Is "Star Citizen Bulk XPLORer (Dwayde's mod)" on Chrome Web Store Safe to Install?

[email protected] · chrome · v6.6

# Star Citizen BulkXPLOR modified This project aims to add Bulk Melting and Gifting functionality to the [HangarXPLOR] plugin. It helps to improve the default Hangar page at https://robertsspaceindustries.com/account/pledges. WARNING: This plugin has been split off from the original HangarXPLOR, as it adds functionality which requires your password to work. As such, this plugin WILL ask for your password, when you are melting or gifting ships, but at no stage is this password ever stored, or sent to any non-RSI websites. Current features include: * Add bulk Melt button * Add bulk Gift button # Installation Instructions This plugin will only work if [HangarXPLOR](https://chromewebstore.google.com/detail/star-citizen-hangar-xplor/hmiiohicemghafoicmmlfklnngmcinnm) is already installed. # Source code https://github.com/Dwayde/StarCitizen-HangarXPLOR-Bulk # Modified * This is modified version by /u/Dwayde_Wade. * If you have any problems/issues please feel free to contact me. (Discord - dwaydewade, reddit - /u/Dwayde_Wade) * Also you can ask for new features. # Changes * UI and design fixes (Melting window, melting results) * Fully functional bulk gifting with UI # Support * Referral code in case you need that for registration: STAR-V5T3-P2HR * If you like extension and want support me, here is donation link: https://www.paypal.com/donate/?hosted_button_id=FE4Z7JYPRN2DN

Risk Assessment

Analyzed
60.9
out of 100
MEDIUM

54 security findings detected across all analyzers

Chrome extension requesting 1 permission

Severity Breakdown

0
Critical
0
High
50
Medium
4
Low
0
Info

Finding Categories

2
Network
48
IoC Indicators

YARA Rules Matched

3 rules(4 hits)
postinstall file manipulation postinstall crypto operations postinstall network communication

Requested Permissions

1 permission
https://robertsspaceindustries.com/*
Low

About This Extension

# Star Citizen BulkXPLOR modified This project aims to add Bulk Melting and Gifting functionality to the [HangarXPLOR] plugin. It helps to improve the default Hangar page at https://robertsspaceindustries.com/account/pledges. WARNING: This plugin has been split off from the original HangarXPLOR, as it adds functionality which requires your password to work. As such, this plugin WILL ask for your password, when you are melting or gifting ships, but at no stage is this password ever stored, or sent to any non-RSI websites. Current features include: * Add bulk Melt button * Add bulk Gift button # Installation Instructions This plugin will only work if [HangarXPLOR](https://chromewebstore.google.com/detail/star-citizen-hangar-xplor/hmiiohicemghafoicmmlfklnngmcinnm) is already installed. # Source code https://github.com/Dwayde/StarCitizen-HangarXPLOR-Bulk # Modified * This is modified version by /u/Dwayde_Wade. * If you have any problems/issues please feel free to contact me. (Discord - dwaydewade, reddit - /u/Dwayde_Wade) * Also you can ask for new features. # Changes * UI and design fixes (Melting window, melting results) * Fully functional bulk gifting with UI # Support * Referral code in case you need that for registration: STAR-V5T3-P2HR * If you like extension and want support me, here is donation link: https://www.paypal.com/donate/?hosted_button_id=FE4Z7JYPRN2DN

Detailed Findings

6 total

YARA Rule Matches

3 rules

Indicators of Compromise

Network indicators, suspicious strings, and potential IoCs extracted during analysis

URLs
14
IP Addresses
1
Domains
18
Strings
48

All Indicators · 48

Domain
detected Domain: 1rp.ac

XIOC detected Domain: 1rp.ac

extracted_from_files

Domain
detected Domain: robertsspaceindustries.com

XIOC detected Domain: robertsspaceindustries.com

extracted_from_files

Hash
detected MD5 Hash: 6D70473630BB11E69610DD5CD163389F

XIOC detected MD5 Hash: 6D70473630BB11E69610DD5CD163389F

extracted_from_files

Hash
detected MD5 Hash: 2E3C7A8530BA11E6B0CFD09DD83AC928

XIOC detected MD5 Hash: 2E3C7A8530BA11E6B0CFD09DD83AC928

extracted_from_files

Hash
detected MD5 Hash: 2E3C7A8630BA11E6B0CFD09DD83AC928

XIOC detected MD5 Hash: 2E3C7A8630BA11E6B0CFD09DD83AC928

extracted_from_files

Hash
detected MD5 Hash: 2E3C7A8330BA11E6B0CFD09DD83AC928

XIOC detected MD5 Hash: 2E3C7A8330BA11E6B0CFD09DD83AC928

extracted_from_files

Hash
detected MD5 Hash: 2E3C7A8430BA11E6B0CFD09DD83AC928

XIOC detected MD5 Hash: 2E3C7A8430BA11E6B0CFD09DD83AC928

extracted_from_files

Hash
detected MD5 Hash: 7A8FD87A30BB11E6BD4CC53A3576E6A8

XIOC detected MD5 Hash: 7A8FD87A30BB11E6BD4CC53A3576E6A8

extracted_from_files

Hash
detected MD5 Hash: 7A8FD87B30BB11E6BD4CC53A3576E6A8

XIOC detected MD5 Hash: 7A8FD87B30BB11E6BD4CC53A3576E6A8

extracted_from_files

Hash
detected MD5 Hash: 7A8FD87830BB11E6BD4CC53A3576E6A8

XIOC detected MD5 Hash: 7A8FD87830BB11E6BD4CC53A3576E6A8

extracted_from_files

Hash
detected MD5 Hash: 7A8FD87930BB11E6BD4CC53A3576E6A8

XIOC detected MD5 Hash: 7A8FD87930BB11E6BD4CC53A3576E6A8

extracted_from_files

Hash
detected MD5 Hash: 6D70473730BB11E69610DD5CD163389F

XIOC detected MD5 Hash: 6D70473730BB11E69610DD5CD163389F

extracted_from_files

Domain
detected Domain: ns.adobe.com

XIOC detected Domain: ns.adobe.com

extracted_from_files

Hash
detected MD5 Hash: 6D70473530BB11E69610DD5CD163389F

XIOC detected MD5 Hash: 6D70473530BB11E69610DD5CD163389F

extracted_from_files

URL
detected URL: https://cdn.robertsspaceindustries.com/static/images/error/access_denied_hand.png)

XIOC detected URL: https://cdn.robertsspaceindustries.com/static/images/error/access_denied_hand.png)

extracted_from_files

URL
detected URL: https://cdn.robertsspaceindustries.com/static/images/error/access_denied_exagon.png)

XIOC detected URL: https://cdn.robertsspaceindustries.com/static/images/error/access_denied_exagon.png)

extracted_from_files

URL
detected URL: https://cdn.robertsspaceindustries.com/static/images/common/shadow_btn.png

XIOC detected URL: https://cdn.robertsspaceindustries.com/static/images/common/shadow_btn.png

extracted_from_files

Hash
detected MD5 Hash: E9987D1230BC11E6AC49A7715561039E

XIOC detected MD5 Hash: E9987D1230BC11E6AC49A7715561039E

extracted_from_files

Hash
detected MD5 Hash: E9987D1330BC11E6AC49A7715561039E

XIOC detected MD5 Hash: E9987D1330BC11E6AC49A7715561039E

extracted_from_files

Hash
detected MD5 Hash: E9987D1030BC11E6AC49A7715561039E

XIOC detected MD5 Hash: E9987D1030BC11E6AC49A7715561039E

extracted_from_files

Hash
detected MD5 Hash: E9987D1130BC11E6AC49A7715561039E

XIOC detected MD5 Hash: E9987D1130BC11E6AC49A7715561039E

extracted_from_files

URL
detected URL: https://robertsspaceindustries.com/*

XIOC detected URL: https://robertsspaceindustries.com/*

extracted_from_files

URL
detected URL: https://robertsspaceindustries.com/account/pledges*

XIOC detected URL: https://robertsspaceindustries.com/account/pledges*

extracted_from_files

URL
detected URL: https://www.robertsspaceindustries.com/account/pledges*

XIOC detected URL: https://www.robertsspaceindustries.com/account/pledges*

extracted_from_files

URL
detected URL: https://robertsspaceindustries.com/*/account/pledges*

XIOC detected URL: https://robertsspaceindustries.com/*/account/pledges*

extracted_from_files

URL
detected URL: https://www.robertsspaceindustries.com/*/account/pledges*

XIOC detected URL: https://www.robertsspaceindustries.com/*/account/pledges*

extracted_from_files

URL
detected URL: https://cdn.robertsspaceindustries.com/static/images/signin_modal_error.png)

XIOC detected URL: https://cdn.robertsspaceindustries.com/static/images/signin_modal_error.png)

extracted_from_files

URL
detected URL: https://cdn.robertsspaceindustries.com/static/images/signin_modal_success.png)

XIOC detected URL: https://cdn.robertsspaceindustries.com/static/images/signin_modal_success.png)

extracted_from_files

Domain
detected Domain: w.li

XIOC detected Domain: w.li

extracted_from_files

Domain
detected Domain: cdn.robertsspaceindustries.com

XIOC detected Domain: cdn.robertsspaceindustries.com

extracted_from_files

Domain
detected Domain: callbacks.gift

XIOC detected Domain: callbacks.gift

extracted_from_files

URL
detected URL: https://robertsspaceindustries.com/account/pledges.

XIOC detected URL: https://robertsspaceindustries.com/account/pledges.

extracted_from_files

URL
detected URL: https://github.com/Dwayde/StarCitizen-HangarXPLOR)

XIOC detected URL: https://github.com/Dwayde/StarCitizen-HangarXPLOR)

extracted_from_files

URL
detected URL: https://www.paypal.com/donate/?hosted_button_id=FE4Z7JYPRN2DN

XIOC detected URL: https://www.paypal.com/donate/?hosted_button_id=FE4Z7JYPRN2DN

extracted_from_files

URL
detected URL: https://clients2.google.com/service/update2/crx

XIOC detected URL: https://clients2.google.com/service/update2/crx

extracted_from_files

Domain
detected Domain: m9.tm

XIOC detected Domain: m9.tm

extracted_from_files

Hash
detected MD5 Hash: 6D70473830BB11E69610DD5CD163389F

XIOC detected MD5 Hash: 6D70473830BB11E69610DD5CD163389F

extracted_from_files

Domain
detected Domain: www.robertsspaceindustries.com

XIOC detected Domain: www.robertsspaceindustries.com

extracted_from_files

Domain
detected Domain: j.ma

XIOC detected Domain: j.ma

extracted_from_files

Domain
detected Domain: nv.ups

XIOC detected Domain: nv.ups

extracted_from_files

Domain
detected Domain: g.ge

XIOC detected Domain: g.ge

extracted_from_files

Domain
detected Domain: en.bz

XIOC detected Domain: en.bz

extracted_from_files

Domain
detected Domain: github.com

XIOC detected Domain: github.com

extracted_from_files

Domain
detected Domain: www.paypal.com

XIOC detected Domain: www.paypal.com

extracted_from_files

Domain
detected Domain: style.id

XIOC detected Domain: style.id

extracted_from_files

IP
detected Domain: script.id

XIOC detected Domain: script.id

extracted_from_files

Domain
detected Domain: l.si

XIOC detected Domain: l.si

extracted_from_files

Domain
detected Domain: 0.gu

XIOC detected Domain: 0.gu

extracted_from_files

Security Analysis Summary

Security Analysis Overview

Star Citizen Bulk XPLORer (Dwayde's mod) is a Chrome Web Store extension published by [email protected]. Version 6.6 has been analyzed by the Risky Plugins security platform, receiving a risk score of 60.9/100 (MEDIUM risk) based on 54 security findings.

Risk Assessment

This extension presents high security risk. Significant concerns were identified during analysis. It is not recommended for use in sensitive or production environments without thorough review.

Findings Breakdown

  • Medium: 50 finding(s)
  • Low: 4 finding(s)

What Was Analyzed

The security assessment covers multiple analysis categories:

  • Malware Detection: YARA rule matching against 2,400+ malware signatures
  • Secret Detection: Scanning for exposed API keys, tokens, and credentials
  • Static Analysis: Code-level security analysis for common vulnerability patterns
  • Network Analysis: Detection of suspicious network communications and endpoints
  • Obfuscation Detection: Identification of code obfuscation techniques

Developer Information

Star Citizen Bulk XPLORer (Dwayde's mod) is published by [email protected] on the Chrome Web Store marketplace. The extension has approximately 120 users.

Recommendation

This extension is not recommended for installation without thorough manual review. Consider alternatives with lower risk scores, or contact the developer to address the identified security concerns.

Frequently Asked Questions