Chrome Web Store

gTab

by [email protected] · 18 users
4a388ebd-fb19-5b2e-8c3a-9e1113b11ff8 | v1.7.41.101
0/ 100
MINIMAL risk
Analyst verdict
Confirmed risk

From the RiskyPlugins AI security review of the observed evidence.

Analysis record

Analysed
10 months ago
Version
v1.7.41.101
Artifact
SHA256 7CE…076
Source
Findings (non-IoC)

No Findings

All security checks passed

Publisher Evidence

Limited evidence

[email protected]

Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.

Chrome does not expose the same publisher verification data as IDE stores, so this score is deliberately conservative.

34
Noisy-finding weight
x1.00
Publisher domain
No domain
Missing
Store verification signal
Limited signal
Limited
Extension portfolio
8
Portfolio

12 evidence rows available.

No Threats Detected

This extension passed all security checks

AI Security Report

AI Security Review

Evidence context: threat category browser hijack; evidence quality strong.

Browser Hijacking Pattern Detected

The gTab extension (version 1.7.41.101) exhibits clear browser hijacking behavior. While the store description claims the extension "can set wallpaper from Google or Baidu image," the actual findings reveal search engine redirection infrastructure. The IoC findings contain 12 distinct search engine domains with query parameter templates: https://www.so.com/s?ie=, https://www.quendu.com/search?q=, https://www.qwant.com/?q=, https://search.seznam.cz/favicon.ico, https://www.nona.de/?q=, and https://panda-search.org/search/?q=. These URLs follow the exact pattern described in the browser hijacking threat model: dynamic URL template construction with query parameters (?q=, ?ie=, ?query=).

Category Mismatch

The extension's declared purpose (wallpaper customization) does not match its actual behavior (search query redirection). A wallpaper extension should not contain embedded search engine URLs with query injection templates. This category-behavior mismatch is explicitly listed as a red flag in the threat model. The presence of search engines like Sogou (so.com), Quendu (quendu.com), Qwant (qwant.com), Sěznam (seznam.cz), Nona (nona.de), and Panda Search (panda-search.org) indicates the extension intercepts and redirects user searches to monetized search partners.

Publisher Risk Factors

The developer is listed as "[email protected]" - a generic Gmail address with no verified publisher status. Combined with only 12 users, this suggests either a new or abandoned extension. The high finding count (1466 total, 1354 IoC) is driven by the search engine domains, not by bundled dependencies or known false-positive patterns.

Counterargument

A skeptic might argue these are legitimate search engines (Qwant is privacy-focused, Sogou is a major Chinese search engine) and therefore benign. However, the threat is not the search engines themselves but the unauthorized redirection behavior. Legitimate wallpaper extensions do not embed search engine query templates. The presence of ?q= parameter templates across 6+ search domains indicates intentional search hijacking to monetize user traffic, which is the defining characteristic of browser hijacker PUPs. The extension's actual functionality contradicts its stated purpose, confirming malicious intent regardless of the search engines' legitimacy.

Code-Smell Noise

The 77 code-smell findings are classified as low-severity noise per the CVEQ false-positive guidelines and do not contribute to this verdict. No malware signatures (0) or obfuscation findings (0) were detected, which is typical for browser hijackers that rely on behavioral abuse rather than traditional malware techniques.

Key Reasons

  • Search engine query templates (?q=, ?ie=, ?query=) indicate browser hijacking
  • Extension category mismatch: wallpaper description vs search hijacking behavior
  • Anonymous publisher (Gmail address) with no verification
  • Multiple monetized search engine domains embedded in extension
  • No malware signatures but behavioral abuse pattern is clear

False Positive Considerations

  • code-smell findings (77 total, low severity noise)
  • high IoC count driven by legitimate search engine domains

Reviewed 2026-05-08; recommended action: escalate; model confidence 85%.

About This Extension

A new tab that allows you to select wallpapers directly from Baidu Images, Google Images, Wallhaven, Unsplash and Pixabay. Affiliate Disclosure We may participate in various affiliate marketing programs, which means we may earn commissions on purchases made through our links to retailer

Frequently Asked Questions