API Debugger - Capture
The AI review rates the findings as likely false positive, but the risk score (65/100) still counts them.
Analysis record
- Analysed
- 4 weeks ago
- Version
- v2.5.5
- Artifact
- SHA256 A24…74C
- Source
- Findings (non-IoC)
Evidence ledger
Ranked by severity · findings with a source location link to the code viewer
YARA Rule Matches
14 rules| Severity | Rule | Hits | Files | Metadata |
|---|---|---|---|---|
| LOW | credential env files | 1 | chunks/dashboard-Cw8_oheF.js | - |
| LOW | postinstall persistence mechanism | 2 | chunks/dashboard-Cw8_oheF.jsbackground.js | - |
| LOW | credential generic tokens | 2 | chunks/dashboard-Cw8_oheF.jsbackground.js | - |
| LOW | postinstall file download | 3 | chunks/dashboard-Cw8_oheF.jschunks/_virtual_wxt-html-plugins-DPbbfBKe.jsbackground.js | - |
| LOW | NoUseWeakRandom | 2 | chunks/dashboard-Cw8_oheF.jsbackground.js | - |
| LOW | postinstall crypto operations | 1 | chunks/dashboard-Cw8_oheF.js | - |
| LOW | postinstall file manipulation | 2 | chunks/dashboard-Cw8_oheF.jsbackground.js | - |
| LOW | postinstall environment access | 1 | chunks/dashboard-Cw8_oheF.js | - |
| LOW | postinstall registry modification | 1 | chunks/dashboard-Cw8_oheF.js | - |
| LOW | postinstall obfuscation | 2 | chunks/dashboard-Cw8_oheF.jsbackground.js | - |
| LOW | postinstall network communication | 2 | chunks/dashboard-Cw8_oheF.jsbackground.js | - |
| LOW | postinstall system command | 3 | assets/welcome-B4x7absd.csschunks/dashboard-Cw8_oheF.jsassets/dashboard-DBBBqFVk.css | - |
| LOW | ServerHostnameNotVerified | 1 | chunks/dashboard-Cw8_oheF.js | - |
| LOW | DebuggerStatementsShouldNotBeUsed | 5 | chunks/dashboard-Cw8_oheF.jsMETA-INF/mozilla.rsaMETA-INF/cose.sig +2 more | - |
Network Indicators
Concrete URLs, domains, IPs, emails, and hashes extracted from the analyzed artifact.
Network indicators are queued for lazy loading
Scroll this section into view to load the detailed rows.
Publisher Evidence
Limited evidenceDracon
Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.
Firefox does not expose the same publisher verification data as IDE stores, so this score is deliberately conservative.
12 evidence rows available.
Finding Categories
YARA Rules Matched
14 rules(28 hits)Requested Permissions
6 permissionsAccess and modify data on every website you visit
Intercept, modify, and block all network requests
Read and modify cookies on all sites
AI Security Report
AI Security Review
Evidence context: threat category none; evidence quality moderate.
This API debugging extension triggers 212 findings, but examination of the actual evidence reveals no malicious behavior. All 208 IoC findings reference benign domains: https://api.example.com/user, https://api.example.com/data, and https://accounts.example.com/authorize use example.com, a domain reserved by RFC 2606 for documentation and testing purposes. The finding XIOC-URL-https://jsonplaceholder.typicode.com/posts/1 references a well-known public testing API used by developers worldwide. Source map files like s.environments.map and s.requests.map are standard build artifacts, not suspicious domains.
The extension's declared purpose—"Inspect every HTTP request your browser makes. Capture, replay, build, and debug APIs"—aligns perfectly with the code findings. API debugging tools legitimately contain OAuth flows (https://oauth.example.com/token), localhost endpoints (https://localhost/callback), and test API references. These are implementation details of the tool's functionality, not indicators of malicious intent.
Critically, the scan found zero malware signatures, zero obfuscation, zero code-smell findings, and zero secrets. The only other findings are 2 manifest-analysis and 2 network findings, all at medium severity. A genuinely malicious extension would show malware-family matches, obfuscation patterns, or suspicious external domains—not documentation examples and localhost callbacks.
The strongest counterargument is the empty developer name field and extremely low user count (1). These are legitimate trust concerns that suggest the extension may be abandoned or poorly maintained. However, trust metadata is distinct from code behavior. The actual code contains no evidence of credential theft, data exfiltration, browser hijacking, or malware delivery. The empty developer name indicates poor publishing hygiene, not malicious intent.
This extension represents a classic false-positive pattern: high finding volume driven by benign test infrastructure. The IoC extractor flagged every URL string in the codebase, including documentation examples and development endpoints. Without malware signatures or obfuscation, the finding count alone cannot justify a malicious verdict. The recommended action is to suppress these false positives while noting that the extension should ideally include proper developer attribution.
Key Reasons
- All IoCs reference benign domains (example.com, localhost, jsonplaceholder.typicode.com)
- Zero malware signatures detected in scan
- Zero obfuscation findings
- IoCs align with legitimate API debugging tool functionality
- example.com domains are RFC 2606 reserved for documentation
False Positive Considerations
- example.com documentation domains
- localhost development endpoints
- Public test API references
- Source map file paths misread as domains
Reviewed 2026-05-30; recommended action: suppress false positive; model confidence 85%.
Firefox version history
Risk trend by version
2 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.
Pick any point on the chart to explore that version's code below.
Source Code Not Available
Source code is not available for this version of the extension.
About This Extension
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace