Chrome Web Store Verified

Google Translate

by [email protected] · 38.0M users · 4.2 rating
21e01ca4-f69c-5baa-bd79-952ec97122f7 | v2.0.17
0/ 100
MINIMAL risk
-28 since v2.0.16
28 → 0 · false positives removed
Analyst verdict
No high-risk signal observed

Based on the RiskyPlugins AI security review of the observed evidence.

Analysis record

Analysed
2 weeks ago
Version
v2.0.17
Artifact
SHA256 3F7…DD1
Source
Findings (non-IoC)

No Findings

All security checks passed

Publisher Evidence

Low

[email protected]

Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.

Chrome does not expose the same publisher verification data as IDE stores, so this score is deliberately conservative.

89
Noisy-finding weight
x1.00
Publisher domain
google.com
Trusted match
Store verification signal
Limited signal
Limited
Extension portfolio
557
Portfolio

12 evidence rows available.

No Threats Detected

This extension passed all security checks

AI Security Report

AI Security Review

Evidence context: threat category none; evidence quality strong.

This is the official Google Translate extension published by Google itself (developer: [email protected]) with 36 million users. The security findings flagged in this scan are well-documented false positives that do not indicate actual malicious behavior.

The 55 high-severity "malware signature" findings all originate from the same YARA rule: YARA--postinstall_crypto_operations, which triggered in bubble_compiled.js, options_compiled.js, and popup_compiled.js. This rule is a known false-positive pattern that matches basic cryptographic operations and Node.js patterns (fetch, exec, fs, crypto) present in virtually any non-trivial JavaScript application. For a translation extension that legitimately needs to communicate with translation APIs, crypto operations are expected and benign.

The 9 medium-severity network findings show generic fetch calls across the compiled JavaScript files (bubble_compiled.js, options_compiled.js, popup_compiled.js, main_compiled.js). These are standard HTTP requests required for the extension's core functionality—sending text to translation services and retrieving results. Critically, the scan extracted zero suspicious network domains (IoC count is 0), meaning no external tracking domains, credential theft endpoints, or hijacking infrastructure were detected.

There are no obfuscation findings, no secret exposure, no credential theft indicators, and no browser hijacking behavior. The extension's description matches its publisher: "View translations easily as you browse the web. By the Google Translate team."

Addressing the strongest counterargument: A skeptic might argue that 55 high-severity malware signatures is too many to dismiss. However, finding count is not evidence of malicious intent—the nature of findings matters. All 55 signatures come from a single overly-broad rule that matches legitimate crypto operations. The scan found zero actual malware signatures (the malware-signature category here refers to code-smell rules misclassified as signatures), zero suspicious domains, zero obfuscation, and zero data exfiltration patterns. A truly malicious extension would show specific malicious behaviors like credential access, suspicious domain connections, or hidden payloads—not just basic crypto functions.

The combination of verified Google publisher identity, legitimate extension purpose, and findings that match documented false-positive patterns confirms this is a false positive. No action is needed beyond suppressing these known noise patterns.

Key Reasons

  • Verified Google publisher with 36M users and legitimate description
  • All 55 malware-signature findings from known false-positive postinstall_crypto_operations rule
  • Zero suspicious network domains extracted (IoC count is 0)
  • No obfuscation, credential theft, or hijacking indicators present
  • Network findings are generic fetch calls expected for translation functionality

False Positive Considerations

  • postinstall_crypto_operations YARA rule matches basic crypto operations
  • Generic fetch calls flagged as network findings without domain analysis
  • Compiled JavaScript files trigger broad pattern matches
  • Score inflation from finding count rather than finding nature

Reviewed 2026-06-10; recommended action: suppress false positive; model confidence 95%.

About This Extension

Highlight or right-click on a section of text and click on Translate icon next to it to translate it to your language. Learn more about Google Translate at https://support.google.com/translate. By installing this extension, you agree to the Google Terms of Service and Privacy Policy at https://www.google.com/intl/en/policies. UPDATE (v.2.0): Now you can highlight or right-click a text and translate it vs. translate the entire page. You can also change extension options to automatically show translation every time you highlight text. UPDATE (v.2.14+): Page translation is now supported natively in Chrome browsers and is no longer supported in the Google Translate extension. See https://support.google.com/chrome/answer/173424 to learn how to use it.

Frequently Asked Questions