QuizShot – AI Math Solver, Homework Helper & Study Assistant Tutor
The AI review rates the findings as likely false positive, but the risk score (68/100) still counts them.
Analysis record
- Analysed
- 6 months ago
- Version
- v1.0.6
- Artifact
- SHA256 3BF…372
- Source
- Findings (non-IoC)
Evidence ledger
Ranked by severity · findings with a source location link to the code viewer
YARA Rule Matches
20 rules| Severity | Rule | Hits | Files | Metadata |
|---|---|---|---|---|
| LOW | postinstall obfuscation | 7 | onboarding.jssrc/content-scripts/inject.jsassets/lodash-CENC7AxJ.js +4 more | - |
| LOW | postinstall crypto operations | 8 | src/content-scripts/inject.jsassets/core-BVhkoKEc.jsonboarding.js +5 more | - |
| LOW | postinstall file manipulation | 8 | src/content-scripts/inject.jsassets/background.ts-CqgA4Ha3.jsassets/lodash-CENC7AxJ.js +5 more | - |
| LOW | postinstall environment access | 4 | assets/core-Bi3GsuN1.jsonboarding.jsassets/sidepanel.html-DimldSYa.js +1 more | - |
| LOW | postinstall system command | 11 | assets/sidepanel.html-DimldSYa.jssrc/content-scripts/inject.jsonboarding.js +8 more | - |
| LOW | postinstall registry modification | 2 | assets/client-nIXsMTUk.jsassets/sidepanel.html-DimldSYa.js | - |
| LOW | postinstall network communication | 9 | src/content-scripts/inject.jsassets/sidepanel.html-DimldSYa.jssidepanel.html +6 more | - |
| LOW | OriginsNotVerified | 2 | assets/client-nIXsMTUk.jsassets/sidepanel.html-DimldSYa.js | - |
| LOW | LocalStorageShouldNotBeUsed | 2 | assets/client-nIXsMTUk.jsassets/sidepanel.html-DimldSYa.js | - |
| LOW | DebuggerStatementsShouldNotBeUsed | 2 | assets/client-nIXsMTUk.jsassets/sidepanel.html-DimldSYa.js | - |
| LOW | ScarhiknStrings | 2 | assets/client-nIXsMTUk.jsassets/sidepanel.html-DimldSYa.js | - |
| LOW | credential metamask extension | 1 | assets/background.ts-CqgA4Ha3.js | - |
| LOW | NoUseEval | 2 | assets/client-nIXsMTUk.jsassets/sidepanel.html-DimldSYa.js | - |
| LOW | postinstall file download | 8 | assets/client-nIXsMTUk.jsonboarding.jssrc/content-scripts/inject.js +5 more | - |
| LOW | UntrustedContentShouldNotBeIncluded | 1 | assets/client-nIXsMTUk.js | - |
| LOW | SQLInjection | 2 | assets/client-nIXsMTUk.jsassets/sidepanel.html-DimldSYa.js | - |
| LOW | NoUseWeakRandom | 6 | assets/client-nIXsMTUk.jsonboarding.jssrc/content-scripts/inject.js +3 more | - |
| LOW | credential env files | 3 | assets/client-nIXsMTUk.jsonboarding.jsassets/sidepanel.html-DimldSYa.js | - |
| LOW | Cerberus | 2 | assets/client-nIXsMTUk.jsassets/sidepanel.html-DimldSYa.js | - |
| LOW | postinstall persistence mechanism | 5 | assets/client-nIXsMTUk.jsonboarding.jssrc/content-scripts/inject.js +2 more | - |
Network Indicators
Concrete URLs, domains, IPs, emails, and hashes extracted from the analyzed artifact.
Network indicators are queued for lazy loading
Scroll this section into view to load the detailed rows.
Publisher Evidence
Limited evidencePublisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.
Chrome does not expose the same publisher verification data as IDE stores, so this score is deliberately conservative.
11 evidence rows available.
Finding Categories
YARA Rules Matched
20 rules(87 hits)Requested Permissions
9 permissionsAccess and modify data on every website you visit
Read and modify cookies on all sites
AI Security Report
AI Security Review
Risky Plugins reviewed this extension with an AI-assisted security workflow on 2026-04-27. The review verdict is likely false positive with 85% confidence.
Recommended action: suppress false positive. Evidence context: threat category none; evidence quality moderate.
The QuizShot extension shows 2389 total findings, but the nature of these findings indicates systematic false positives rather than actual malicious behavior. The 2284 IoC findings include classic XIOC extractor garbage: property access chains misidentified as domains (me.call, rt.call in the IoC list), and extremely short generic strings (o.th, u.tr, h.ba, m.ax) that are characteristic of hex substrings from minified JavaScript being misread as TLDs.
Zero malware signatures were detected in any file. The single obfuscation finding is insufficient to indicate malicious intent without corroborating evidence. The 87 code-smell findings fall into the documented noise category—rules like postinstall_*, credential_*, and code-quality checks that fire on almost any non-trivial JavaScript. The 16 network findings lack specific suspicious domains in the provided evidence.
The developer attribution uses an email address ([email protected]) rather than a company name, which is a minor trust signal but not inherently suspicious. The extension's stated purpose (AI math solver and homework helper) aligns with its name and description. The 17 user count indicates this is a new or niche extension, not a widely deployed threat.
The strongest counterargument would be the sheer volume of 2284 IoC findings, which might suggest hidden malicious infrastructure. However, the CVEQ platform's own documentation confirms that IoC COUNT alone is meaningless and that the XIOC extractor produces massive false-positive volumes from property access chains and minified code artifacts. The specific domains listed (me.call, rt.call) are textbook examples of this known false-positive pattern. Without malware signatures, without specific suspicious domains (like custom search engines, credential harvesting endpoints, or known C2 infrastructure), and with the finding profile matching documented false-positive patterns, the high count reflects extraction noise rather than actual threat indicators.
Key Reasons
- Zero malware signatures detected across all files
- IoC findings match known XIOC false-positive patterns (property access chains like me.call, rt.call)
- Generic short domains (o.th, u.tr, h.ba) are characteristic of hex substring misreads from minified code
- Code-smell findings (87) are documented noise for non-trivial JavaScript
- Extension category matches stated functionality with no behavioral mismatch
False Positive Considerations
- XIOC property access chain misreads (me.call, rt.call)
- Minified JavaScript hex substrings misidentified as domains
- Code-smell YARA rules firing on standard patterns
- IoC volume inflation from bundled code extraction
Source Code Not Available
Source code is not available for this version of the extension.
About This Extension
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace
Edge Translate - Text Selection Translation
[email protected]
Canvas Zero - Canvas quizzes Assistant
[email protected]
Pinora – Pinterest Board Pins Images Downloader
[email protected]
Quiz Boost AI - Smart Test Assistant, Exam Helper & Homework Quiz Solver
[email protected]
No Distract - Hide YouTube, Facebook, Reddit, Twitter Feeds
[email protected]
SideGPT - Free Access ChatGPT sidebar
[email protected]