Firefox Add-ons Verified

Ultimate New Tab Page - AI Search & Dial

by Dracon
41234b6f-c24a-55f3-a365-9413eda07d18 | v0.5.0
85/ 100
CRITICAL risk
+26 since v0.4.1
Analyst verdict
Do not install

The AI review rates the findings as likely false positive, but the risk score (85/100) still counts them.

Analysis record

Analysed
4 days ago
Version
v0.5.0
Artifact
SHA256 830…F0F
Source
Findings (non-IoC)

Is Ultimate New Tab Page - AI Search & Dial safe?

Ultimate New Tab Page - AI Search & Dial replaces the new tab page with wallpapers, an AI search box, and quick links. The manifest declares no permissions, so the extension cannot read history, cookies, or site data on its own. The scanner did flag seven network findings in bundled chunk files such as chunks/SearchSourceToggles-BGHf6nKQ.js:1:0 and chunks/results-BlGlzKTJ.js:21354:0. Those findings point to fetch or axios calls inside the built JavaScript.

The massive finding count (99,180) comes from two known noise sources. The IoC extractor produced 99,117 matches on string fragments in the minified bundles, things that look like IP addresses or domains but are actually hexadecimal garbage or property names like b.call. The other 56 findings are code-smell rules that fire on any modern JavaScript using fetch, axios, or process.env. No malware signatures matched, and no obfuscation was detected.

The network endpoints in the bundle follow a synthetic pattern (0---netoppofindoppofindstage0apache.supertms.com, 0-0-0-asana-emealer.supertms.com) that resembles generated test data rather than real tracking servers. With no permissions, no malware signatures, and findings explained by scanner quirks on bundled code, the extension does not show evidence of malicious behavior.

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

63 detail rows

YARA Rule Matches

17 rules
SeverityRuleHitsFilesMetadata
LOWcredential generic tokens 1
chunks/results-BlGlzKTJ.js
-
LOWpostinstall file download 6
chunks/SearchSourceToggles-BGHf6nKQ.jschunks/SearchSuggestions-mwZvoVta.jschunks/taste-BjQcbucX.js +3 more
-
LOWNoUseWeakRandom 3
chunks/SearchSourceToggles-BGHf6nKQ.jschunks/SettingsPanel-C7tlHbSk.jschunks/newtab-D0a-KBOX.js
-
LOWpostinstall obfuscation 4
META-INF/cose.manifestMETA-INF/manifest.mfchunks/SearchSourceToggles-BGHf6nKQ.js +1 more
-
LOWpostinstall crypto operations 3
chunks/SearchSourceToggles-BGHf6nKQ.jschunks/results-BlGlzKTJ.jschunks/taste-BjQcbucX.js
-
LOWpostinstall file manipulation 9
chunks/results-BlGlzKTJ.jsbackground.jschunks/SearchSourceToggles-BGHf6nKQ.js +6 more
-
LOWpostinstall system command 7
META-INF/cose.manifestMETA-INF/manifest.mfassets/results-C2PeIwOE.css +4 more
-
LOWpostinstall environment access 5
chunks/SearchSuggestions-mwZvoVta.jschunks/taste-BjQcbucX.jschunks/SettingsPanel-C7tlHbSk.js +2 more
-
LOWpostinstall registry modification 1
chunks/results-BlGlzKTJ.js
-
LOWpostinstall network communication 5
chunks/results-settings-D77eHSMO.jschunks/SearchSourceToggles-BGHf6nKQ.jschunks/SettingsPanel-C7tlHbSk.js +2 more
-
LOWcredential steam data 2
chunks/SearchSourceToggles-BGHf6nKQ.jschunks/results-BlGlzKTJ.js
-
LOWLocalStorageShouldNotBeUsed 3
chunks/SearchSourceToggles-BGHf6nKQ.jschunks/SettingsPanel-C7tlHbSk.jschunks/newtab-D0a-KBOX.js
-
LOWDebuggerStatementsShouldNotBeUsed 1
chunks/results-BlGlzKTJ.js
-
LOWcredential env files 1
chunks/results-BlGlzKTJ.js
-
LOWCerberus 1
chunks/results-BlGlzKTJ.js
-
LOWcredential skype data 1
chunks/results-BlGlzKTJ.js
-
LOWpostinstall persistence mechanism 3
background.jschunks/newtab-D0a-KBOX.jschunks/results-BlGlzKTJ.js
-

Network Indicators

Concrete URLs, domains, IPs, emails, and hashes extracted from the analyzed artifact.

99,116 total
...

Network indicators are queued for lazy loading

Scroll this section into view to load the detailed rows.

Publisher Evidence

Limited evidence

Dracon

Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.

Firefox does not expose the same publisher verification data as IDE stores, so this score is deliberately conservative.

43
Noisy-finding weight
x1.00
Publisher domain
dracon.uk
Observed
Store verification signal
Limited signal
Limited
Extension portfolio
17
Portfolio

12 evidence rows available.

Finding Categories

7
Network
99,116
IoC Indicators

YARA Rules Matched

17 rules(56 hits)
credential generic tokens postinstall file download NoUseWeakRandom postinstall obfuscation postinstall crypto operations postinstall file manipulation postinstall system command postinstall environment access postinstall registry modification postinstall network communication credential steam data LocalStorageShouldNotBeUsed DebuggerStatementsShouldNotBeUsed credential env files Cerberus credential skype data +1 more

Requested Permissions

7 permissions
https://*/*
Dangerous
history

Read and modify your browsing history

High
bookmarks
Medium
topSites
Medium
storage
Low
notifications
Low
alarms
Low

AI Security Report

AI Security Review

Evidence context: threat category none; evidence quality moderate.

The extension Ultimate New Tab Page - AI Search & Dial (version 0.5.0) from developer Dracon presents as a new tab replacement with AI search features. The manifest declares no permissions and no host permissions, which limits its theoretical reach. However, the network_endpoints list contains dozens of suspicious-looking domains following a pattern of subdomain prefixes like "0---" and "0-0-" attached to domains such as supertms.com, canva-apps.cn, and manulife-sinochem.com. These resemble generated test domains or placeholder values rather than legitimate API endpoints.

The scanner produced 99,180 total findings, but the breakdown reveals the nature of the noise. The findings_summary shows 99,117 IoC findings and 56 code-smell findings, with zero malware signatures, zero malware matches, and zero obfuscation findings. The seven network findings all point to chunk files in the build output: chunks/SearchSourceToggles-BGHf6nKQ.js, chunks/SearchSuggestions-mwZvoVta.js, chunks/results-BlGlzKTJ.js (four separate locations), and chunks/taste-BjQcbucX.js. These are webpack/bundler output files where the IoC extractor has flagged string fragments that resemble URLs or IPs. The code-smell findings are YARA rules that trigger on common JavaScript patterns like fetch, axios, and environment variable access — patterns present in any modern bundled extension.

A skeptic would note the sheer volume of findings and the odd network endpoints as red flags. The volume is explained by known scanner behavior: the IoC extractor produces false positives on minified code fragments, IPv6-like hex strings, and property access chains (b.call, h.next). The endpoints follow a synthetic pattern inconsistent with real tracking infrastructure. No credential theft, browser hijack, or proxyware indicators appear. The extension has zero users and no established publisher reputation, but the technical findings do not support malicious function.

Key Reasons

  • 99,117 IoC findings are extractor false positives on minified bundles
  • 56 code-smell findings are generic YARA rules on common JS patterns
  • Zero malware signatures or obfuscation findings
  • Manifest declares no permissions or host permissions
  • Network endpoints follow synthetic test-data pattern

False Positive Considerations

  • IoC extractor garbage on bundled chunks
  • YARA code-smell rules on minified JavaScript
  • Synthetic network endpoint patterns
  • High finding count from known noise sources

Reviewed 2026-09-29; recommended action: suppress false positive; model confidence 82%.

Firefox version history

Risk trend by version

2 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.

Selected
85
Change since first
+26
Change from previous
+26
Versions:
First analyzed version
0.4.1
Sep 26, 2026
Risk range
59 to 85
Across analyzed versions
Latest analyzed version
0.5.0
Sep 27, 2026
Selected version
critical
Version
v0.5.0
4 days ago
Risk score
85
Findings
99180
Change vs previous
+26

Pick any point on the chart to explore that version's code below.

About This Extension

New Tab Ultimate turns every new tab into a calm, focused canvas: a cinematic wallpaper, a glowing clock and search bar, and your favorite sites one click away. No account, no tracking. SEARCH WITH AI ANSWERS - Type in the new-tab search bar and get an AI answer panel with suggestions - Bring your own free Google AI Studio key - it stays on your device and is only ever sent directly to Google - Like sites to tint them, hide sites you never want to see, filter to liked-only for a quiet page - Optional automatic link checks quietly drop confirmed-dead links (404/410) and keep everything else - no clutter, no badges A CANVAS THAT FEELS ALIVE - Rotating cinematic wallpapers (mountains, aurora, ocean) plus custom image URL support with dim and blur controls - Clock, date and search front and center; nothing shouting for attention - Quick-link grid with density, tile and icon sizing, folders and auto-widening layout FAST RIGHT-EDGE SETTINGS - The sidebar is the single config surface: grid, wallpaper, search sources, AI settings, todos - all one click away - Import your existing top sites in one click, or start from curated starters - Optional bookmark dials and history suggestions, each behind a runtime permission you grant only if you want it - Todo reminders with notifications and alarms, all local PRIVACY - No account, no analytics, no tracking, no vendor proxy - Your API key lives in local extension storage; AI requests go straight from your browser to Google's Generative Language API when you search - Link checks are simple HEAD probes (5-second limit); response bodies are never read. Full policy in the privacy policy field below. PERMISSIONS - storage (required): saves your preferences, todos and reminder schedule - bookmarks, history, topSites, notifications, alarms (all optional): only requested when you enable the feature that needs them - HTTPS site access (optional): only for the automatic link checks, granted on the AI results settings page HOW IT WORKS 1. Install - your current new tab is replaced instantly 2. Open settings from the right edge and arrange your grid and wallpaper 3. Optionally paste a free Google AI Studio key for AI answers 4. Every new tab is now your calm launchpad

Frequently Asked Questions