Firefox Add-ons

General Sticker System (GSS)

by ElfinL · 32 users
4cb06a78-ab5e-598c-8497-06e9fe58caa3 | v8.8
85/ 100
CRITICAL risk
+35 since v8.7
Analyst verdict
Do not install

The AI review rates the findings as likely false positive, but the risk score (85/100) still counts them.

Analysis record

Analysed
Today
Version
v8.8
Artifact
SHA256 089…9AB
Source
Findings (non-IoC)

Is General Sticker System (GSS) safe?

General Sticker System adds a sticker picker to streaming chat on Twitch, Kick, YouTube and a few smaller platforms. The Firefox listing asks for no special permissions and no host permissions, so the extension has no declared ability to read pages or cookies on its own. The work it does is outbound: background.js calls fetch at lines 188, 232, 268, 291, 352 and 392 to pull sticker images from the image sources named in its description.

Eight medium findings in the scan are those fetch calls, logged as NET-FETCH-background.js-188 and seven more of the same kind, plus two in content.js at lines 9665 and 9668. Fetching a remote image is how any extension shows you a picture. For a sticker tool that is the entire product. The scanner reports no destination domain, no malware signature and no hidden code alongside them. The other 97 findings are low-severity code-smell matches, the sort of thing that fires on ordinary JavaScript: loops, string building and page element handling.

The scanner tripped on volume. Nothing in the manifest asks for access it should not have, no file hides its own contents, and no finding points to a suspicious domain or a credential path. The developer, ElfinL, publishes under a name that mimics no popular extension. With 32 users, this is a small utility doing what its description says it does.

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

105 detail rows

YARA Rule Matches

12 rules
SeverityRuleHitsFilesMetadata
LOWpostinstall persistence mechanism 1
background.js
-
LOWpostinstall file download 4
editor.jsi18n.jscontent.js +1 more
-
LOWSQLInjection 1
i18n.js
-
LOWNoUseWeakRandom 2
popup.jscleanelement/index.js
-
LOWLocalStorageShouldNotBeUsed 1
cleanelement/storage.js
-
LOWpostinstall crypto operations 2
content.jsmodules/gsstracker.js
-
LOWpostinstall system command 24
content.jseditor.htmlpopup.js +21 more
-
LOWpostinstall file manipulation 15
popup.jscleanelement/index.jsplatforms/gosh.js +12 more
-
LOWAlertStatementsShouldNotBeUsed 1
TexoStreamCore/sharedChat.js
-
LOWpostinstall registry modification 14
popup.jsplatforms/youtube.jsbackground.js +11 more
-
LOWpostinstall obfuscation 6
libraries/catbox.jslibraries/base.jslibraries/meee.js +3 more
-
LOWpostinstall network communication 26
popup.jsplatforms/base.jspopup.html +23 more
-

Publisher Evidence

Limited evidence

ElfinL

Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.

Firefox does not expose the same publisher verification data as IDE stores, so this score is deliberately conservative.

34
Noisy-finding weight
x1.00
Publisher domain
No domain
Missing
Store verification signal
Limited signal
Limited
Extension portfolio
2
Portfolio

13 evidence rows available.

Finding Categories

8
Network

YARA Rules Matched

12 rules(97 hits)
postinstall persistence mechanism postinstall file download SQLInjection NoUseWeakRandom LocalStorageShouldNotBeUsed postinstall crypto operations postinstall system command postinstall file manipulation AlertStatementsShouldNotBeUsed postinstall registry modification postinstall obfuscation postinstall network communication

Requested Permissions

19 permissions
storage
Low
scripting
Low
https://twitch.tv/*
Low
https://www.twitch.tv/*
Low
https://*.twitch.tv/*
Low
https://vaughn.live/*
Low
https://*.vaughn.live/*
Low
https://kick.com/*
Low
https://*.kick.com/*
Low
https://youtube.com/*
Low
https://www.youtube.com/*
Low
https://*.youtube.com/*
Low
https://beamstream.gg/*
Low
https://*.beamstream.gg/*
Low
https://*.w.tv/*
Low
https://gosh.com/*
Low
https://*.gosh.com/*
Low
https://ms-hls.vaughn.live/*
Low
https://*.vaughnsoft.net/*
Low

AI Security Report

AI Security Review

Evidence context: threat category none; evidence quality moderate.

General Sticker System (GSS) is a Firefox add-on by developer ElfinL that adds a sticker picker to chat on Twitch, Kick, YouTube, Vaughn, W.TV and BeamStream.gg. Version 8.7 has 32 users. The scan recorded 105 findings: 8 medium network findings, 97 low-severity code-smell findings, and zero findings in every category that would point at intent, including malware signatures, IoCs, obfuscation, secrets, dependency issues and tool poisoning.

What the code does

All eight medium findings are the same primitive, a fetch call. Six are in background.js at lines 188, 232, 268, 291, 352 and 392, titled NET-FETCH-background.js-188 through NET-FETCH-background.js-392. Two more are in content.js at lines 9665 and 9668. A sticker tool downloads images from the sources it supports, and remote image retrieval is what fetch is for. The manifest declares no permissions and no host permissions, so the extension has no declared ability to read page content or cookies.

The other 97 findings are low-severity code-smell matches. Those rules fire on loops, string handling and DOM access in any non-trivial script. They are not behavioural evidence, and not one of them sits in the same file as a malware signature.

What is missing matters more

The categories that would turn this into a real finding are empty. No YARA malware family matched. No obfuscation was detected, so nothing in background.js or content.js hides its own contents. No suspicious domain appears anywhere in the package, and the IoC list is empty. The developer publishes under a name that copies no popular extension, and the store listing describes sticker sourcing and tag categories, which matches the fetch calls in background.js.

The counterargument

A skeptic would point at content.js lines 9665 and 9668. Two network calls from a content script injected into streaming sites deserve a question, and the scanner recorded no destination domain for any of the eight, so we cannot see where those requests go. No manifest-analysis findings were recorded either, which means the empty permission list could be a parse gap rather than a genuinely clean manifest. Those gaps are real. They are also the only gaps. A hostile extension normally pairs outbound calls with elevated host permissions, an obfuscated payload, or an IoC to a domain that is not a CDN or the extension's own service. None of those is present, and nothing here reaches a login page or cookie store. If a later version declares host permissions such as ://.twitch.tv/* alongside an endpoint that is not an image host, that would justify re-running the analysis.

Key Reasons

  • Zero malware signatures, zero obfuscation, zero IoCs, zero secrets and zero tool-poisoning findings across the package.
  • All eight medium findings are fetch calls (NET-FETCH-background.js-188 through NET-FETCH-background.js-392, plus content.js lines 9665 and 9668), which is the expected mechanism for downloading sticker images.
  • The remaining 97 findings are low-severity code-smell matches that fire on ordinary JavaScript and carry no behavioural weight.
  • The manifest declares no permissions and no host permissions, so the extension has no declared access to page content, cookies or login pages.
  • The name copies no popular extension and the description matches the observed behaviour of fetching and categorising stickers.

False Positive Considerations

  • Code-smell YARA rules firing on ordinary JavaScript patterns at low severity, accounting for 97 of 105 findings.
  • NET-FETCH rules flagging every fetch call, including routine remote image retrieval.
  • No manifest-analysis findings recorded, so the empty permission list may reflect an extraction gap rather than a clean manifest.
  • Small user base and no destination domains captured for the network findings, leaving the endpoints unreported.

Reviewed 2026-09-26; recommended action: suppress false positive; model confidence 80%.

Firefox version history

Risk trend by version

5 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.

Selected
85
Change since first
+29
Change from previous
+35
Versions:
First analyzed version
8.4
Sep 12, 2026
Risk range
50 to 85
Across analyzed versions
Latest analyzed version
8.8
Oct 1, 2026
Selected version
critical
Version
v8.8
Today
Risk score
85
Findings
105
Change vs previous
+35

Pick any point on the chart to explore that version's code below.

About This Extension

General Sticker System (GSS) 一鍵發送 Twitch/Kick/Vaughn/YouTube/<a href="https://prod.outgoing.prod.webservices.mozgcp.net/v1/8d88c9bdff778c76b8d99a25200c07d1230ccf54025877bd0149bd87c98e11f7/http%3A//W.TV/BeamStream" rel="nofollow">W.TV/BeamStream</a> 貼圖,支援自定義標籤與多種圖庫(CB/IM/ME/YT)。 一键发送 Twitch/Kick/Vaughn/YouTube/<a href="https://prod.outgoing.prod.webservices.mozgcp.net/v1/8d88c9bdff778c76b8d99a25200c07d1230ccf54025877bd0149bd87c98e11f7/http%3A//W.TV/BeamStream" rel="nofollow">W.TV/BeamStream</a> 贴图,支持自定义标签与多种图库(CB/IM/ME/YT)。 One-click stickers for Twitch/Kick/Vaughn/YouTube/<a href="https://prod.outgoing.prod.webservices.mozgcp.net/v1/8d88c9bdff778c76b8d99a25200c07d1230ccf54025877bd0149bd87c98e11f7/http%3A//W.TV/BeamStream" rel="nofollow">W.TV/BeamStream</a> with custom tags and multiple image sources (CB/IM/ME/YT). ワンクリックで Twitch/Kick/Vaughn/YouTube/<a href="https://prod.outgoing.prod.webservices.mozgcp.net/v1/8d88c9bdff778c76b8d99a25200c07d1230ccf54025877bd0149bd87c98e11f7/http%3A//W.TV/BeamStream" rel="nofollow">W.TV/BeamStream</a> スタンプ送信。カスタムタグと複数の画像ソース(CB/IM/ME/YT)対応。 원클릭 Twitch/Kick/Vaughn/YouTube/<a href="https://prod.outgoing.prod.webservices.mozgcp.net/v1/8d88c9bdff778c76b8d99a25200c07d1230ccf54025877bd0149bd87c98e11f7/http%3A//W.TV/BeamStream" rel="nofollow">W.TV/BeamStream</a> 스티커 전송. 커스텀 태그와 다양한 이미지 소스(CB/IM/ME/YT) 지원. 繁體中文 主要功能: 貼圖管理系統:儲存常用貼圖 ID 並自定義標籤,透過分類面板快速尋找並發送。 支援圖庫:CatBox (CB)、Imgur (IM)、Meee (ME)、YouTube (YT)。 支援平台:Twitch、Kick、Vaughn、YouTube、<a href="https://prod.outgoing.prod.webservices.mozgcp.net/v1/5594f33af0d0f9cb64723c11d9e44f516375417bd8b81db2e3ccb5f34d556763/http%3A//W.TV" rel="nofollow">W.TV</a>、<a href="https://prod.outgoing.prod.webservices.mozgcp.net/v1/db79b808bcd0bd94d1cb1387fba8ff7a409fcc2a845c34cbcb2814a97f3b0c16/http%3A//BeamStream.gg" rel="nofollow">BeamStream.gg</a>。 右鍵快速新增:在直播間對任何貼圖點擊右鍵,即可立即收錄至您的 GSS 清單。 隱私聲明:所有貼圖、標籤與設定均存儲於您的本地瀏覽器,本擴充功能不會上傳或共享任何個人資料。 简体中文 主要功能: 贴图管理系统:存储常用贴图 ID 并自定义标签,通过分类面板快速寻找并发送。 支持图库:CatBox (CB)、Imgur (IM)、Meee (ME)、YouTube (YT)。 支持平台:Twitch、Kick、Vaughn、YouTube、<a href="https://prod.outgoing.prod.webservices.mozgcp.net/v1/5594f33af0d0f9cb64723c11d9e44f516375417bd8b81db2e3ccb5f34d556763/http%3A//W.TV" rel="nofollow">W.TV</a>、<a href="https://prod.outgoing.prod.webservices.mozgcp.net/v1/db79b808bcd0bd94d1cb1387fba8ff7a409fcc2a845c34cbcb2814a97f3b0c16/http%3A//BeamStream.gg" rel="nofollow">BeamStream.gg</a>。 右键快速新增:在直播间对任何贴图点击右键,即可立即收录至您的 GSS 清单。 隐私声明:所有贴图、标签与设定均存储于您的本地浏览器,本扩展功能不会上传或共享任何个人资料。 English Key Features: Sticker Management: Save sticker IDs with custom tags. Organize and send stickers via a dedicated panel. Supported Image Sources: CatBox (CB), Imgur (IM), Meee (ME), YouTube (YT). Supported Platforms: Twitch, Kick, Vaughn, YouTube, <a href="https://prod.outgoing.prod.webservices.mozgcp.net/v1/5594f33af0d0f9cb64723c11d9e44f516375417bd8b81db2e3ccb5f34d556763/http%3A//W.TV" rel="nofollow">W.TV</a>, <a href="https://prod.outgoing.prod.webservices.mozgcp.net/v1/db79b808bcd0bd94d1cb1387fba8ff7a409fcc2a845c34cbcb2814a97f3b0c16/http%3A//BeamStream.gg" rel="nofollow">BeamStream.gg</a>. Right-Click Quick Add: Add any sticker to your GSS list instantly via the right-click context menu. Privacy Commitment: All stickers, tags, and settings are stored locally on your device. This extension does not upload or share any personal data. 日本語 主な機能: スタンプ管理システム:よく使うスタンプ ID を保存し、カスタムタグで分類。専用パネルから素早く検索・送信。 対応画像ソース:CatBox (CB)、Imgur (IM)、Meee (ME)、YouTube (YT)。 対応プラットフォーム:Twitch、Kick、Vaughn、YouTube、<a href="https://prod.outgoing.prod.webservices.mozgcp.net/v1/5594f33af0d0f9cb64723c11d9e44f516375417bd8b81db2e3ccb5f34d556763/http%3A//W.TV" rel="nofollow">W.TV</a>、<a href="https://prod.outgoing.prod.webservices.mozgcp.net/v1/db79b808bcd0bd94d1cb1387fba8ff7a409fcc2a845c34cbcb2814a97f3b0c16/http%3A//BeamStream.gg" rel="nofollow">BeamStream.gg</a>。 右クリックで即追加:配信中のスタンプを右クリックするだけで GSS リストに追加。 プライバシー保護:すべてのスタンプ、タグ、設定はローカルブラウザに保存されます。個人情報をアップロードまたは共有することはありません。 한국어 (Korean) 주요 기능: 스티커 관리 시스템: 자주 사용하는 스티커 ID를 저장하고 커스텀 태그로 분류. 전용 패널에서 빠르게 검색 및 전송. 지원 이미지 소스: CatBox (CB), Imgur (IM), Meee (ME), YouTube (YT). 지원 플랫폼: Twitch, Kick, Vaughn, YouTube, <a href="https://prod.outgoing.prod.webservices.mozgcp.net/v1/5594f33af0d0f9cb64723c11d9e44f516375417bd8b81db2e3ccb5f34d556763/http%3A//W.TV" rel="nofollow">W.TV</a>, <a href="https://prod.outgoing.prod.webservices.mozgcp.net/v1/db79b808bcd0bd94d1cb1387fba8ff7a409fcc2a845c34cbcb2814a97f3b0c16/http%3A//BeamStream.gg" rel="nofollow">BeamStream.gg</a>. 우클릭 즉시 추가: 방송 중 스티커를 우클릭하면 GSS 목록에 바로 추가. 개인정보 보호: 모든 스티커, 태그, 설정은 로컬 브라우저에 저장됩니다. 개인 정보를 업로드하거나 공유하지 않습니다.

Frequently Asked Questions