Chrome Web Store Verified

My Apps Secure Sign-in Extension

by [email protected] · 2.0M users · 2.2 rating
4764f100-617a-5407-9abe-5af17cbf1f1a | v8.2.1.252
62/ 100
MEDIUM risk
+51 since v8.2.1.250
Risk verdict
Review before use

Score-based assessment (medium risk, 62/100). No analyst review available.

Analysis record

Analysed
2 weeks ago
Version
v8.2.1.252
Artifact
SHA256 3B3…004
Source
Findings (non-IoC)

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

61 detail rows

YARA Rule Matches

9 rules
SeverityRuleHitsFilesMetadata
LOWpostinstall persistence mechanism 1
background.js
-
LOWLocalStorageShouldNotBeUsed 7
js/ExtensionIdentifier.jspopup/js/LoggedInPopup.jscommon/Log.js +4 more
-
LOWpostinstall network communication 18
manifest.jsonjs/CaptureListOfApps.jsjs/ListenSamlResponse.js +15 more
-
LOWpostinstall crypto operations 5
popup/js/LoggedInPopup.jspopup/js/SSOPopup.jscommon/Log.js +2 more
-
LOWpostinstall file manipulation 6
popup/js/LoggedInPopup.jscommon/Log.jsjs/PasswordField.js +3 more
-
LOWpostinstall environment access 1
js/Redirection.js
-
LOWpostinstall obfuscation 8
js/ListenSamlResponse.jspopup/js/LoggedInPopup.jsjs/TamperSaml.js +5 more
-
LOWpostinstall system command 7
js/ListenSamlResponse.jspopup/js/LoggedInPopup.jsjs/TamperSaml.js +4 more
-
LOWpostinstall file download 4
popup/js/LoggedInPopup.jscommon/Log.jsbackground.js +1 more
-

Network Indicators

Concrete URLs, domains, IPs, emails, and hashes extracted from the analyzed artifact.

100 total
...

Network indicators are queued for lazy loading

Scroll this section into view to load the detailed rows.

Publisher Evidence

Low

[email protected]

Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.

Chrome does not expose the same publisher verification data as IDE stores, so this score is deliberately conservative.

89
Noisy-finding weight
x1.00
Publisher domain
microsoft.com
Trusted match
Store verification signal
Limited signal
Limited
Extension portfolio
653
Portfolio

12 evidence rows available.

Finding Categories

3
Network
100
IoC Indicators

YARA Rules Matched

9 rules(57 hits)
postinstall persistence mechanism LocalStorageShouldNotBeUsed postinstall network communication postinstall crypto operations postinstall file manipulation postinstall environment access postinstall obfuscation postinstall system command postinstall file download

Requested Permissions

10 permissions
https://*/*
Dangerous
http://*/*
Dangerous
tabs
Medium
activeTab
Medium
scripting
Low
contextMenus
Low
unlimitedStorage
Low
webNavigation
Low
storage
Low
declarativeNetRequest
Low

Security Analysis Summary

Security Analysis Overview

My Apps Secure Sign-in Extension is a Chrome Web Store extension published by [email protected]. Version 8.2.1.252 has been analyzed by the Risky Plugins security platform, receiving a risk score of 61.93/100 (MEDIUM risk) based on 161 security findings.

Risk Assessment

This extension presents moderate security risk. Several findings were detected that may warrant attention. Users should carefully review the permissions and findings before installation.

Findings Breakdown

  • Medium: 104 finding(s)
  • Low: 57 finding(s)

What Was Analyzed

The security assessment covers multiple analysis categories:

  • Malware Detection: YARA rule matching against 2,400+ malware signatures
  • Secret Detection: Scanning for exposed API keys, tokens, and credentials
  • Static Analysis: Code-level security analysis for common vulnerability patterns
  • Network Analysis: Detection of suspicious network communications and endpoints
  • Obfuscation Detection: Identification of code obfuscation techniques

Developer Information

My Apps Secure Sign-in Extension is published by [email protected] on the Chrome Web Store marketplace. The extension has approximately 2.0M users.

Recommendation

This extension is not recommended for installation without thorough manual review. Consider alternatives with lower risk scores, or contact the developer to address the identified security concerns.

Chrome version history

Risk trend by version

3 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.

Selected
62
Change since first
+4
Change from previous
+51
Versions:
First analyzed version
8.2.1.196
Apr 6, 2026
Risk range
11 to 62
Across analyzed versions
Latest analyzed version
8.2.1.252
Sep 15, 2026
Selected version
medium
Version
v8.2.1.252
2 weeks ago
Risk score
62
Findings
161
Change vs previous
+51

Pick any point on the chart to explore that version's code below.

About This Extension

This extension is required for both App Proxy link translation and application password-based single sign-on. It may also be optionally used to launch the My Apps portal to search the applications you have access to. With this extension you can: • Sign into password-based single sign-on applications- both directly from the application's login page and from the My Apps portal • Access internal company URLs while remote • Launch into the My Apps portal to search across the applications you have access to Learn more: • App proxy link translation: https://learn.microsoft.com/en-us/entra/identity/app-proxy/application-proxy-configure-hard-coded-link-translation • Password-based single sign-on: https://learn.microsoft.com/en-us/entra/identity/enterprise-apps/configure-password-single-sign-on-non-gallery-applications • My Apps portal: https://learn.microsoft.com/en-us/entra/identity/enterprise-apps/myapps-overview THIRD-PARTY SOFTWARE NOTICES AND INFORMATION This software is based on or incorporates material from the projects listed below (collectively, "Third Party Code"). Microsoft is not the original author of the Third Party Code. The original copyright notice and license, under which Microsoft received such Third Party Code, are set forth below. Microsoft reserves all rights not expressly granted herein, whether by implication, estoppel or otherwise. JavaScript Zlib Library Copyright (c) 2012 imaya The MIT License Permission is hereby granted, free of charge, to any person obtaining a copy of this software and associated documentation files (the "Software"), to deal in the Software without restriction, including without limitation the rights to use, copy, modify, merge, publish, distribute, sublicense, and/or sell copies of the Software, and to permit persons to whom the Software is furnished to do so, subject to the following conditions: The above copyright notice and this permission notice shall be included in all copies or substantial portions of the Software. THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE. JavaScript autoComplete v1.0.4 Copyright (c) 2014 Simon Steinberger / Pixabay The MIT License Permission is hereby granted, free of charge, to any person obtaining a copy of this software and associated documentation files (the "Software"), to deal in the Software without restriction, including without limitation the rights to use, copy, modify, merge, publish, distribute, sublicense, and/or sell copies of the Software, and to permit persons to whom the Software is furnished to do so, subject to the following conditions: The above copyright notice and this permission notice shall be included in all copies or substantial portions of the Software. THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE.

Frequently Asked Questions