Firefox Add-ons Verified

Dark Mode & Custom Themes

by Dracon · 1 users
40436c89-8ddb-549e-b2e6-8242a28029ed | v1.0.1
59/ 100
MEDIUM risk
+13 since v1.0.0
Analyst verdict
Review before use

The AI review rates the findings as likely false positive, but the risk score (59/100) still counts them.

Analysis record

Analysed
4 weeks ago
Version
v1.0.1
Artifact
SHA256 538…ECA
Source
Findings (non-IoC)

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

41 detail rows

YARA Rule Matches

9 rules
SeverityRuleHitsFilesMetadata
LOWpostinstall file download 2
chunks/ErrorBoundary-DgC19fYm.jschunks/options-BvuMK7a4.js
-
LOWNoUseWeakRandom 2
chunks/ErrorBoundary-DgC19fYm.jscontent-scripts/content.js
-
LOWpostinstall crypto operations 2
chunks/ErrorBoundary-DgC19fYm.jschunks/popup-2fUJvM0_.js
-
LOWpostinstall system command 9
chunks/popup-2fUJvM0_.jschunks/index-DcQvZ-An.jsassets/welcome-CIdKyu6O.css +6 more
-
LOWpostinstall file manipulation 6
chunks/index-DcQvZ-An.jschunks/ErrorBoundary-DgC19fYm.jsbackground.js +3 more
-
LOWpostinstall environment access 4
chunks/index-DcQvZ-An.jschunks/options-BvuMK7a4.jschunks/popup-2fUJvM0_.js +1 more
-
LOWpostinstall obfuscation 3
chunks/ErrorBoundary-DgC19fYm.jsbackground.jscontent-scripts/content.js
-
LOWpostinstall network communication 7
META-INF/manifest.mfchunks/ErrorBoundary-DgC19fYm.jsbackground.js +4 more
-
LOWpostinstall persistence mechanism 3
background.jschunks/options-BvuMK7a4.jscontent-scripts/content.js
-

Publisher Evidence

Limited evidence

Dracon

Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.

Firefox does not expose the same publisher verification data as IDE stores, so this score is deliberately conservative.

47
Noisy-finding weight
x1.00
Publisher domain
dracon.uk
Observed
Store verification signal
Limited signal
Limited
Extension portfolio
17
Portfolio

12 evidence rows available.

Finding Categories

1
Network

YARA Rules Matched

9 rules(38 hits)
postinstall file download NoUseWeakRandom postinstall crypto operations postinstall system command postinstall file manipulation postinstall environment access postinstall obfuscation postinstall network communication postinstall persistence mechanism

Requested Permissions

4 permissions
<all_urls>

Access and modify data on every website you visit

Dangerous
tabs
Medium
storage
Low
alarms
Low

AI Security Report

AI Security Review

Evidence context: threat category none; evidence quality moderate.

This Dark Mode extension triggers 94 IoC findings, but the actual code analysis reveals no malware signatures, no obfuscation, and no code-smell patterns. The findings are entirely from the XIOC extractor, which produces well-documented false positives.

The IoC matches are all explainable as extraction errors. Strings like g.bg, a.bg, t.bg, v.theme.id, l.storage, and c.watch are JavaScript property access chains, not network domains. The finding XIOC-DOMAIN-window.location.search is a JavaScript API reference, not a domain. Similarly, this.locationwatcher.run is object property access. These patterns are classic XIOC false positives that occur when the extractor misreads JavaScript syntax as domain names.

The remaining IoC matches are legitimate infrastructure: stripe.com (payment processor), google.com and chromewebstore.google.com (Google services). These are benign and expected in any extension that may reference payment flows or store pages.

Crucially, the findings summary shows zero malware signatures, zero obfuscation findings, and zero code-smell findings. If this were actually malicious, we would expect to see at least one of these categories flagged. The absence of actual malware indicators combined with the clear false-positive nature of the IoC matches indicates this is a benign extension.

Counterargument: A skeptic could argue that the anonymous developer (empty developer_name) and zero user count suggest this could be a new malicious extension attempting to avoid detection. However, this concern is not supported by the code findings. Anonymous publishers do exist for legitimate projects, and the actual security analysis shows no malicious patterns in the code itself. The 94 findings are all explainable as XIOC extraction errors, not evidence of malicious behavior. If this were a stealthy malware, it would likely use obfuscation or contain actual malware signatures—neither of which are present here.

The extension's description matches its category (Dark Mode themes), and there are no browser hijacking indicators, credential theft patterns, or suspicious network domains beyond the false positives.

Key Reasons

  • All 94 IoC findings are XIOC false positives from property access chains
  • Zero malware signatures detected
  • Zero obfuscation findings
  • Zero code-smell findings
  • IoC matches include legitimate domains (stripe.com, google.com)

False Positive Considerations

  • Property access chains misread as domains (g.bg, a.bg, v.theme.id)
  • JavaScript API references (window.location.search, this.locationwatcher.run)
  • Legitimate infrastructure domains (stripe.com, google.com, chromewebstore.google.com)
  • XIOC extractor false positive patterns

Reviewed 2026-05-31; recommended action: suppress false positive; model confidence 85%.

Firefox version history

Risk trend by version

2 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.

Selected
59
Change since first
+13
Change from previous
+13
Versions:
First analyzed version
1.0.0
May 30, 2026
Risk range
46 to 59
Across analyzed versions
Latest analyzed version
1.0.1
Sep 3, 2026
Selected version
medium
Version
v1.0.1
4 weeks ago
Risk score
59
Findings
41
Change vs previous
+13

Pick any point on the chart to explore that version's code below.

About This Extension

Turn off the lights without losing the plot. Most dark modes desaturate your photos and make videos look like X-rays. This one doesn't. Dark Mode &amp; Custom Themes applies real CSS color overrides to every site you visit — your images stay vivid, videos stay crisp, and graphics stay on-brand. It's the dark mode that actually respects your content. 🖤 11 hand-crafted themes Midnight, Rose Pine, Gruvbox Dark, Dracula, Nord, Catppuccin, Graphite, Light, Sepia, AMOLED, Ocean — each tuned for readability and personality. 🎨 Per-site themes Assign a different vibe to work, social, and entertainment. Your developer docs stay sharp in Gruvbox while YouTube kicks back in Midnight. ✨ Build your own Custom 4-color palette editor with live preview. Pick background, text, link, and accent colors — no code. Brightness, contrast, sepia, warmth, grayscale sliders fine-tune the rest. 🔤 Font override that doesn't break icons Swap your reading font without nuking Font Awesome or emoji. Icon libraries stay intact while body text transforms. ⌨️ Alt+Shift+D toggles from anywhere. Shadow DOM support handles modern web apps. All data stays on your device — no accounts, no tracking, no ads.

Frequently Asked Questions