Firefox Add-ons

SamAI - Smart AI Assistant

by Dracon
39e6b080-6665-523f-9f02-7dbe86d5354f | v49.3.1
65/ 100
MEDIUM risk
-3 since v49.3.0
Analyst verdict
Review before use

The AI review rates the findings as likely false positive, but the risk score (65/100) still counts them.

Analysis record

Analysed
1 weeks ago
Version
v49.3.1
Artifact
SHA256 0D1…864
Source
Findings (non-IoC)

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

74 detail rows

YARA Rule Matches

15 rules
SeverityRuleHitsFilesMetadata
LOWpostinstall obfuscation 7
chunks/WireframeIcon-DNZIKz7a.jsbackground.jscontent-scripts/content.js +4 more
-
LOWpostinstall crypto operations 5
background.jschunks/expand-aFX-GGpy.jschunks/home-CcHM0pj4.js +2 more
-
LOWpostinstall file manipulation 7
assets/home-wblVHT1_.cssbackground.jschunks/WireframeIcon-DNZIKz7a.js +4 more
-
LOWpostinstall environment access 6
META-INF/manifest.mfMETA-INF/cose.manifestchunks/copyToClipboard-DhpGqCzs.js +3 more
-
LOWpostinstall system command 9
assets/home-wblVHT1_.csschunks/home-CcHM0pj4.jsbackground.js +6 more
-
LOWpostinstall registry modification 4
assets/home-wblVHT1_.csscontent-scripts/content.jschunks/expand-aFX-GGpy.js +1 more
-
LOWpostinstall network communication 6
background.jschunks/WireframeIcon-DNZIKz7a.jscontent-scripts/content.js +3 more
-
LOWcredential steam data 1
content-scripts/content.js
-
LOWNoUseEval 2
content-scripts/content.jschunks/expand-aFX-GGpy.js
-
LOWpostinstall file download 5
background.jschunks/WireframeIcon-DNZIKz7a.jscontent-scripts/content.js +2 more
-
LOWSQLInjection 3
content-scripts/content.jschunks/expand-aFX-GGpy.jschunks/home-CcHM0pj4.js
-
LOWNoUseWeakRandom 5
background.jschunks/WireframeIcon-DNZIKz7a.jscontent-scripts/content.js +2 more
-
LOWLocalStorageShouldNotBeUsed 1
content-scripts/content.js
-
LOWDebuggerStatementsShouldNotBeUsed 2
content-scripts/content.jschunks/expand-aFX-GGpy.js
-
LOWpostinstall persistence mechanism 4
background.jscontent-scripts/content.jschunks/expand-aFX-GGpy.js +1 more
-

Network Indicators

Concrete URLs, domains, IPs, emails, and hashes extracted from the analyzed artifact.

906 total
...

Network indicators are queued for lazy loading

Scroll this section into view to load the detailed rows.

Publisher Evidence

Limited evidence

Dracon

Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.

Firefox does not expose the same publisher verification data as IDE stores, so this score is deliberately conservative.

52
Noisy-finding weight
x1.00
Publisher domain
dracon.uk
Observed
Store verification signal
Limited signal
Limited
Extension portfolio
26
Portfolio

12 evidence rows available.

Finding Categories

2
Obfuscation
4
Network
906
IoC Indicators

YARA Rules Matched

15 rules(67 hits)
postinstall obfuscation postinstall crypto operations postinstall file manipulation postinstall environment access postinstall system command postinstall registry modification postinstall network communication credential steam data NoUseEval postinstall file download SQLInjection NoUseWeakRandom LocalStorageShouldNotBeUsed DebuggerStatementsShouldNotBeUsed postinstall persistence mechanism

Requested Permissions

16 permissions
http://*/*
Dangerous
https://*/*
Dangerous
identity

Access your identity and sign-in tokens

High
tabs
Medium
activeTab
Medium
storage
Low
contextMenus
Low
scripting
Low
alarms
Low
https://generativelanguage.googleapis.com/*
Low
https://www.googleapis.com/*
Low
https://accounts.google.com/*
Low
https://html.duckduckgo.com/*
Low
https://links.duckduckgo.com/*
Low
https://www.bing.com/*
Low
https://www.google.com/*
Low

AI Security Report

AI Security Review

Evidence context: threat category none; evidence quality moderate.

SamAI - Smart AI Assistant presents a concerning finding count of 372 at first glance, but the nature of these findings reveals a classic false positive pattern. All 372 findings are categorized as IoCs (Indicators of Compromise) with medium severity, while the extension has zero malware signatures, zero obfuscation detections, and zero code-smell findings.

The IoC findings follow a well-documented false positive pattern from the XIOC extractor. Domains like c.head.next, d.hooks.run, q.pattern.global, and r.rest are not actual domain names—they are JavaScript property access chains being misidentified as domains. The XIOC extractor incorrectly parses code like object.property.property as domain names, which is a known noise source documented in CVEQ's false positive patterns. Similarly, l.properties, h.properties, c.properties, and x.properties follow this same property-access pattern rather than representing legitimate domain references.

The few findings that look like actual domains (h.to, l.run, i.run, a.one) are extremely short and could represent either legitimate short domain services or additional false positives from string parsing. Without evidence of actual network traffic to these domains or malware signatures, they cannot be treated as confirmed malicious indicators.

The extension has an anonymous developer (empty developer name field) and only 1 user, which are red flags that warrant caution. However, the absence of any malware signatures, obfuscation, or code-smell findings is significant. A genuinely malicious extension would typically show at least one malware signature match or obfuscation pattern, especially with 372 total findings. The complete lack of these indicators suggests the findings are noise rather than evidence of malicious intent.

Counterargument: A skeptic might argue that 372 findings is too many to dismiss, and the anonymous developer status combined with low user count suggests this could be a newly deployed malicious extension. However, the evidence does not support this. The findings are exclusively IoCs following known false positive patterns, with zero malware signatures or obfuscation. If this were malicious code, YARA rules would have detected at least some code-smell patterns or malware family signatures. The finding volume is driven by the XIOC extractor's property chain misinterpretation, not by actual malicious indicators. The verdict remains likely_false_positive because the evidence shows no actual malicious behavior, only detection noise.

Key Reasons

  • Zero malware signatures detected
  • Zero obfuscation findings
  • Zero code-smell findings
  • IoC domains follow property access chain false positive pattern (c.head.next, d.hooks.run, q.pattern.global)
  • All 372 findings are medium-severity IoCs with no critical or high severity detections

False Positive Considerations

  • XIOC property access chain misinterpretation (c.head.next, d.hooks.run, q.pattern.global)
  • Property access patterns misread as domains (l.properties, h.properties, c.properties)
  • High IoC count from benign code patterns
  • No malware signatures or obfuscation to corroborate malicious intent

Reviewed 2026-05-31; recommended action: suppress false positive; model confidence 75%.

Firefox version history

Risk trend by version

4 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.

Selected
65
Change since first
No change
Change from previous
-3
Versions:
First analyzed version
49.1.0
May 30, 2026
Risk range
59 to 68
Across analyzed versions
Latest analyzed version
49.3.1
Sep 18, 2026
Selected version
medium
Version
v49.3.1
1 weeks ago
Risk score
65
Findings
980
Change vs previous
-3

Pick any point on the chart to explore that version's code below.

About This Extension

🌟 SamAI - Your Smart AI Assistant (100% Free!) Transform your browsing experience with SamAI, your free intelligent companion that seamlessly integrates with your browser. No hidden costs, no subscriptions - just powerful AI assistance at your fingertips. 💎 COMPLETELY FREE • No subscription required • All features included • No hidden costs • Free updates 🔍 SMART SEARCH ENHANCEMENT • Get instant, intelligent analysis of search results • Receive contextual insights and summaries • View information in beautiful markdown formatting • Understand complex topics at a glance 💬 CONTEXTUAL CHAT • Chat naturally with AI about any webpage • Get instant answers to your questions • Enjoy code-aware responses with syntax highlighting • Experience seamless context understanding ✍️ WRITING ASSISTANT • Enhance your writing with AI-powered suggestions • Get help with editing and refinement • Choose from multiple writing styles • Perfect for emails, documents, and more ⚡️ KEY FEATURES • Lightning-fast responses • Beautifully designed interface • Dark mode support • Rich markdown formatting • Code syntax highlighting 🛡️ PRIVACY FOCUSED • No data collection • Privacy-first design • Secure AI interactions • No personal data storage • Complete transparency 🎯 PERFECT FOR • Students researching topics • Professionals writing content • Developers seeking code explanations • Researchers analyzing information • Anyone who wants to work smarter ⚙️ SEAMLESS INTEGRATION • Works right in your browser • No additional apps needed • Simple, intuitive interface • Quick access from any webpage 🚀 GET STARTED Install SamAI for free and experience a smarter way to browse, search, and create content. Unlock the power of AI while maintaining your privacy. ✨ Updates & Support • Regular free updates with new features • Active development • Responsive support team • Community-driven improvements Join thousands of users who have transformed their browsing experience with SamAI - completely free! AI #Free #Productivity #Privacy #BrowserExtension

Frequently Asked Questions