Superhuman Go: AI Assistant
The AI review rates the findings as likely false positive, but the risk score (65/100) still counts them.
Analysis record
- Analysed
- 4 days ago
- Version
- v1.21.0
- Artifact
- SHA256 6C9…1EB
- Source
- Findings (non-IoC)
Evidence ledger
Ranked by severity · findings with a source location link to the code viewer
YARA Rule Matches
18 rules| Severity | Rule | Hits | Files | Metadata |
|---|---|---|---|---|
| LOW | postinstall persistence mechanism | 55 | src/js/8954.libs.chunk.jssrc/js/5457.vendors.chunk.jssrc/js/3327.vendors.chunk.js +52 more | - |
| LOW | credential env files | 31 | src/js/79.libs.chunk.jssrc/js/8954.libs.chunk.jssrc/js/SduiInlineEngineIntegration.common.chunk.js +28 more | - |
| LOW | postinstall file download | 94 | src/js/8137.libs.chunk.jssrc/js/7219.vendors.chunk.jssrc/js/4873.libs.chunk.js +91 more | - |
| LOW | NoUseWeakRandom | 73 | src/js/9970.vendors.chunk.jssrc/js/Grammarly-check.jssrc/js/g2.common.chunk.js +70 more | - |
| LOW | NoUseEval | 2 | src/js/2515.vendors.chunk.jssrc/js/humanWritingReport.common.chunk.js | - |
| LOW | UntrustedContentShouldNotBeIncluded | 1 | src/js/Grammarly-gDocsEarlyInjector.js | - |
| LOW | SQLInjection | 13 | src/js/g2.common.chunk.jssrc/js/3178.libs.chunk.jssrc/js/4905.vendors.chunk.js +10 more | - |
| LOW | LocalStorageShouldNotBeUsed | 16 | src/js/9456.libs.chunk.jssrc/js/7861.libs.chunk.jssrc/js/Grammarly-gDocs.js +13 more | - |
| LOW | credential metamask extension | 1 | src/js/Grammarly.js | - |
| LOW | DebuggerStatementsShouldNotBeUsed | 11 | src/js/Grammarly.jssrc/js/2515.vendors.chunk.jssrc/js/Grammarly-gDocs.js +8 more | - |
| LOW | UsingCommandLineArguments | 1 | src/js/Grammarly-bg.js | - |
| LOW | postinstall crypto operations | 67 | src/js/6273.common.chunk.jssrc/js/1212.vendors.chunk.jssrc/js/8961.libs.chunk.js +64 more | - |
| LOW | postinstall file manipulation | 287 | src/js/6283.libs.chunk.jssrc/js/2023.common.chunk.jssrc/js/8961.libs.chunk.js +284 more | - |
| LOW | postinstall environment access | 3 | src/js/Grammarly.styles.jssrc/inkwell/assets/index-uVYElzgq.jssrc/js/Grammarly-gDocs.styles.js | - |
| LOW | postinstall registry modification | 30 | src/js/2791.vendors.chunk.jssrc/js/Grammarly-sidePanel.jssrc/js/2515.vendors.chunk.js +27 more | - |
| LOW | AlertStatementsShouldNotBeUsed | 1 | src/js/Grammarly-check.js | - |
| LOW | postinstall obfuscation | 134 | src/js/9421.vendors.chunk.jssrc/inkwell/assets/index-BM-moq3b.jssrc/js/Agents-StaticSelectionIntegration.common.chunk.js +131 more | - |
| LOW | postinstall system command | 159 | src/inkwell/assets/index-LtbzZSV1.jssrc/js/2515.vendors.chunk.jssrc/inkwell/assets/index-BM-moq3b.js +156 more | - |
Network Indicators
Concrete URLs, domains, IPs, emails, and hashes extracted from the analyzed artifact.
Network indicators are queued for lazy loading
Scroll this section into view to load the detailed rows.
Publisher Evidence
Limited evidencePublisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.
Chrome does not expose the same publisher verification data as IDE stores, so this score is deliberately conservative.
12 evidence rows available.
Finding Categories
YARA Rules Matched
18 rules(979 hits)Requested Permissions
11 permissionsExchange messages with programs outside the browser
Read and modify cookies on all sites
Access your identity and sign-in tokens
Read data from your clipboard
AI Security Report
AI Security Review
Evidence context: threat category none; evidence quality moderate.
Superhuman Go is published by Grammarly ([email protected]), the widely-used writing assistant with millions of active users. The extension declares no host permissions and requests no special API access, which aligns with a tool that inspects and augments text within standard web forms.
The findings bundle reports 4912 total findings, but this count is driven almost entirely by two known false-positive sources. First, the obfuscation detections (UNICODE_HEAVY and LARGE_BASE64) all appear in vendor chunk files (2515.vendors.chunk.js, 7422.vendors.chunk.js, Grammarly-check.js, etc.). These file paths and naming patterns are characteristic of webpack or esbuild bundled output, where minified third-party libraries are normal. Minification and bundled dependency code routinely trigger unicode and base64 obfuscation rules without indicating malicious intent.
Second, the IoC extractor produced 3559 findings, but none of the network endpoints in the bundle are specific, suspicious domains. The listed endpoints (1w.gy, 3-o.md, 3e3-date.now, 54-i.client.top, account.ppgr.io, adnxs.com, adsrvr.org) are either fragmented property chains from minified code misread as domains, or they are generic advertising/analytics infrastructure. The presence of adnxs.com and adsrvr.org (both legitimate ad networks) in a list of thousands is expected noise from bundled vendor code and does not indicate active malicious behavior. No malware signatures matched the scanned files, and the extension's declared behavior (grammar checking and AI assistance) does not require the hostile capabilities (credential theft, hijacking, proxyware) that would justify the obfuscation findings if they were real.
A skeptic might note that obfuscation findings exist at all, or that the extension does make network calls (NET-WEBSOCKET, NET-FETCH). However, grammar checking inherently requires network communication to reach Grammarly's backend services. The specific network findings are generic API usage patterns found in distributed JavaScript chunks, not indicators of hidden payloads. A legitimate writing-assistant extension must talk to its backend; the obfuscation findings in production bundles are noise, not evidence of concealment. The zero malware signatures, combined with Grammarly's known publisher status and the absence of any suspicious behavioral indicators, makes a malicious verdict unreasonable.
Key Reasons
- Developer is Grammarly ([email protected]), a known, legitimate company with millions of users
- Zero malware signatures matched despite 4912 total findings
- Obfuscation findings are in vendor/libs chunk files, consistent with production bundled code
- No host permissions or dangerous API access patterns
- No typosquatting or impersonation indicators; extension name and description match legitimate product
False Positive Considerations
- Bundled vendor/chunk JavaScript files trigger UNICODE_HEAVY and BASE64 obfuscation rules typical of webpack/esbuild output
- Network findings (NET-WEBSOCKET, NET-FETCH, NET-JQUERY_AJAX) are generic API usage patterns in distributed chunks, not suspicious endpoints
- 3559 IoC findings are from XIOC extractor noise (property chains, loopback IPs, CDN domains); zero malware signatures and no specific suspicious domains indicate false positives
Reviewed 2026-09-29; recommended action: suppress false positive; model confidence 82%.
Chrome version history
Risk trend by version
5 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.
Pick any point on the chart to explore that version's code below.
Source Code Not Available
Source code is not available for this version of the extension.
About This Extension
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace
Grammarly: AI Writing Assistant and Grammar Checker App
[email protected]
Edge Translate - Browser Translator | PDF Translation | MV3 | Open Source
[email protected]
Intelbras Cloud
[email protected]
SlingPlayer for DISH Anywhere
Unknown Developer
My Jobscore
[email protected]
种草星球-TikTok爆单神器,商品自动提报采集邀评【永久免费】
[email protected]