Is "Brightery OTP Vault & Autofill" on Chrome Web Store Safe to Install?

[email protected] · chrome · v2.0.0

Brightery OTP Vault & Autofill is a robust and user-friendly browser extension designed to enhance the security and convenience of managing Two-Factor Authentication (2FA). This comprehensive tool allows users to efficiently scan QR codes, manage their one-time password (OTP) accounts, and effortlessly autofill OTP codes directly within the browser environment. Specifically crafted to streamline the 2FA experience, Brightery OTP Vault & Autofill integrates seamlessly with the Brightery authentication platform, delivering secure synchronization and access to your code tokens across multiple devices. Once installed, the extension presents an intuitive popup dashboard that centralizes all your configured OTP accounts in a clean, organized interface. Each account’s essential details, such as issuer name, username, and the current OTP code, are displayed clearly for at-a-glance access. Adding new OTP accounts is simplified through the built-in QR code scanner, which supports adding tokens by scanning images on web pages, screenshots, or directly via webcam, eliminating the need for manual input. The tool also allows for easy account management—users can quickly delete outdated credentials or rearrange tokens to maintain a clutter-free and secure environment. A key highlight of Brightery OTP Vault & Autofill is its intelligent autofill engine. It detects 2FA input fields on websites automatically and provides inline prompts or context menu options to insert the correct OTP without the need for manual typing. This feature significantly speeds up login workflows and reduces user errors. The extension’s context menu shortcuts further enhance this ease-of-use by offering quick access to scanning QR codes, copying OTP codes, or autofilling authentication fields with just a right-click, blending naturally into everyday browsing habits. Security and privacy are core to Brightery OTP Vault & Autofill. The extension leverages the Brightery backend API to securely store, synchronize, and retrieve OTP tokens, ensuring your authentication codes are protected and accessible only to authenticated users. Feedback mechanisms provide confirmation when critical actions like copying or deleting tokens occur, reducing accidental mistakes. Compatibility with popular OTP standards such as TOTP and HOTP ensures broad applicability across numerous services and platforms. The extension is thoughtfully designed with a modern, minimalistic interface suitable for both power users managing numerous 2FA accounts and casual users seeking a hassle-free solution to 2FA management. By carefully controlling required browser permissions, Brightery OTP Vault & Autofill handles QR code scanning, clipboard operations, and data encryption efficiently without compromising privacy or responsiveness. Whether for personal use, business accounts, or developer environments, this extension brings enhanced control, speed, and security to your 2FA process directly through the browser. Key Features: - Unified OTP Dashboard: View, copy, and manage all your one-time password accounts in a single, easy-to-navigate popup interface. - QR Code Scanning: Quickly add new OTP accounts by scanning QR codes from web page images, screenshots, or webcam through the built-in scanner or context menu. - Autofill Engine: Automatically detects two-factor authentication fields on websites and offers inline or context menu options to accurately fill OTP codes, reducing login friction. - Secure Account Synchronization: Synchronized storage and retrieval of OTP tokens via the Brightery authentication API, ensuring your data is secure and accessible across all devices. - Context Menu Shortcuts: Convenient right-click menu options to scan QR codes, autofill OTP codes, or copy one-time passwords instantly from your browser. - Account Management: Easily add, delete, and organize multiple OTP accounts, complete with issuer and user details, to stay organized and maintain security integrity. - Dynamic Code Copying: One-click copy functionality with clipboard integration to quickly transfer OTP codes when manual entry is necessary. How It Works: 1. Install Brightery OTP Vault & Autofill from your browser’s extension store. 2. Open the extension popup to view existing OTP accounts, manage them, or add new tokens. 3. To add a new OTP account, scan a QR code using the popup scanner or right-click context menu options—tokens are securely imported without manual input. 4. When logging into a site requiring 2FA, use the autofill feature by right-clicking the input field and selecting “Autofill OTP Code” or accepting inline prompts. 5. If autofill is not preferred, simply open the extension popup and copy the current OTP code with one click. 6. Maintain your OTP account list by removing expired or compromised tokens directly through the dashboard interface. 7. All account data and codes are synchronized securely through the integrated Brightery backend, allowing seamless access on all authenticated devices. Privacy: - No personal data collected. Only OTP account metadata and codes (as entered or scanned) are stored securely via the Brightery authentication backend. See our privacy policy for details.

Risk Assessment

Analyzed
61.3
out of 100
MEDIUM

80 security findings detected across all analyzers

Chrome extension requesting 9 permissions

Severity Breakdown

0
Critical
23
High
57
Medium
0
Low
0
Info

Finding Categories

23
Malware Signatures
10
Network
46
IoC Indicators

YARA Rules Matched

6 rules(23 hits)
postinstall network communication postinstall file manipulation postinstall file download postinstall system command postinstall obfuscation postinstall crypto operations

Requested Permissions

9 permissions
<all_urls>

Access and modify data on every website you visit

Dangerous
activeTab
Medium
tabs
Medium
contextMenus
Low
scripting
Low
storage
Low
clipboardWrite
Low
notifications
Low
https://auth.brightery.com/*
Low

About This Extension

Brightery OTP Vault & Autofill is a robust and user-friendly browser extension designed to enhance the security and convenience of managing Two-Factor Authentication (2FA). This comprehensive tool allows users to efficiently scan QR codes, manage their one-time password (OTP) accounts, and effortlessly autofill OTP codes directly within the browser environment. Specifically crafted to streamline the 2FA experience, Brightery OTP Vault & Autofill integrates seamlessly with the Brightery authentication platform, delivering secure synchronization and access to your code tokens across multiple devices. Once installed, the extension presents an intuitive popup dashboard that centralizes all your configured OTP accounts in a clean, organized interface. Each account’s essential details, such as issuer name, username, and the current OTP code, are displayed clearly for at-a-glance access. Adding new OTP accounts is simplified through the built-in QR code scanner, which supports adding tokens by scanning images on web pages, screenshots, or directly via webcam, eliminating the need for manual input. The tool also allows for easy account management—users can quickly delete outdated credentials or rearrange tokens to maintain a clutter-free and secure environment. A key highlight of Brightery OTP Vault & Autofill is its intelligent autofill engine. It detects 2FA input fields on websites automatically and provides inline prompts or context menu options to insert the correct OTP without the need for manual typing. This feature significantly speeds up login workflows and reduces user errors. The extension’s context menu shortcuts further enhance this ease-of-use by offering quick access to scanning QR codes, copying OTP codes, or autofilling authentication fields with just a right-click, blending naturally into everyday browsing habits. Security and privacy are core to Brightery OTP Vault & Autofill. The extension leverages the Brightery backend API to securely store, synchronize, and retrieve OTP tokens, ensuring your authentication codes are protected and accessible only to authenticated users. Feedback mechanisms provide confirmation when critical actions like copying or deleting tokens occur, reducing accidental mistakes. Compatibility with popular OTP standards such as TOTP and HOTP ensures broad applicability across numerous services and platforms. The extension is thoughtfully designed with a modern, minimalistic interface suitable for both power users managing numerous 2FA accounts and casual users seeking a hassle-free solution to 2FA management. By carefully controlling required browser permissions, Brightery OTP Vault & Autofill handles QR code scanning, clipboard operations, and data encryption efficiently without compromising privacy or responsiveness. Whether for personal use, business accounts, or developer environments, this extension brings enhanced control, speed, and security to your 2FA process directly through the browser. Key Features: - Unified OTP Dashboard: View, copy, and manage all your one-time password accounts in a single, easy-to-navigate popup interface. - QR Code Scanning: Quickly add new OTP accounts by scanning QR codes from web page images, screenshots, or webcam through the built-in scanner or context menu. - Autofill Engine: Automatically detects two-factor authentication fields on websites and offers inline or context menu options to accurately fill OTP codes, reducing login friction. - Secure Account Synchronization: Synchronized storage and retrieval of OTP tokens via the Brightery authentication API, ensuring your data is secure and accessible across all devices. - Context Menu Shortcuts: Convenient right-click menu options to scan QR codes, autofill OTP codes, or copy one-time passwords instantly from your browser. - Account Management: Easily add, delete, and organize multiple OTP accounts, complete with issuer and user details, to stay organized and maintain security integrity. - Dynamic Code Copying: One-click copy functionality with clipboard integration to quickly transfer OTP codes when manual entry is necessary. How It Works: 1. Install Brightery OTP Vault & Autofill from your browser’s extension store. 2. Open the extension popup to view existing OTP accounts, manage them, or add new tokens. 3. To add a new OTP account, scan a QR code using the popup scanner or right-click context menu options—tokens are securely imported without manual input. 4. When logging into a site requiring 2FA, use the autofill feature by right-clicking the input field and selecting “Autofill OTP Code” or accepting inline prompts. 5. If autofill is not preferred, simply open the extension popup and copy the current OTP code with one click. 6. Maintain your OTP account list by removing expired or compromised tokens directly through the dashboard interface. 7. All account data and codes are synchronized securely through the integrated Brightery backend, allowing seamless access on all authenticated devices. Privacy: - No personal data collected. Only OTP account metadata and codes (as entered or scanned) are stored securely via the Brightery authentication backend. See our privacy policy for details.

Detailed Findings

34 total

YARA Rule Matches

6 rules

Indicators of Compromise

Network indicators, suspicious strings, and potential IoCs extracted during analysis

URLs
13
IP Addresses
2
Domains
32
Strings
46

All Indicators · 46

Domain
detected Domain: targetselectorinfo.id

XIOC detected Domain: targetselectorinfo.id

extracted_from_files

Domain
detected Domain: event.target

XIOC detected Domain: event.target

extracted_from_files

URL
detected URL: https://auth.brightery.com/api/api.php?entity=otp&action=list',

XIOC detected URL: https://auth.brightery.com/api/api.php?entity=otp&action=list',

extracted_from_files

URL
detected URL: https://auth.brightery.com

XIOC detected URL: https://auth.brightery.com

extracted_from_files

URL
detected URL: https://unpkg.com/@zxing/library@latest

XIOC detected URL: https://unpkg.com/@zxing/library@latest

extracted_from_files

URL
detected URL: https://auth.brightery.com/*

XIOC detected URL: https://auth.brightery.com/*

extracted_from_files

URL
detected URL: https://auth.brightery.com/;

XIOC detected URL: https://auth.brightery.com/;

extracted_from_files

URL
detected URL: https://auth.brightery.com/

XIOC detected URL: https://auth.brightery.com/

extracted_from_files

URL
detected URL: http://www.w3.org/2000/svg

XIOC detected URL: http://www.w3.org/2000/svg

extracted_from_files

URL
detected URL: https://fontawesome.com

XIOC detected URL: https://fontawesome.com

extracted_from_files

URL
detected URL: https://fontawesome.com/license/free

XIOC detected URL: https://fontawesome.com/license/free

extracted_from_files

Domain
detected Domain: this.data

XIOC detected Domain: this.data

extracted_from_files

Domain
detected Domain: apiresponse.data

XIOC detected Domain: apiresponse.data

extracted_from_files

Domain
detected Domain: tempinput.select

XIOC detected Domain: tempinput.select

extracted_from_files

Domain
detected Domain: unpkg.com

XIOC detected Domain: unpkg.com

extracted_from_files

Other
detected Email: [email protected]

XIOC detected Email: [email protected]

extracted_from_files

URL
detected URL: https://auth.brightery.com/api/api.php

XIOC detected URL: https://auth.brightery.com/api/api.php

extracted_from_files

URL
detected URL: http://en.wikipedia.org/wiki/Bresenham's_line_algorithm

XIOC detected URL: http://en.wikipedia.org/wiki/Bresenham's_line_algorithm

extracted_from_files

URL
detected URL: https://clients2.google.com/service/update2/crx

XIOC detected URL: https://clients2.google.com/service/update2/crx

extracted_from_files

Domain
detected Domain: rlast.degree

XIOC detected Domain: rlast.degree

extracted_from_files

Domain
detected Domain: errorlocator.degree

XIOC detected Domain: errorlocator.degree

extracted_from_files

Domain
detected Domain: q.top

XIOC detected Domain: q.top

extracted_from_files

Domain
detected Domain: clients2.google.com

XIOC detected Domain: clients2.google.com

extracted_from_files

Domain
detected Domain: brightery.com

XIOC detected Domain: brightery.com

extracted_from_files

Domain
detected Domain: www.w3.org

XIOC detected Domain: www.w3.org

extracted_from_files

Domain
detected Domain: fontawesome.com

XIOC detected Domain: fontawesome.com

extracted_from_files

Domain
detected Domain: this.field.zero

XIOC detected Domain: this.field.zero

extracted_from_files

Domain
detected Domain: bytes.map

XIOC detected Domain: bytes.map

extracted_from_files

Domain
detected Domain: a.degree

XIOC detected Domain: a.degree

extracted_from_files

Domain
detected Domain: b.degree

XIOC detected Domain: b.degree

extracted_from_files

Domain
detected Domain: field.zero

XIOC detected Domain: field.zero

extracted_from_files

Domain
detected Domain: field.one

XIOC detected Domain: field.one

extracted_from_files

Domain
detected Domain: r.degree

XIOC detected Domain: r.degree

extracted_from_files

Domain
detected Domain: targetselectorinfo.name

XIOC detected Domain: targetselectorinfo.name

extracted_from_files

IP
detected Domain: en.wikipedia.org

XIOC detected Domain: en.wikipedia.org

extracted_from_files

Domain
detected Domain: object.prototype.hasownproperty.call

XIOC detected Domain: object.prototype.hasownproperty.call

extracted_from_files

URL
detected URL: https://auth.brightery.com/api/api.php?entity=auth&action=get_extension_token',

XIOC detected URL: https://auth.brightery.com/api/api.php?entity=auth&action=get_extension_token',

extracted_from_files

Domain
detected Domain: this.zero

XIOC detected Domain: this.zero

extracted_from_files

Domain
detected Domain: this.one

XIOC detected Domain: this.one

extracted_from_files

Domain
detected Domain: genericgfpoly.prototype.degree

XIOC detected Domain: genericgfpoly.prototype.degree

extracted_from_files

Domain
detected Domain: lastfocusedinput.id

XIOC detected Domain: lastfocusedinput.id

extracted_from_files

Domain
detected Domain: lastfocusedinput.name

XIOC detected Domain: lastfocusedinput.name

extracted_from_files

Domain
detected Domain: auth.brightery.com

XIOC detected Domain: auth.brightery.com

extracted_from_files

Domain
detected Domain: tab.id

XIOC detected Domain: tab.id

extracted_from_files

Domain
detected Domain: data.data

XIOC detected Domain: data.data

extracted_from_files

Domain
detected Domain: sender.tab.id

XIOC detected Domain: sender.tab.id

extracted_from_files

Security Analysis Summary

Security Analysis Overview

Brightery OTP Vault & Autofill is a Chrome Web Store extension published by [email protected]. Version 2.0.0 has been analyzed by the Risky Plugins security platform, receiving a risk score of 61.3/100 (MEDIUM risk) based on 80 security findings.

Risk Assessment

This extension presents high security risk. Significant concerns were identified during analysis. It is not recommended for use in sensitive or production environments without thorough review.

Findings Breakdown

  • High: 23 finding(s)
  • Medium: 57 finding(s)

What Was Analyzed

The security assessment covers multiple analysis categories:

  • Malware Detection: YARA rule matching against 2,400+ malware signatures
  • Secret Detection: Scanning for exposed API keys, tokens, and credentials
  • Static Analysis: Code-level security analysis for common vulnerability patterns
  • Network Analysis: Detection of suspicious network communications and endpoints
  • Obfuscation Detection: Identification of code obfuscation techniques

Developer Information

Brightery OTP Vault & Autofill is published by [email protected] on the Chrome Web Store marketplace. The extension has approximately 31 users.

Recommendation

This extension is not recommended for installation without thorough manual review. Consider alternatives with lower risk scores, or contact the developer to address the identified security concerns.

Frequently Asked Questions