Video Download Helper
From the RiskyPlugins AI security review of the observed evidence.
Analysis record
- Analysed
- 3 weeks ago
- Version
- v10.5.49.2
- Artifact
- SHA256 6B2…465
- Source
- Findings (non-IoC)
Evidence ledger
Ranked by severity · findings with a source location link to the code viewer
YARA Rule Matches
14 rules| Severity | Rule | Hits | Files | Metadata |
|---|---|---|---|---|
| LOW | credential env files | 2 | injected/youtube.jscontent/smartnaming.js | - |
| LOW | postinstall persistence mechanism | 9 | injected/youtube.jsservice/main.js_locales/it/messages.json +6 more | - |
| LOW | DebuggerStatementsShouldNotBeUsed | 2 | content/smartnaming.jsinjected/youtube.js | - |
| LOW | UsingCommandLineArguments | 1 | download_worker/libav-6.5.7.1-h264-aac-mp3.wasm.mjs | - |
| LOW | NoUseEval | 1 | injected/youtube.js | - |
| LOW | NoUseWeakRandom | 13 | injected/facebook.jsinjected/youtube.jscontent/smartnaming.js +10 more | - |
| LOW | postinstall file download | 68 | injected/twitcasting.js_locales/is/messages.jsondownload_worker/main.js +65 more | - |
| LOW | SQLInjection | 2 | content/translate.jscontent/smartnaming.js | - |
| LOW | postinstall file manipulation | 55 | content/global_persistent.jscontent/translate.jsinjected/vimeo.js +52 more | - |
| LOW | postinstall obfuscation | 28 | manifest.jsoncontent/translate.jsfactory/factory.js +25 more | - |
| LOW | postinstall crypto operations | 27 | content/history.jsdownload_worker/main.jsinjected/bilibili.js +24 more | - |
| LOW | postinstall system command | 52 | injected/osmosis.jscontent/translate.jscontent/details.js +49 more | - |
| LOW | postinstall registry modification | 13 | content/translate.jsinjected/youtube.jsinjected/vk.js +10 more | - |
| LOW | postinstall network communication | 27 | content/translate.jsinjected/javrank.jsinjected/osmosis.js +24 more | - |
Publisher Evidence
Limited evidencevdh
Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.
Firefox does not expose the same publisher verification data as IDE stores, so this score is deliberately conservative.
13 evidence rows available.
Finding Categories
YARA Rules Matched
14 rules(300 hits)Requested Permissions
40 permissionsAccess and modify data on every website you visit
Manage, modify, and monitor downloads
Intercept, modify, and block all network requests
AI Security Report
AI Security Review
Evidence context: threat category none; evidence quality moderate.
The extension’s manifest reports a description of "Download videos from the web. Easy, smart, no tracking." and the code base contains a set of injected helper scripts that each issue a fetch request. The findings show explicit network calls such as NET-FETCH-injected/vimeo.js-9 in injected/vimeo.js, NET-FETCH-injected/bilibili.js-6 in injected/bilibili.js, NET-FETCH-injected/kick.js-9* and *-6* in *injected/kick.js*, NET-FETCH-injected/chaturbate.js-9in *injected/chaturbate.js*, andNET-FETCH-injected/facebook.js-10in *injected/facebook.js*. These scripts are clearly intended to retrieve video data or metadata from the named platforms (Vimeo, Bilibili, Kick, Chaturbate, Facebook, YouTube, Canva, etc.). Another set of fetch calls originates from the core workers:NET-FETCH-download_worker/main.js-9in *download_worker/main.js* andNET-FETCH-service/main.js-18* and -40 in service/main.js. Additionally, a Socket.IO connection is opened from service/main.js (NET-SOCKET_IO-service/main.js-41). All of these network interactions are typical for a downloader that contacts the source sites to acquire video streams.
No findings indicate the presence of malware signatures, obfuscation, credential harvesting, or data exfiltration. The findings_summary reports zero IoCs, zero malware signatures, and zero obfuscation flags. The only other category present is the single manifest analysis finding, which does not raise any security concerns. There are no code‑smell or secret‑leak findings, and the extension does not request cookies, storage, or other sensitive permissions beyond what a downloader would need.
The extension name, Video DownloadHelper, matches a well‑known Firefox add‑on that is widely used for exactly this purpose. Although the developer_name field is blank, the user count exceeds 1.8 million, suggesting a mature and popular tool rather than a freshly published imposter. No typographic similarity to a different popular extension is observed, so impersonation is not a factor.
A skeptic might argue that the numerous fetch calls to many third‑party domains could hide unwanted tracking or serve as a conduit for malicious payloads. However, each call is tied to a specific site‑specific script (e.g., youtube.js, vimeo.js), and there is no evidence of these scripts transmitting user data to unknown endpoints, nor any indication of the extension modifying browser settings, hijacking the new‑tab page, or acting as a proxy. The absence of any data‑exfiltration or credential‑theft signatures, combined with the transparent purpose of the code, strongly mitigates that concern.
In summary, the extension behaves as advertised: it contacts video‑hosting services to retrieve media streams. Its behavior aligns with the functionality of a legitimate video‑download helper, and no malicious or high‑risk patterns were observed.
Key Reasons
- Only fetch calls to known video‑site scripts (e.g., injected/vimeo.js, injected/bilibili.js)
- No malware signatures, obfuscation, or credential‑stealing code detected
- Extension name matches a popular, legitimate downloader
- No network calls to suspicious or unknown domains
Reviewed 2026-05-23; recommended action: no action; model confidence 88%.
Firefox version history
Risk trend by version
8 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.
Pick any point on the chart to explore that version's code below.
Source Code Not Available
Source code is not available for this version of the extension.
About This Extension
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace
VaultysHub extension
Vaultys
Kindredly - A safer, private web for families
Kindredly.ai
Malwarebytes Browser Guard
Malwarebytes
VHS - Dev Tools
Vihat Software
Ultimate New Tab Page - AI Search & Dial
Dracon
General Sticker System (GSS)
ElfinL