Dark Mode & Custom Themes
The AI review rates the findings as likely false positive, but the risk score (59/100) still counts them.
Analysis record
- Analysed
- 4 weeks ago
- Version
- v1.0.1
- Artifact
- SHA256 538…ECA
- Source
- Findings (non-IoC)
Evidence ledger
Ranked by severity · findings with a source location link to the code viewer
YARA Rule Matches
9 rules| Severity | Rule | Hits | Files | Metadata |
|---|---|---|---|---|
| LOW | postinstall persistence mechanism | 3 | content-scripts/content.jsbackground.jschunks/options-BvuMK7a4.js | - |
| LOW | postinstall crypto operations | 2 | chunks/popup-2fUJvM0_.jschunks/ErrorBoundary-DgC19fYm.js | - |
| LOW | postinstall system command | 9 | background.jsassets/popup-Cfw1exKk.cssassets/options-BPUl-H53.css +6 more | - |
| LOW | postinstall file manipulation | 6 | chunks/popup-2fUJvM0_.jscontent-scripts/content.jschunks/index-DcQvZ-An.js +3 more | - |
| LOW | postinstall environment access | 4 | chunks/sparkles-Zj4uVtAR.jschunks/index-DcQvZ-An.jschunks/options-BvuMK7a4.js +1 more | - |
| LOW | postinstall obfuscation | 3 | content-scripts/content.jschunks/ErrorBoundary-DgC19fYm.jsbackground.js | - |
| LOW | postinstall network communication | 7 | chunks/popup-2fUJvM0_.jscontent-scripts/content.jsMETA-INF/manifest.mf +4 more | - |
| LOW | postinstall file download | 2 | chunks/ErrorBoundary-DgC19fYm.jschunks/options-BvuMK7a4.js | - |
| LOW | NoUseWeakRandom | 2 | chunks/ErrorBoundary-DgC19fYm.jscontent-scripts/content.js | - |
Publisher Evidence
Limited evidenceDracon
Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.
Firefox does not expose the same publisher verification data as IDE stores, so this score is deliberately conservative.
12 evidence rows available.
Finding Categories
YARA Rules Matched
9 rules(38 hits)Requested Permissions
4 permissionsAccess and modify data on every website you visit
AI Security Report
AI Security Review
Evidence context: threat category none; evidence quality moderate.
This Dark Mode extension triggers 94 IoC findings, but the actual code analysis reveals no malware signatures, no obfuscation, and no code-smell patterns. The findings are entirely from the XIOC extractor, which produces well-documented false positives.
The IoC matches are all explainable as extraction errors. Strings like g.bg, a.bg, t.bg, v.theme.id, l.storage, and c.watch are JavaScript property access chains, not network domains. The finding XIOC-DOMAIN-window.location.search is a JavaScript API reference, not a domain. Similarly, this.locationwatcher.run is object property access. These patterns are classic XIOC false positives that occur when the extractor misreads JavaScript syntax as domain names.
The remaining IoC matches are legitimate infrastructure: stripe.com (payment processor), google.com and chromewebstore.google.com (Google services). These are benign and expected in any extension that may reference payment flows or store pages.
Crucially, the findings summary shows zero malware signatures, zero obfuscation findings, and zero code-smell findings. If this were actually malicious, we would expect to see at least one of these categories flagged. The absence of actual malware indicators combined with the clear false-positive nature of the IoC matches indicates this is a benign extension.
Counterargument: A skeptic could argue that the anonymous developer (empty developer_name) and zero user count suggest this could be a new malicious extension attempting to avoid detection. However, this concern is not supported by the code findings. Anonymous publishers do exist for legitimate projects, and the actual security analysis shows no malicious patterns in the code itself. The 94 findings are all explainable as XIOC extraction errors, not evidence of malicious behavior. If this were a stealthy malware, it would likely use obfuscation or contain actual malware signatures—neither of which are present here.
The extension's description matches its category (Dark Mode themes), and there are no browser hijacking indicators, credential theft patterns, or suspicious network domains beyond the false positives.
Key Reasons
- All 94 IoC findings are XIOC false positives from property access chains
- Zero malware signatures detected
- Zero obfuscation findings
- Zero code-smell findings
- IoC matches include legitimate domains (stripe.com, google.com)
False Positive Considerations
- Property access chains misread as domains (g.bg, a.bg, v.theme.id)
- JavaScript API references (window.location.search, this.locationwatcher.run)
- Legitimate infrastructure domains (stripe.com, google.com, chromewebstore.google.com)
- XIOC extractor false positive patterns
Reviewed 2026-05-31; recommended action: suppress false positive; model confidence 85%.
Firefox version history
Risk trend by version
2 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.
Pick any point on the chart to explore that version's code below.
Source Code Not Available
Source code is not available for this version of the extension.
About This Extension
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace