General Sticker System (GSS)
The AI review rates the findings as likely false positive, but the risk score (85/100) still counts them.
Analysis record
- Analysed
- Today
- Version
- v8.8
- Artifact
- SHA256 089…9AB
- Source
- Findings (non-IoC)
Is General Sticker System (GSS) safe?
General Sticker System adds a sticker picker to streaming chat on Twitch, Kick, YouTube and a few smaller platforms. The Firefox listing asks for no special permissions and no host permissions, so the extension has no declared ability to read pages or cookies on its own. The work it does is outbound: background.js calls fetch at lines 188, 232, 268, 291, 352 and 392 to pull sticker images from the image sources named in its description.
Eight medium findings in the scan are those fetch calls, logged as NET-FETCH-background.js-188 and seven more of the same kind, plus two in content.js at lines 9665 and 9668. Fetching a remote image is how any extension shows you a picture. For a sticker tool that is the entire product. The scanner reports no destination domain, no malware signature and no hidden code alongside them. The other 97 findings are low-severity code-smell matches, the sort of thing that fires on ordinary JavaScript: loops, string building and page element handling.
The scanner tripped on volume. Nothing in the manifest asks for access it should not have, no file hides its own contents, and no finding points to a suspicious domain or a credential path. The developer, ElfinL, publishes under a name that mimics no popular extension. With 32 users, this is a small utility doing what its description says it does.
Evidence ledger
Ranked by severity · findings with a source location link to the code viewer
YARA Rule Matches
12 rules| Severity | Rule | Hits | Files | Metadata |
|---|---|---|---|---|
| LOW | postinstall persistence mechanism | 1 | background.js | - |
| LOW | postinstall file download | 4 | editor.jsi18n.jscontent.js +1 more | - |
| LOW | SQLInjection | 1 | i18n.js | - |
| LOW | NoUseWeakRandom | 2 | popup.jscleanelement/index.js | - |
| LOW | LocalStorageShouldNotBeUsed | 1 | cleanelement/storage.js | - |
| LOW | postinstall crypto operations | 2 | content.jsmodules/gsstracker.js | - |
| LOW | postinstall system command | 24 | content.jseditor.htmlpopup.js +21 more | - |
| LOW | postinstall file manipulation | 15 | popup.jscleanelement/index.jsplatforms/gosh.js +12 more | - |
| LOW | AlertStatementsShouldNotBeUsed | 1 | TexoStreamCore/sharedChat.js | - |
| LOW | postinstall registry modification | 14 | popup.jsplatforms/youtube.jsbackground.js +11 more | - |
| LOW | postinstall obfuscation | 6 | libraries/catbox.jslibraries/base.jslibraries/meee.js +3 more | - |
| LOW | postinstall network communication | 26 | popup.jsplatforms/base.jspopup.html +23 more | - |
Publisher Evidence
Limited evidenceElfinL
Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.
Firefox does not expose the same publisher verification data as IDE stores, so this score is deliberately conservative.
13 evidence rows available.
Finding Categories
YARA Rules Matched
12 rules(97 hits)Requested Permissions
19 permissionsAI Security Report
AI Security Review
Evidence context: threat category none; evidence quality moderate.
General Sticker System (GSS) is a Firefox add-on by developer ElfinL that adds a sticker picker to chat on Twitch, Kick, YouTube, Vaughn, W.TV and BeamStream.gg. Version 8.7 has 32 users. The scan recorded 105 findings: 8 medium network findings, 97 low-severity code-smell findings, and zero findings in every category that would point at intent, including malware signatures, IoCs, obfuscation, secrets, dependency issues and tool poisoning.
What the code does
All eight medium findings are the same primitive, a fetch call. Six are in background.js at lines 188, 232, 268, 291, 352 and 392, titled NET-FETCH-background.js-188 through NET-FETCH-background.js-392. Two more are in content.js at lines 9665 and 9668. A sticker tool downloads images from the sources it supports, and remote image retrieval is what fetch is for. The manifest declares no permissions and no host permissions, so the extension has no declared ability to read page content or cookies.
The other 97 findings are low-severity code-smell matches. Those rules fire on loops, string handling and DOM access in any non-trivial script. They are not behavioural evidence, and not one of them sits in the same file as a malware signature.
What is missing matters more
The categories that would turn this into a real finding are empty. No YARA malware family matched. No obfuscation was detected, so nothing in background.js or content.js hides its own contents. No suspicious domain appears anywhere in the package, and the IoC list is empty. The developer publishes under a name that copies no popular extension, and the store listing describes sticker sourcing and tag categories, which matches the fetch calls in background.js.
The counterargument
A skeptic would point at content.js lines 9665 and 9668. Two network calls from a content script injected into streaming sites deserve a question, and the scanner recorded no destination domain for any of the eight, so we cannot see where those requests go. No manifest-analysis findings were recorded either, which means the empty permission list could be a parse gap rather than a genuinely clean manifest. Those gaps are real. They are also the only gaps. A hostile extension normally pairs outbound calls with elevated host permissions, an obfuscated payload, or an IoC to a domain that is not a CDN or the extension's own service. None of those is present, and nothing here reaches a login page or cookie store. If a later version declares host permissions such as ://.twitch.tv/* alongside an endpoint that is not an image host, that would justify re-running the analysis.
Key Reasons
- Zero malware signatures, zero obfuscation, zero IoCs, zero secrets and zero tool-poisoning findings across the package.
- All eight medium findings are fetch calls (NET-FETCH-background.js-188 through NET-FETCH-background.js-392, plus content.js lines 9665 and 9668), which is the expected mechanism for downloading sticker images.
- The remaining 97 findings are low-severity code-smell matches that fire on ordinary JavaScript and carry no behavioural weight.
- The manifest declares no permissions and no host permissions, so the extension has no declared access to page content, cookies or login pages.
- The name copies no popular extension and the description matches the observed behaviour of fetching and categorising stickers.
False Positive Considerations
- Code-smell YARA rules firing on ordinary JavaScript patterns at low severity, accounting for 97 of 105 findings.
- NET-FETCH rules flagging every fetch call, including routine remote image retrieval.
- No manifest-analysis findings recorded, so the empty permission list may reflect an extraction gap rather than a clean manifest.
- Small user base and no destination domains captured for the network findings, leaving the endpoints unreported.
Reviewed 2026-09-26; recommended action: suppress false positive; model confidence 80%.
Firefox version history
Risk trend by version
5 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.
Pick any point on the chart to explore that version's code below.
Source Code Not Available
Source code is not available for this version of the extension.
About This Extension
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace
VaultysHub extension
Vaultys
Kindredly - A safer, private web for families
Kindredly.ai
Malwarebytes Browser Guard
Malwarebytes
VHS - Dev Tools
Vihat Software
Ultimate New Tab Page - AI Search & Dial
Dracon
Patreon Easy Downloader
Cosmious