Brick Break Game
The AI review rates the findings as likely false positive, but the risk score (44/100) still counts them.
Analysis record
- Analysed
- 2 months ago
- Version
- v0.2.0
- Artifact
- SHA256 4C6…122
- Source
- Findings (non-IoC)
Evidence ledger
Ranked by severity · findings with a source location link to the code viewer
Publisher Evidence
Limited evidencePublisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.
Chrome does not expose the same publisher verification data as IDE stores, so this score is deliberately conservative.
12 evidence rows available.
Finding Categories
Requested Permissions
1 permissionAI Security Report
AI Security Review
Evidence context: threat category none; evidence quality moderate.
Brick Break Game (UUID: 0aabd4a1-55df-5559-b3b5-0338c4b860ca) is a simple browser game extension with 41 total findings, but none indicate malicious intent. The findings are entirely explainable by known CVEQ false-positive patterns.
IoC Analysis: All 27 IoC findings reference benign infrastructure. XIOC-DOMAIN-ns.adobe.com and XIOC-URL-http://ns.adobe.com/exif/1.0/ are Adobe namespace URIs commonly embedded in image metadata, not active network calls. XIOC-URL-https://clients2.google.com/service/update2/crx is the legitimate Chrome extension update service. XIOC-URL-https://cdn.gameforbreak.com/feeds/chrome/image/ is the extension's own CDN. XIOC-URL-https://www.gameanything.com/game/brick-blaster/ is a game portal URL. None of these domains are suspicious or indicative of data exfiltration.
Network Findings: The 4 network findings are all NET-FETCH calls in expected locations. js/game.js contains fetch calls at lines 220, 249, and 258, which is normal for a game that may load assets or track progress. js/google-analytics.js:73 contains analytics tracking, which is standard practice. These network calls match the extension's stated purpose as a game.
Code-Smell: The 10 code-smell findings are low-severity YARA rules that fire on basic JavaScript patterns. Per the CVEQ false-positive documentation, code-smell findings (severity=low, finding_type=code-smell) are noise and should never drive a verdict.
Malware Signatures: Zero malware signatures were detected. Zero obfuscation findings were detected. This is the most important signal—actual malicious extensions have malware signatures.
Counterargument: A skeptic might argue the developer email [email protected] is suspicious because it's not a verified publisher. While this is a minor concern, anonymous developers are common for simple games. The extension has no deceptive naming (not typosquatting), no browser hijacking behavior, no credential access, and no suspicious domains. The user count of 1000 suggests it's a legitimate but small game. Without malware signatures or obfuscation, the anonymous developer alone does not constitute evidence of malicious intent.
Conclusion: This extension is a benign browser game. All findings are explainable by known false-positive patterns: benign infrastructure domains in IoC extraction and code-smell rules on normal JavaScript. No action is warranted.
Key Reasons
- Zero malware signatures detected
- Zero obfuscation findings
- All IoC domains are benign infrastructure (Adobe, Google, W3C, own CDN)
- Network calls match expected game behavior
- Code-smell findings are known false-positive noise
False Positive Considerations
- IoC extractor capturing benign infrastructure domains (ns.adobe.com, clients2.google.com)
- Code-smell YARA rules firing on standard JavaScript patterns
- Adobe namespace URIs in image metadata misidentified as network destinations
Reviewed 2026-04-28; recommended action: suppress false positive; model confidence 85%.
Chrome version history
Risk trend by version
3 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.
Pick any point on the chart to explore that version's code below.
Source Code Not Available
Source code is not available for this version of the extension.
About This Extension
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace
Level Maze
[email protected]
Table Tennis
[email protected]
Maze
[email protected]
Bridge the Snake
[email protected]
Drag Maze: Back-and-forth Blockers
[email protected]
Unique Triangle Hunt Game
[email protected]