The AI review rates the findings as likely false positive, but the risk score (65/100) still counts them.
Analysis record
- Analysed
- 1 weeks ago
- Version
- v49.3.1
- Artifact
- SHA256 0D1…864
- Source
- Findings (non-IoC)
Evidence ledger
Ranked by severity · findings with a source location link to the code viewer
YARA Rule Matches
15 rules| Severity | Rule | Hits | Files | Metadata |
|---|---|---|---|---|
| LOW | postinstall persistence mechanism | 4 | chunks/home-CcHM0pj4.jsbackground.jscontent-scripts/content.js +1 more | - |
| LOW | postinstall obfuscation | 7 | chunks/copyToClipboard-DhpGqCzs.jschunks/home-CcHM0pj4.jsbackground.js +4 more | - |
| LOW | postinstall crypto operations | 5 | chunks/home-CcHM0pj4.jscontent-scripts/content.jschunks/expand-aFX-GGpy.js +2 more | - |
| LOW | postinstall file manipulation | 7 | chunks/home-CcHM0pj4.jschunks/copyToClipboard-DhpGqCzs.jsassets/home-wblVHT1_.css +4 more | - |
| LOW | postinstall environment access | 6 | chunks/home-CcHM0pj4.jsMETA-INF/cose.manifestchunks/copyToClipboard-DhpGqCzs.js +3 more | - |
| LOW | postinstall system command | 9 | chunks/home-CcHM0pj4.jschunks/expand-aFX-GGpy.jschunks/copyToClipboard-DhpGqCzs.js +6 more | - |
| LOW | postinstall registry modification | 4 | chunks/home-CcHM0pj4.jsassets/home-wblVHT1_.csscontent-scripts/content.js +1 more | - |
| LOW | postinstall network communication | 6 | chunks/home-CcHM0pj4.jsbackground.jschunks/WireframeIcon-DNZIKz7a.js +3 more | - |
| LOW | credential steam data | 1 | content-scripts/content.js | - |
| LOW | NoUseEval | 2 | chunks/expand-aFX-GGpy.jscontent-scripts/content.js | - |
| LOW | postinstall file download | 5 | chunks/expand-aFX-GGpy.jschunks/home-CcHM0pj4.jsbackground.js +2 more | - |
| LOW | SQLInjection | 3 | chunks/expand-aFX-GGpy.jschunks/home-CcHM0pj4.jscontent-scripts/content.js | - |
| LOW | NoUseWeakRandom | 5 | chunks/expand-aFX-GGpy.jschunks/home-CcHM0pj4.jsbackground.js +2 more | - |
| LOW | LocalStorageShouldNotBeUsed | 1 | content-scripts/content.js | - |
| LOW | DebuggerStatementsShouldNotBeUsed | 2 | content-scripts/content.jschunks/expand-aFX-GGpy.js | - |
Network Indicators
Concrete URLs, domains, IPs, emails, and hashes extracted from the analyzed artifact.
Network indicators are queued for lazy loading
Scroll this section into view to load the detailed rows.
Publisher Evidence
Limited evidenceDracon
Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.
Firefox does not expose the same publisher verification data as IDE stores, so this score is deliberately conservative.
12 evidence rows available.
Finding Categories
YARA Rules Matched
15 rules(67 hits)Requested Permissions
16 permissionsAccess your identity and sign-in tokens
AI Security Report
AI Security Review
Evidence context: threat category none; evidence quality moderate.
SamAI - Smart AI Assistant presents a concerning finding count of 372 at first glance, but the nature of these findings reveals a classic false positive pattern. All 372 findings are categorized as IoCs (Indicators of Compromise) with medium severity, while the extension has zero malware signatures, zero obfuscation detections, and zero code-smell findings.
The IoC findings follow a well-documented false positive pattern from the XIOC extractor. Domains like c.head.next, d.hooks.run, q.pattern.global, and r.rest are not actual domain names—they are JavaScript property access chains being misidentified as domains. The XIOC extractor incorrectly parses code like object.property.property as domain names, which is a known noise source documented in CVEQ's false positive patterns. Similarly, l.properties, h.properties, c.properties, and x.properties follow this same property-access pattern rather than representing legitimate domain references.
The few findings that look like actual domains (h.to, l.run, i.run, a.one) are extremely short and could represent either legitimate short domain services or additional false positives from string parsing. Without evidence of actual network traffic to these domains or malware signatures, they cannot be treated as confirmed malicious indicators.
The extension has an anonymous developer (empty developer name field) and only 1 user, which are red flags that warrant caution. However, the absence of any malware signatures, obfuscation, or code-smell findings is significant. A genuinely malicious extension would typically show at least one malware signature match or obfuscation pattern, especially with 372 total findings. The complete lack of these indicators suggests the findings are noise rather than evidence of malicious intent.
Counterargument: A skeptic might argue that 372 findings is too many to dismiss, and the anonymous developer status combined with low user count suggests this could be a newly deployed malicious extension. However, the evidence does not support this. The findings are exclusively IoCs following known false positive patterns, with zero malware signatures or obfuscation. If this were malicious code, YARA rules would have detected at least some code-smell patterns or malware family signatures. The finding volume is driven by the XIOC extractor's property chain misinterpretation, not by actual malicious indicators. The verdict remains likely_false_positive because the evidence shows no actual malicious behavior, only detection noise.
Key Reasons
- Zero malware signatures detected
- Zero obfuscation findings
- Zero code-smell findings
- IoC domains follow property access chain false positive pattern (c.head.next, d.hooks.run, q.pattern.global)
- All 372 findings are medium-severity IoCs with no critical or high severity detections
False Positive Considerations
- XIOC property access chain misinterpretation (c.head.next, d.hooks.run, q.pattern.global)
- Property access patterns misread as domains (l.properties, h.properties, c.properties)
- High IoC count from benign code patterns
- No malware signatures or obfuscation to corroborate malicious intent
Reviewed 2026-05-31; recommended action: suppress false positive; model confidence 75%.
Firefox version history
Risk trend by version
4 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.
Pick any point on the chart to explore that version's code below.
Source Code Not Available
Source code is not available for this version of the extension.
About This Extension
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace