance.now

extracted_from_files

Domain
detected Domain: m.circle

XIOC detected Domain: m.circle

extracted_from_files

Domain
detected Domain: n.id

XIOC detected Domain: n.id

extracted_from_files

Domain
detected Domain: r.post

XIOC detected Domain: r.post

extracted_from_files

Domain
detected Domain: this.data

XIOC detected Domain: this.data

extracted_from_files

Domain
detected Domain: w.next

XIOC detected Domain: w.next

extracted_from_files

Domain
detected Domain: i.target

XIOC detected Domain: i.target

extracted_from_files

Domain
detected Domain: p.call

XIOC detected Domain: p.call

extracted_from_files

Domain
detected Domain: this.cx

XIOC detected Domain: this.cx

extracted_from_files

Domain
detected Domain: this.cy

XIOC detected Domain: this.cy

extracted_from_files

Domain
detected Domain: t.cx

XIOC detected Domain: t.cx

extracted_from_files

Domain
detected Domain: date.now

XIOC detected Domain: date.now

extracted_from_files

Domain
detected Domain: i.data

XIOC detected Domain: i.data

extracted_from_files

Domain
detected Domain: w.energy

XIOC detected Domain: w.energy

extracted_from_files

Domain
detected Domain: e.energy

XIOC detected Domain: e.energy

extracted_from_files

Domain
detected Domain: a.energy

XIOC detected Domain: a.energy

extracted_from_files

Domain
detected Domain: this.target

XIOC detected Domain: this.target

extracted_from_files

Domain
detected Domain: a.data

XIOC detected Domain: a.data

extracted_from_files

Domain
detected Domain: e.at

XIOC detected Domain: e.at

extracted_from_files

Domain
detected Domain: this.currentws.open

XIOC detected Domain: this.currentws.open

extracted_from_files

Domain
detected Domain: l.ac

XIOC detected Domain: l.ac

extracted_from_files

Domain
detected Domain: e.open

XIOC detected Domain: e.open

extracted_from_files

Domain
detected Domain: n.open

XIOC detected Domain: n.open

extracted_from_files

Hash
detected SHA256 Hash: ad1b033f4885a8bc3ae4f055f591a79c59ce73a6a7380b00c4fcb75ac3eefffb

XIOC detected SHA256 Hash: ad1b033f4885a8bc3ae4f055f591a79c59ce73a6a7380b00c4fcb75ac3eefffb

extracted_from_files

Domain
detected Domain: r.now

XIOC detected Domain: r.now

extracted_from_files

Domain
detected Domain: e.call

XIOC detected Domain: e.call

extracted_from_files

Domain
detected Domain: i.id

XIOC detected Domain: i.id

extracted_from_files

Domain
detected Domain: n.post

XIOC detected Domain: n.post

extracted_from_files

Domain
detected Domain: r.call

XIOC detected Domain: r.call

extracted_from_files

Domain
detected Domain: this.post

XIOC detected Domain: this.post

extracted_from_files

Domain
detected Domain: socket.io

XIOC detected Domain: socket.io

extracted_from_files

Domain
detected Domain: t.map

XIOC detected Domain: t.map

extracted_from_files

Domain
detected Domain: o.click

XIOC detected Domain: o.click

extracted_from_files

Domain
detected Domain: e.endpoint.post

XIOC detected Domain: e.endpoint.post

extracted_from_files

Domain
detected Domain: r.menu

XIOC detected Domain: r.menu

extracted_from_files

Domain
detected Domain: d.gallery

XIOC detected Domain: d.gallery

extracted_from_files

Domain
detected Domain: r.data

XIOC detected Domain: r.data

extracted_from_files

Domain
detected Domain: github.com

XIOC detected Domain: github.com

extracted_from_files

Domain
detected Domain: ns.adobe.com

XIOC detected Domain: ns.adobe.com

extracted_from_files

Domain
detected Domain: e.post

XIOC detected Domain: e.post

extracted_from_files

Domain
detected Domain: e.id

XIOC detected Domain: e.id

extracted_from_files

Domain
detected Domain: t.target

XIOC detected Domain: t.target

extracted_from_files

Domain
detected Domain: r.previous.data

XIOC detected Domain: r.previous.data

extracted_from_files

Domain
detected Domain: f.click

XIOC detected Domain: f.click

extracted_from_files

Domain
detected Domain: f.download

XIOC detected Domain: f.download

extracted_from_files

Domain
detected Domain: r.click

XIOC detected Domain: r.click

extracted_from_files

Domain
detected Domain: n.name

XIOC detected Domain: n.name

extracted_from_files

Domain
detected Domain: y.download

XIOC detected Domain: y.download

extracted_from_files

Domain
detected Domain: y.click

XIOC detected Domain: y.click

extracted_from_files

Domain
detected Domain: e.activedrawing.inwindow.element.style.top

XIOC detected Domain: e.activedrawing.inwindow.element.style.top

extracted_from_files

Domain
detected Domain: e.name

XIOC detected Domain: e.name

extracted_from_files

Domain
detected Domain: h.post

XIOC detected Domain: h.post

extracted_from_files

Domain
detected Domain: o.data

XIOC detected Domain: o.data

extracted_from_files

Domain
detected Domain: u.top

XIOC detected Domain: u.top

extracted_from_files

Domain
detected Domain: garticphone.com

XIOC detected Domain: garticphone.com

extracted_from_files

Domain
detected Domain: e.click

XIOC detected Domain: e.click

extracted_from_files

Domain
detected Domain: t.bg

XIOC detected Domain: t.bg

extracted_from_files

Domain
detected Domain: beta.garticphone.com

XIOC detected Domain: beta.garticphone.com

extracted_from_files

Domain
detected Domain: e.detail.data

XIOC detected Domain: e.detail.data

extracted_from_files

Domain
detected Domain: this.bg

XIOC detected Domain: this.bg

extracted_from_files

Domain
detected Domain: t.next

XIOC detected Domain: t.next

extracted_from_files

Domain
detected Domain: this.setting.next

XIOC detected Domain: this.setting.next

extracted_from_files

Domain
detected Domain: t.refimage.style.top

XIOC detected Domain: t.refimage.style.top

extracted_from_files

Domain
detected Domain: t.name

XIOC detected Domain: t.name

extracted_from_files

Domain
detected Domain: i.clienty-t.top

XIOC detected Domain: i.clienty-t.top

extracted_from_files

Domain
detected Domain: e.style.top

XIOC detected Domain: e.style.top

extracted_from_files

Domain
detected Domain: n.style.top

XIOC detected Domain: n.style.top

extracted_from_files

Domain
detected Domain: hasownproperty.call

XIOC detected Domain: hasownproperty.call

extracted_from_files

Domain
detected Domain: o.get.call

XIOC detected Domain: o.get.call

extracted_from_files

Domain
detected Domain: n.data

XIOC detected Domain: n.data

extracted_from_files

Domain
detected Domain: this.endpoint.post

XIOC detected Domain: this.endpoint.post

extracted_from_files

Domain
detected Domain: c.data

XIOC detected Domain: c.data

extracted_from_files

Domain
detected Domain: this.name

XIOC detected Domain: this.name

extracted_from_files

Domain
detected Domain: r.name

XIOC detected Domain: r.name

extracted_from_files

Domain
detected Domain: e.off

XIOC detected Domain: e.off

extracted_from_files

Domain
detected Domain: e.red

XIOC detected Domain: e.red

extracted_from_files

Domain
detected Domain: we.off

XIOC detected Domain: we.off

extracted_from_files

Domain
detected Domain: this.storage

XIOC detected Domain: this.storage

extracted_from_files

Domain
detected Domain: n.style

XIOC detected Domain: n.style

extracted_from_files

Domain
detected Domain: we.red

XIOC detected Domain: we.red

extracted_from_files

Domain
detected Domain: i.click

XIOC detected Domain: i.click

extracted_from_files

Domain
detected Domain: z.seven

XIOC detected Domain: z.seven

extracted_from_files

Domain
detected Domain: i.call

XIOC detected Domain: i.call

extracted_from_files

Domain
detected Domain: e.style

XIOC detected Domain: e.style

extracted_from_files

Domain
detected Domain: n.next

XIOC detected Domain: n.next

extracted_from_files

Domain
detected Domain: f.style.top

XIOC detected Domain: f.style.top

extracted_from_files

Domain
detected Domain: u.position.top

XIOC detected Domain: u.position.top

extracted_from_files

Domain
detected Domain: e.ac

XIOC detected Domain: e.ac

extracted_from_files

Domain
detected Domain: l.tm

XIOC detected Domain: l.tm

extracted_from_files

Domain
detected Domain: loading.io

XIOC detected Domain: loading.io

extracted_from_files

Domain
detected Domain: g.by

XIOC detected Domain: g.by

extracted_from_files

Domain
detected Domain: m.host

XIOC detected Domain: m.host

extracted_from_files

Domain
detected Domain: m.progressive

XIOC detected Domain: m.progressive

extracted_from_files

Domain
detected Domain: n.coop

XIOC detected Domain: n.coop

extracted_from_files

Domain
detected Domain: z.one

XIOC detected Domain: z.one

extracted_from_files

Domain
detected Domain: e.gallery

XIOC detected Domain: e.gallery

extracted_from_files

Domain
detected Domain: e.coop

XIOC detected Domain: e.coop

extracted_from_files

Domain
detected Domain: e.fast

XIOC detected Domain: e.fast

extracted_from_files

Domain
detected Domain: e.progressive

XIOC detected Domain: e.progressive

extracted_from_files

Domain
detected Domain: e.host

XIOC detected Domain: e.host

extracted_from_files

Domain
detected Domain: e.one

XIOC detected Domain: e.one

extracted_from_files

Domain
detected Domain: e.seven

XIOC detected Domain: e.seven

extracted_from_files

Domain
detected Domain: t.data.data

XIOC detected Domain: t.data.data

extracted_from_files

Domain
detected Domain: t.post

XIOC detected Domain: t.post

extracted_from_files

Domain
detected Domain: tostring.call

XIOC detected Domain: tostring.call

extracted_from_files

Domain
detected Domain: e.constructor.name

XIOC detected Domain: e.constructor.name

extracted_from_files

Domain
detected Domain: e.data

XIOC detected Domain: e.data

extracted_from_files

Domain
detected Domain: t.data

XIOC detected Domain: t.data

extracted_from_files

Domain
detected Domain: r.map

XIOC detected Domain: r.map

extracted_from_files

Domain
detected Domain: h.ac

XIOC detected Domain: h.ac

extracted_from_files

Domain
detected Domain: e.map

XIOC detected Domain: e.map

extracted_from_files

Domain
detected Domain: object.prototype.hasownproperty.call

XIOC detected Domain: object.prototype.hasownproperty.call

extracted_from_files

Domain
detected Domain: t.call

XIOC detected Domain: t.call

extracted_from_files

Domain
detected Domain: function.tostring.call

XIOC detected Domain: function.tostring.call

extracted_from_files

Domain
detected Domain: boolean.prototype.valueof.call

XIOC detected Domain: boolean.prototype.valueof.call

extracted_from_files

Domain
detected Domain: n.call

XIOC detected Domain: n.call

extracted_from_files

Domain
detected Domain: gist.githubusercontent.com

XIOC detected Domain: gist.githubusercontent.com

extracted_from_files

Domain
detected Domain: i.ac

XIOC detected Domain: i.ac

extracted_from_files

Domain
detected Domain: n.ac

XIOC detected Domain: n.ac

extracted_from_files

Domain
detected Domain: s.ac

XIOC detected Domain: s.ac

extracted_from_files

Domain
detected Domain: c.style.top

XIOC detected Domain: c.style.top

extracted_from_files

Domain
detected Domain: e.by

XIOC detected Domain: e.by

extracted_from_files

Domain
detected Domain: this.globalgamestate.host

XIOC detected Domain: this.globalgamestate.host

extracted_from_files

Security Analysis Summary

Security Analysis Overview

Gartic Cellulart for Gartic Phone is a Chrome Web Store extension published by [email protected]. Version 1.7.7 has been analyzed by the Risky Plugins security platform, receiving a risk score of 63/100 (MEDIUM risk) based on 164 security findings.

Risk Assessment

This extension presents high security risk. Significant concerns were identified during analysis. It is not recommended for use in sensitive or production environments without thorough review.

Findings Breakdown

  • High: 1 finding(s)
  • Medium: 139 finding(s)
  • Low: 24 finding(s)

What Was Analyzed

The security assessment covers multiple analysis categories:

  • Malware Detection: YARA rule matching against 2,400+ malware signatures
  • Secret Detection: Scanning for exposed API keys, tokens, and credentials
  • Static Analysis: Code-level security analysis for common vulnerability patterns
  • Network Analysis: Detection of suspicious network communications and endpoints
  • Obfuscation Detection: Identification of code obfuscation techniques

Developer Information

Gartic Cellulart for Gartic Phone is published by [email protected] on the Chrome Web Store marketplace. The extension has approximately 1K users.

Recommendation

This extension is not recommended for installation without thorough manual review. Consider alternatives with lower risk scores, or contact the developer to address the identified security concerns.

Frequently Asked Questions