迅雷下载支持
Score-based assessment (medium risk, 65/100). Last analyst review covers version 3.53.3.
Analysis record
- Analysed
- 6 days ago
- Version
- v4.1.3
- Artifact
- SHA256 D03…0A2
- Source
- Findings (non-IoC)
Evidence ledger
Ranked by severity · findings with a source location link to the code viewer
YARA Rule Matches
14 rules| Severity | Rule | Hits | Files | Metadata |
|---|---|---|---|---|
| LOW | LocalStorageShouldNotBeUsed | 2 | assets/xl-player-fd184909.jsassets/messages-94096533.js | - |
| LOW | DebuggerStatementsShouldNotBeUsed | 2 | assets/xl-player/lib/TAppDecoderStatic.jsassets/xl-player/lib/libffmpeg.js | - |
| LOW | postinstall crypto operations | 13 | assets/risk-error-6a79c80a.jsassets/options.html-684ac5ac.jsassets/options-tab-2013941f.js +10 more | - |
| LOW | postinstall obfuscation | 32 | assets/xl-images-998ea1e9.cssassets/scss/popup.cssmanifest.json +29 more | - |
| LOW | postinstall file manipulation | 28 | assets/login-success-162fee85.jsassets/util-9ee2f234.jsassets/messages-94096533.js +25 more | - |
| LOW | postinstall environment access | 6 | assets/index-52585ddd.jsassets/background.js-7414d968.jsassets/content.js-4b73743c.js +3 more | - |
| LOW | postinstall network communication | 33 | assets/get-dom-caa529e9.jsassets/svg/empty.svgconnection-exception.html +30 more | - |
| LOW | postinstall system command | 31 | assets/get-dom-caa529e9.jsassets/popup-14532677.cssassets/scss/reset.scss +28 more | - |
| LOW | OriginsNotVerified | 1 | assets/content.js-4b73743c.js | - |
| LOW | postinstall file download | 33 | assets/sidepanel.cssassets/risk-error-6a79c80a.jsmanifest.json +30 more | - |
| LOW | NoUseWeakRandom | 6 | assets/index-7f10a347.jsassets/background.js-7414d968.jsassets/content.js-4b73743c.js +3 more | - |
| LOW | SQLInjection | 1 | assets/background.js-7414d968.js | - |
| LOW | credential env files | 1 | assets/util-e26c1ce0.js | - |
| LOW | postinstall persistence mechanism | 6 | assets/image/svg/logo.svgassets/scss/video-tag.module.cssassets/background.js-7414d968.js +3 more | - |
Network Indicators
Concrete URLs, domains, IPs, emails, and hashes extracted from the analyzed artifact.
Network indicators are queued for lazy loading
Scroll this section into view to load the detailed rows.
Publisher Evidence
Limited evidencePublisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.
Chrome does not expose the same publisher verification data as IDE stores, so this score is deliberately conservative.
13 evidence rows available.
Finding Categories
YARA Rules Matched
14 rules(195 hits)Requested Permissions
12 permissionsExchange messages with programs outside the browser
Access and modify data on every website you visit
Read and modify cookies on all sites
Intercept, modify, and block all network requests
Manage, modify, and monitor downloads
AI Security Report
AI Security Review
Evidence context: threat category none; evidence quality strong.
The extension "迅雷下载支持" from developer "[email protected]" has been analyzed. With zero findings across all categories, including IoC, malware signatures, network analysis, obfuscation, and code smell, there is no evidence to suggest malicious behavior. The extension's description as "迅雷下载支持" (which translates to "Thunder download support") and its large user base of 66,000,000 users could suggest it is a legitimate tool for facilitating downloads, possibly related to the Xunlei Thunder download manager. A potential counterargument could be that the lack of findings is due to sophisticated evasion techniques. However, given the comprehensive nature of the analysis and the absence of any suspicious indicators, this seems unlikely. Therefore, based on the evidence, or rather the lack thereof, it is reasonable to conclude that this extension does not pose a significant risk. The large user count and the developer's email address provided could further support the legitimacy of the extension, as malicious actors often attempt to remain anonymous. In conclusion, the extension appears to be benign, with no clear indicators of malicious intent or behavior.
Key Reasons
- Zero findings across all analysis categories
- Large user base with no reported issues
- Developer information is provided
Reviewed 2026-05-23; recommended action: no action; model confidence 90%.
Chrome version history
Risk trend by version
6 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.
Pick any point on the chart to explore that version's code below.
Source Code Not Available
Source code is not available for this version of the extension.
About This Extension
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace
Edge Translate - Browser Translator | PDF Translation | MV3 | Open Source
[email protected]
Intelbras Cloud
[email protected]
SlingPlayer for DISH Anywhere
Unknown Developer
My Jobscore
[email protected]
种草星球-TikTok爆单神器,商品自动提报采集邀评【永久免费】
[email protected]
Kindredly - A safer, private web for families
[email protected]