Chrome Web Store

Unique Triangle Hunt Game

by [email protected] · 211 users · 5.0 rating
08353129-0901-5618-acdd-22c63b31ecb0 | v0.1.8
44/ 100
MEDIUM risk
No change since v0.1.7
Analyst verdict
Review before use

The AI review rates the findings as likely false positive, but the risk score (44/100) still counts them.

Analysis record

Analysed
2 months ago
Version
v0.1.8
Artifact
SHA256 6F6…AED
Source
Findings (non-IoC)

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

4 detail rows

Publisher Evidence

Limited evidence

[email protected]

Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.

Chrome does not expose the same publisher verification data as IDE stores, so this score is deliberately conservative.

39
Noisy-finding weight
x1.00
Publisher domain
No domain
Missing
Store verification signal
Limited signal
Limited
Extension portfolio
61
Portfolio

12 evidence rows available.

Finding Categories

4
Network

Requested Permissions

1 permission
storage
Low

AI Security Report

AI Security Review

Evidence context: threat category none; evidence quality moderate.

This extension, 'Unique Triangle Hunt Game', demonstrates no indicators of malicious activity despite 37 total findings. The evidence reveals a simple browser game with benign network behavior.

IoC Analysis: All 21 IoC findings are from known false positive patterns. The XIOC-DOMAIN-event.target finding is a JavaScript property access chain misidentified as a domain, not actual network traffic. The clients2.google.com and https://clients2.google.com/service/update2/crx findings reference Google's Chrome update service, standard for all Chrome extensions. The https://cdn.gameforbreak.com/feeds/chrome/ URLs are the extension's own CDN domain, not suspicious third-party infrastructure. The Adobe namespace URL (http://ns.adobe.com/exif/1.0/) and Google Analytics documentation URLs are embedded references, not active connections.

Network Analysis: The 4 network findings show standard fetch calls: js/script.js:207 and js/script.js:244 make generic fetch requests, while js/google-analytics.js:73 connects to Google Analytics for tracking. These are expected behaviors for a browser game extension.

Code Analysis: The 12 code-smell findings are classified as low severity and represent known noise patterns (postinstall_*, credential_*, code-quality rules) that match basic JavaScript patterns. There are zero malware signatures, zero obfuscation findings, and zero credential theft indicators.

Counterargument: A skeptic might point to the anonymous developer ([email protected]) and 284 users as concerning. However, anonymous publishers are common for small game extensions, and user count alone does not indicate safety or danger. The critical factor is the nature of findings, not their volume. None of the 37 findings demonstrate actual malicious behavior—no custom search engines, no credential access to login domains, no obfuscated payloads, no malware signatures, and no suspicious third-party domains. The evidence quality is moderate but sufficient to conclude these are false positives from the XIOC extractor and YARA code-smell rules.

Conclusion: This extension is a legitimate browser game with findings driven entirely by known false positive patterns.

Key Reasons

  • Zero malware signatures and zero obfuscation findings
  • All IoCs are Google infrastructure or extension's own CDN
  • XIOC-DOMAIN-event.target is a property access false positive
  • Network findings show only standard fetch calls to Google Analytics
  • Code-smell findings are known noise per CVEQ documentation

False Positive Considerations

  • XIOC property access false positives (event.target)
  • Google infrastructure domains (clients2.google.com)
  • Code-smell findings (low severity, known noise)
  • Extension's own CDN domain flagged as IoC

Reviewed 2026-04-28; recommended action: suppress false positive; model confidence 85%.

Chrome version history

Risk trend by version

3 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.

Selected
44
Change since first
-7
Change from previous
No change
Versions:
First analyzed version
0.1.5
Feb 1, 2026
Risk range
44 to 50
Across analyzed versions
Latest analyzed version
0.1.8
Jul 31, 2026
Selected version
medium
Version
v0.1.8
2 months ago
Risk score
44
Findings
4
Change vs previous
No change

Pick any point on the chart to explore that version's code below.

About This Extension

This triangle hunt game is a fun and challenging way to test how well you notice details when you're in a hurry. The goal is to find the one unique triangle in a 3x3 grid within 100 seconds. Eight of these triangles are identical, but one is different and marked uniquely. To increase game difficulty, each triangle is rotated randomly, with a black line beneath it indicating its orientation. How to Play: 1. Just click on the extension icon in the browser, you'll be presented with a grid of nine triangles and a section at the top showing your points and time left. 2. Click on the one you think is different. It will light up red. 3. If you're right, you get 5 points and automatically move to the next round. If you're wrong, keep guessing by clicking on another triangle. 4. You can keep playing to get as many points as you can until the time runs out. Tips to Win: - In your quick review of the grid, focus more on any triangle that noticeably differs from the rest in triangle area. - Find the right mix of quickness and precision to boost your score the most. Good luck and enjoy the game! Plus, we've featured our other exciting game extensions after the game ends for even more fun! CHANGELOG ========== Version 0.1.1 - 0.1.8 - Add google analytics - Show featured games after game over - Dynamic update of featured game list - Prettify code and styles Version 0.1.0 - Initial release of game

Frequently Asked Questions