Ultimate New Tab Page - AI Search & Dial
The AI review rates the findings as likely false positive, but the risk score (85/100) still counts them.
Analysis record
- Analysed
- 4 days ago
- Version
- v0.5.0
- Artifact
- SHA256 830…F0F
- Source
- Findings (non-IoC)
Is Ultimate New Tab Page - AI Search & Dial safe?
Ultimate New Tab Page - AI Search & Dial replaces the new tab page with wallpapers, an AI search box, and quick links. The manifest declares no permissions, so the extension cannot read history, cookies, or site data on its own. The scanner did flag seven network findings in bundled chunk files such as chunks/SearchSourceToggles-BGHf6nKQ.js:1:0 and chunks/results-BlGlzKTJ.js:21354:0. Those findings point to fetch or axios calls inside the built JavaScript.
The massive finding count (99,180) comes from two known noise sources. The IoC extractor produced 99,117 matches on string fragments in the minified bundles, things that look like IP addresses or domains but are actually hexadecimal garbage or property names like b.call. The other 56 findings are code-smell rules that fire on any modern JavaScript using fetch, axios, or process.env. No malware signatures matched, and no obfuscation was detected.
The network endpoints in the bundle follow a synthetic pattern (0---netoppofindoppofindstage0apache.supertms.com, 0-0-0-asana-emealer.supertms.com) that resembles generated test data rather than real tracking servers. With no permissions, no malware signatures, and findings explained by scanner quirks on bundled code, the extension does not show evidence of malicious behavior.
Evidence ledger
Ranked by severity · findings with a source location link to the code viewer
YARA Rule Matches
17 rules| Severity | Rule | Hits | Files | Metadata |
|---|---|---|---|---|
| LOW | credential generic tokens | 1 | chunks/results-BlGlzKTJ.js | - |
| LOW | postinstall file download | 6 | chunks/SearchSourceToggles-BGHf6nKQ.jschunks/SearchSuggestions-mwZvoVta.jschunks/taste-BjQcbucX.js +3 more | - |
| LOW | NoUseWeakRandom | 3 | chunks/SearchSourceToggles-BGHf6nKQ.jschunks/SettingsPanel-C7tlHbSk.jschunks/newtab-D0a-KBOX.js | - |
| LOW | postinstall obfuscation | 4 | META-INF/cose.manifestMETA-INF/manifest.mfchunks/SearchSourceToggles-BGHf6nKQ.js +1 more | - |
| LOW | postinstall crypto operations | 3 | chunks/SearchSourceToggles-BGHf6nKQ.jschunks/results-BlGlzKTJ.jschunks/taste-BjQcbucX.js | - |
| LOW | postinstall file manipulation | 9 | chunks/results-BlGlzKTJ.jsbackground.jschunks/SearchSourceToggles-BGHf6nKQ.js +6 more | - |
| LOW | postinstall system command | 7 | META-INF/cose.manifestMETA-INF/manifest.mfassets/results-C2PeIwOE.css +4 more | - |
| LOW | postinstall environment access | 5 | chunks/SearchSuggestions-mwZvoVta.jschunks/taste-BjQcbucX.jschunks/SettingsPanel-C7tlHbSk.js +2 more | - |
| LOW | postinstall registry modification | 1 | chunks/results-BlGlzKTJ.js | - |
| LOW | postinstall network communication | 5 | chunks/results-settings-D77eHSMO.jschunks/SearchSourceToggles-BGHf6nKQ.jschunks/SettingsPanel-C7tlHbSk.js +2 more | - |
| LOW | credential steam data | 2 | chunks/SearchSourceToggles-BGHf6nKQ.jschunks/results-BlGlzKTJ.js | - |
| LOW | LocalStorageShouldNotBeUsed | 3 | chunks/SearchSourceToggles-BGHf6nKQ.jschunks/SettingsPanel-C7tlHbSk.jschunks/newtab-D0a-KBOX.js | - |
| LOW | DebuggerStatementsShouldNotBeUsed | 1 | chunks/results-BlGlzKTJ.js | - |
| LOW | credential env files | 1 | chunks/results-BlGlzKTJ.js | - |
| LOW | Cerberus | 1 | chunks/results-BlGlzKTJ.js | - |
| LOW | credential skype data | 1 | chunks/results-BlGlzKTJ.js | - |
| LOW | postinstall persistence mechanism | 3 | background.jschunks/newtab-D0a-KBOX.jschunks/results-BlGlzKTJ.js | - |
Network Indicators
Concrete URLs, domains, IPs, emails, and hashes extracted from the analyzed artifact.
Network indicators are queued for lazy loading
Scroll this section into view to load the detailed rows.
Publisher Evidence
Limited evidenceDracon
Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.
Firefox does not expose the same publisher verification data as IDE stores, so this score is deliberately conservative.
12 evidence rows available.
Finding Categories
YARA Rules Matched
17 rules(56 hits)Requested Permissions
7 permissionsRead and modify your browsing history
AI Security Report
AI Security Review
Evidence context: threat category none; evidence quality moderate.
The extension Ultimate New Tab Page - AI Search & Dial (version 0.5.0) from developer Dracon presents as a new tab replacement with AI search features. The manifest declares no permissions and no host permissions, which limits its theoretical reach. However, the network_endpoints list contains dozens of suspicious-looking domains following a pattern of subdomain prefixes like "0---" and "0-0-" attached to domains such as supertms.com, canva-apps.cn, and manulife-sinochem.com. These resemble generated test domains or placeholder values rather than legitimate API endpoints.
The scanner produced 99,180 total findings, but the breakdown reveals the nature of the noise. The findings_summary shows 99,117 IoC findings and 56 code-smell findings, with zero malware signatures, zero malware matches, and zero obfuscation findings. The seven network findings all point to chunk files in the build output: chunks/SearchSourceToggles-BGHf6nKQ.js, chunks/SearchSuggestions-mwZvoVta.js, chunks/results-BlGlzKTJ.js (four separate locations), and chunks/taste-BjQcbucX.js. These are webpack/bundler output files where the IoC extractor has flagged string fragments that resemble URLs or IPs. The code-smell findings are YARA rules that trigger on common JavaScript patterns like fetch, axios, and environment variable access — patterns present in any modern bundled extension.
A skeptic would note the sheer volume of findings and the odd network endpoints as red flags. The volume is explained by known scanner behavior: the IoC extractor produces false positives on minified code fragments, IPv6-like hex strings, and property access chains (b.call, h.next). The endpoints follow a synthetic pattern inconsistent with real tracking infrastructure. No credential theft, browser hijack, or proxyware indicators appear. The extension has zero users and no established publisher reputation, but the technical findings do not support malicious function.
Key Reasons
- 99,117 IoC findings are extractor false positives on minified bundles
- 56 code-smell findings are generic YARA rules on common JS patterns
- Zero malware signatures or obfuscation findings
- Manifest declares no permissions or host permissions
- Network endpoints follow synthetic test-data pattern
False Positive Considerations
- IoC extractor garbage on bundled chunks
- YARA code-smell rules on minified JavaScript
- Synthetic network endpoint patterns
- High finding count from known noise sources
Reviewed 2026-09-29; recommended action: suppress false positive; model confidence 82%.
Firefox version history
Risk trend by version
2 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.
Pick any point on the chart to explore that version's code below.
Source Code Not Available
Source code is not available for this version of the extension.
About This Extension
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace