randstad_poc
Based on the RiskyPlugins AI security review of the observed evidence.
Analysis record
- Analysed
- 9 months ago
- Version
- v2022.6.21.1026
- Artifact
- SHA256 1A2…A84
- Source
- Findings (non-IoC)
No Findings
All security checks passed
Publisher Evidence
Limited evidencePublisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.
Chrome does not expose the same publisher verification data as IDE stores, so this score is deliberately conservative.
12 evidence rows available.
No Threats Detected
This extension passed all security checks
AI Security Report
AI Security Review
Risky Plugins reviewed this extension with an AI-assisted security workflow on 2026-05-09. The review verdict is likely false positive with 75% confidence.
Recommended action: suppress false positive. Evidence context: threat category none; evidence quality strong.
This extension named "randstad_poc" is published by [email protected] with a description stating it provides "in-app interactive guides and walkthroughs." The network findings exclusively reference whatfix.com domains: whatfix.com/6f75c0b0-c0be-11ec-8265-000d3a1efee9/widget/widget.nocache.js (lines 2785, 2801, 3038), whatfix.com/6f75c0b0-c0be-11ec-8265-000d3a1efee9/embed/711B885AD03BD3091F7C057FE247FAF0.cache.js (line 6671), and whatfix.com/6f75c0b0-c0be-11ec-8265-000d3a1efee9/blogs/blogs.nocache.js (line 2279). These are legitimate service endpoints for the Whatfix platform, not suspicious third-party domains.
The 2796 IoC findings represent known false-positive noise from the XIOC extractor. The evidence shows zero malware signatures and zero malware findings in the findings_summary. The obfuscation findings—OBFUSCATION-LARGE_BASE64 in files like tasker/tasker.nocache.js:2688, end/end.nocache.js:2468, and deck/deck.nocache.js:2552—are typical of bundled JavaScript frameworks that embed assets as base64 strings, not malicious obfuscation. The 310 code-smell findings are classified as low-severity noise per the CVEQ false-positive patterns documentation.
The extension's unusual name "randstad_poc" suggests this is a proof-of-concept or enterprise custom build rather than a public-facing extension, which explains the minimal user count of 3. This is consistent with internal deployments of the Whatfix platform.
A skeptic might argue that the combination of obfuscation patterns and high finding counts warrants concern. However, the evidence shows no malware signatures, no suspicious external domains beyond whatfix.com, and the developer email ([email protected]) matches the network destinations. The base64 patterns in .nocache.js files are standard bundling artifacts, not steganographic hiding. Without actual malware signatures or credential-theft indicators, the high finding count is noise from known CVEQ FP patterns.
Key Reasons
- Zero malware signatures and zero malware findings in evidence
- All network activity targets legitimate whatfix.com domains matching developer attribution
- High IoC count (2796) is known XIOC extractor noise with no specific suspicious domains
- Base64 obfuscation patterns are standard bundling artifacts in .nocache.js files
False Positive Considerations
- XIOC extractor noise generating inflated IoC counts
- Bundled JavaScript frameworks triggering obfuscation rules on base64 assets
- Code-smell findings from standard Node.js patterns in bundled code
- Low user count and POC naming create false threat perception
Source Code Not Available
Source code is not available for this version of the extension.
About This Extension
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace
Whatfix Studio
[email protected]
fisglobal_MBP_ext
[email protected]
Whatfix for ATOSS_Salesforce
[email protected]
Whatfix for McDonalds
[email protected]
Whatfix for Midway Staffing
[email protected]
BI_POC
[email protected]