Chrome Web Store

100xBot

by [email protected] · 463 users · 3.9 rating
1cada077-06b5-57e2-b51b-dc8f9d061d90 | v1.5.119
86/ 100
CRITICAL risk
No change since v1.5.118
Risk verdict
Do not install

Score-based assessment (critical risk, 86/100). No analyst review available.

Analysis record

Analysed
1 weeks ago
Version
v1.5.119
Artifact
SHA256 1E2…020
Source
Findings (non-IoC)

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

577 detail rows
Showing 25 of 31 · highest severity first

YARA Rule Matches

26 rules
SeverityRuleHitsFilesMetadata
HIGHsupply chain sourcemap appended iife 1
assets/domainUtils-DViNDAHg.js
-
LOWpostinstall file download 45
assets/index-916GNVqP.jsassets/json.worker-BVAlfHYs.jsmagick.wasm +42 more
-
LOWNoUseEval 2
assets/utils-CmGV79Kc.jsassets/index.ts-BJZFVG97.js
-
LOWNoUseWeakRandom 20
assets/domainUtils-DViNDAHg.jsassets/index.html-BzrwaXRW.jsassets/data-B807kLyo.js +17 more
-
LOWSQLInjection 6
assets/index.html-BzrwaXRW.jsassets/ai-ui-C43g_z33.jssrc/pages/content/index.tsx.js +3 more
-
LOWDebuggerStatementsShouldNotBeUsed 10
assets/TanStackDataTable-BzjApeUn.jsassets/index.html-BzrwaXRW.jspostgres.wasm +7 more
-
LOWUsingCommandLineArguments 3
postgres.dataassets/postgres-CkP7QCDB.dataassets/ts.worker-BPrOvWwc.js
-
LOWLocalStorageShouldNotBeUsed 8
assets/domainUtils-DViNDAHg.jsassets/data-B807kLyo.jsassets/index.ts-BJZFVG97.js +5 more
-
LOWcredential metamask extension 1
assets/index.ts-BJZFVG97.js
-
LOWspyeye 8
perspective-client.wasmassets/magick-DB-sQc3A.wasmassets/mupdf-wasm-b0pRsPEa.wasm +5 more
-
LOWpostinstall registry modification 25
assets/postgres-CyuUVpXN.wasmassets/7zz-CgkXYLdN.wasmassets/mupdf-wasm-b0pRsPEa.wasm +22 more
-
LOWpostinstall network communication 53
assets/utils-CmGV79Kc.jsassets/ChunkedPort-BAGZz87b.jsassets/editor.worker-BctYAlYZ.js +50 more
-
LOWcredential postgres credentials 5
assets/utils-CmGV79Kc.jsassets/postgres-CyuUVpXN.wasmassets/postgres-CkP7QCDB.data +2 more
-
LOWUsingShellInterpreterWhenExecutingOSCommands 4
postgres.dataassets/ts.worker-BPrOvWwc.jsassets/utils-CmGV79Kc.js +1 more
-
LOWReadingTheStandardInput 3
postgres.dataassets/postgres-CkP7QCDB.dataassets/index.html-BzrwaXRW.js
-
LOWOriginsNotVerified 6
assets/json.worker-BVAlfHYs.jsassets/domainUtils-DViNDAHg.jssrc/pages/content/index.tsx.js +3 more
-
LOWpostinstall system command 67
assets/index-DOlrGUaM.cssassets/postgres-CyuUVpXN.wasmassets/browser-CjbdbO2T.js +64 more
-
LOWpostinstall crypto operations 59
assets/styles-5f03d8d2-DxagS05d.jsassets/index.html-BzrwaXRW.jsassets/index.ts-BJZFVG97.js +56 more
-
LOWpostinstall obfuscation 53
assets/HundredxUISchema-BmxvFDm6.jsassets/editor.worker-BctYAlYZ.jsassets/postgres-CyuUVpXN.wasm +50 more
-
LOWpostinstall file manipulation 69
assets/filesystem-DKH_fnEs.jsassets/postgres-CyuUVpXN.wasmassets/browser-CjbdbO2T.js +66 more
-
LOWpostinstall environment access 53
assets/utils-CmGV79Kc.jsassets/timeline-definition-7e6b55e7-C4UpJJPe.jsassets/HundredxUISchema-BmxvFDm6.js +50 more
-
LOWpostinstall persistence mechanism 29
assets/transform-Dl_8WmG_.jsffmpeg-core.wasmfonts/mono.ttf +26 more
-
LOWcredential env files 10
assets/ai-ui-C43g_z33.jsassets/index-C4mOh2Au.jsassets/ts.worker-BPrOvWwc.js +7 more
-
LOWAPT1 WEBC2 Y21K 1
assets/index.ts-BJZFVG97.js
-
LOWWeakSSLTLSProtocolsShouldNotBeUsed 4
assets/postgres-CkP7QCDB.dataassets/postgres-CyuUVpXN.wasmpostgres.data +1 more
-
LOWRedirectToUnknownPath 1
assets/ts.worker-BPrOvWwc.js
-

Network Indicators

Concrete URLs, domains, IPs, emails, and hashes extracted from the analyzed artifact.

1,860 total
...

Network indicators are queued for lazy loading

Scroll this section into view to load the detailed rows.

Publisher Evidence

Limited evidence

[email protected]

Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.

Chrome does not expose the same publisher verification data as IDE stores, so this score is deliberately conservative.

29
Noisy-finding weight
x1.00
Publisher domain
No domain
Missing
Store verification signal
Limited signal
Limited
Extension portfolio
2
Portfolio

12 evidence rows available.

Finding Categories

1
Malware Signatures
15
Obfuscation
15
Network
1,860
IoC Indicators

YARA Rules Matched

26 rules(546 hits)
supply chain sourcemap appended iife postinstall file download NoUseEval NoUseWeakRandom SQLInjection DebuggerStatementsShouldNotBeUsed UsingCommandLineArguments LocalStorageShouldNotBeUsed credential metamask extension spyeye postinstall registry modification postinstall network communication credential postgres credentials UsingShellInterpreterWhenExecutingOSCommands ReadingTheStandardInput OriginsNotVerified +10 more

Requested Permissions

17 permissions
debugger

Full access to Chrome DevTools debugging protocol

Dangerous
<all_urls>

Access and modify data on every website you visit

Dangerous
history

Read and modify your browsing history

High
downloads

Manage, modify, and monitor downloads

High
cookies

Read and modify cookies on all sites

High
webRequest

Intercept, modify, and block all network requests

High
identity

Access your identity and sign-in tokens

High
activeTab
Medium
tabs
Medium
sidePanel
Low
storage
Low
scripting
Low
offscreen
Low
power
Low
webNavigation
Low
contentSettings
Low
alarms
Low

Security Analysis Summary

Security Analysis Overview

100xBot is a Chrome Web Store extension published by [email protected]. Version 1.5.119 has been analyzed by the Risky Plugins security platform, receiving a risk score of 85.54/100 (CRITICAL risk) based on 2437 security findings.

Risk Assessment

This extension presents critical security risk. Severe issues were detected, potentially including malware indicators, exposed secrets, or dangerous behaviors. Installation is strongly discouraged until these issues are addressed.

Findings Breakdown

  • High: 3 finding(s)
  • Medium: 1889 finding(s)
  • Low: 545 finding(s)

What Was Analyzed

The security assessment covers multiple analysis categories:

  • Malware Detection: YARA rule matching against 2,400+ malware signatures
  • Secret Detection: Scanning for exposed API keys, tokens, and credentials
  • Static Analysis: Code-level security analysis for common vulnerability patterns
  • Network Analysis: Detection of suspicious network communications and endpoints
  • Obfuscation Detection: Identification of code obfuscation techniques

Developer Information

100xBot is published by [email protected] on the Chrome Web Store marketplace. The extension has approximately 463 users.

Recommendation

This extension is not recommended for installation without thorough manual review. Consider alternatives with lower risk scores, or contact the developer to address the identified security concerns.

Chrome version history

Risk trend by version

3 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.

Selected
86
Change since first
No change
Change from previous
No change
Versions:
First analyzed version
1.5.116
Aug 24, 2026
Risk range
86 to 86
Across analyzed versions
Latest analyzed version
1.5.119
Sep 22, 2026
Selected version
critical
Version
v1.5.119
1 weeks ago
Risk score
86
Findings
2444
Change vs previous
No change

Pick any point on the chart to explore that version's code below.

About This Extension

100xBot is an AI browser automation extension for Chrome. Describe a task in plain English and its browser agent can navigate pages, click buttons, fill forms, extract website data, and work across tabs. Type or speak your instructions to automate repetitive browser tasks without writing code. WHAT YOU CAN AUTOMATE Web scraping and data extraction Use it as an AI web scraper to collect product names and prices, job listings, directory entries, or other page details. Review the extracted data in a table, then download a CSV file for a spreadsheet or another tool. Form filling and data entry Use its AI form filling capabilities to enter details into web forms. Handle repeated applications, records, or updates that would otherwise mean copying and pasting the same information again. Research across websites Move beyond one page. Ask it to compare products across tabs, gather information from several sites, or bring findings together for a report. It can navigate and interact with pages as part of a multi-step task. Reusable browser workflows When a browser task is worth repeating, save it as a workflow and run it again. Keep a library of useful tasks for recurring research, data collection, and other routine work. HOW IT WORKS 1. Open a page and launch the side panel. 2. Describe the outcome you want. You can type a request or use voice input. 3. Follow its progress in the browser, review the result, and save useful work for next time. Try asking: • “Extract the product names and prices from this page and put them in a table.” • “Fill this form with the details I provide.” • “Compare the products in my open tabs and summarize the differences.” • “Collect the company names and website links from these search results.” It is useful for sales research, recruiting, e-commerce comparisons, operations, and anyone who spends too much time repeating browser tasks. Start with one job you already know how to describe. If you can explain the goal, 100xBot can help you work through the steps.

Frequently Asked Questions