Microsoft Single Sign On
From the RiskyPlugins AI security review of the observed evidence.
Analysis record
- Analysed
- 10 months ago
- Version
- v1.0.11
- Artifact
- SHA256 AC3…24A
- Source
- Findings (non-IoC)
No Findings
All security checks passed
Publisher Evidence
LowPublisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.
Chrome does not expose the same publisher verification data as IDE stores, so this score is deliberately conservative.
12 evidence rows available.
No Threats Detected
This extension passed all security checks
AI Security Report
AI Security Review
Evidence context: threat category typosquatting; evidence quality moderate.
Microsoft Single Sign On is marketed as a tool that enables users to sign in to supported websites with a Microsoft work or school account on Windows and macOS platforms. The extension’s manifest.json contains the permission 'nativemessaging' (MANIFEST-SENSITIVE-PERM-NATIVEMESSAGING), a capability that can expose native host communication. Three high‑severity YARA matches are recorded in unknown_file: two entries are titled YARA--postinstall_network_communication and one is titled YARA--postinstall_crypto_operations. These signatures trigger on post‑install network activity and cryptographic operations, respectively. The developer field lists the identifier [email protected], which does not correspond to any publicly documented Microsoft store publisher profile. No IoC findings such as suspicious domains, proxyware behavior, or credential‑theft patterns appear in the analysis. The extension does not contain obfuscation beyond standard bundling, nor does it exhibit typosquatting beyond its name.
A skeptic might argue that the YARA signatures are generic postinstall rules that frequently fire on legitimate extensions and that the native messaging permission is commonly used for legitimate debugging, therefore the findings are harmless. However, the presence of three distinct high‑severity signatures, combined with an anonymous developer name and an extension title that directly mimics Microsoft’s single‑sign‑on functionality, creates a context where benign intent is not evident. Moreover, the extension’s high user count amplifies any potential impact if the permissions were abused. The description provides no concrete service details and relies on vague language about "supported websites," which further weakens the claim of legitimacy. The YARA rule titles belong to a known set that is often associated with malicious extensions seeking to exfiltrate data or perform cryptominer activity after installation. The combination of network‑related and crypto‑related signatures in the same file is atypical for benign utilities.
The strongest counterargument — that the signatures are non‑specific — does not fully explain why the extension would request a sensitive native messaging permission without any accompanying benign use case. Additionally, the extension’s name directly copies Microsoft’s branding, a classic tactic used in typosquatting to gain trust. While the extension may be an earnest attempt to provide an SSO helper, the evidence package does not demonstrate a clear, legitimate purpose. Instead, it exhibits multiple red‑flag patterns that require further investigation. Given the ambiguous nature of the findings, the appropriate classification is needs_follow_up, indicating that additional runtime observation or a deeper code review is required before a final verdict can be issued.
Key Reasons
- Generic postinstall YARA signatures match common network and crypto patterns
- MANIFEST-SENSITIVE-PERM-NATIVEMESSAGING permission declared
- High user count creates amplification risk
- Extension name mimics Microsoft SSO functionality
- No specific malicious payload beyond generic signatures
False Positive Considerations
- generic postinstall YARA rule matches
- high user count
- native messaging permission flagged
- extension name mimics Microsoft SSO functionality
Reviewed 2026-05-23; recommended action: reanalyze; model confidence 66%.
Source Code Not Available
Source code is not available for this version of the extension.
About This Extension
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace
My Apps Secure Sign-in Extension
[email protected]
Edge Translate - Browser Translator | PDF Translation | MV3 | Open Source
[email protected]
Intelbras Cloud
[email protected]
SlingPlayer for DISH Anywhere
Unknown Developer
My Jobscore
[email protected]
种草星球-TikTok爆单神器,商品自动提报采集邀评【永久免费】
[email protected]