Is "CHUtils" on Firefox Add-ons Safe to Install?

dragongirlsnout · firefox · v1.5.1

CHUtils is a web extension for cohost that adds custom informative, cosmetic, and quality-of-life features to improve the site's default layout and user experience. Features include horizontal navigation, a visible follower count, popover notifications, viewing and responding to post comments from your feed, seeing markdown post previews as you write, and more.

Risk Assessment

Analyzed
57.11
out of 100
MEDIUM

458 security findings detected across all analyzers

Firefox extension requesting 2 permissions

Severity Breakdown

0
Critical
106
High
352
Medium
0
Low
0
Info

Finding Categories

106
Malware Signatures
3
Network
337
IoC Indicators

YARA Rules Matched

10 rules(106 hits)
postinstall network communication postinstall file download postinstall environment access postinstall file manipulation postinstall system command postinstall obfuscation postinstall persistence mechanism NoUseWeakRandom SQLInjection postinstall crypto operations

Requested Permissions

2 permissions
storage
Low
*://*.cohost.org/*
Low

About This Extension

CHUtils is a web extension for cohost that adds custom informative, cosmetic, and quality-of-life features to improve the site's default layout and user experience. Features include horizontal navigation, a visible follower count, popover notifications, viewing and responding to post comments from your feed, seeing markdown post previews as you write, and more.

Detailed Findings

109 total

YARA Rule Matches

10 rules

Indicators of Compromise

Network indicators, suspicious strings, and potential IoCs extracted during analysis

URLs
81
IP Addresses
6
Domains
251
Strings
337

All Indicators · 337

Domain
detected Domain: indexeddb.open

XIOC detected Domain: indexeddb.open

extracted_from_files

Domain
detected Domain: e.now

XIOC detected Domain: e.now

extracted_from_files

Domain
detected Domain: e.elem.style

XIOC detected Domain: e.elem.style

extracted_from_files

URL
detected URL: https://cohost.org/',

XIOC detected URL: https://cohost.org/',

extracted_from_files

IP
detected IP: ::

XIOC detected IP: ::

extracted_from_files

URL
detected URL: https://cohost.org/minecraft

XIOC detected URL: https://cohost.org/minecraft

extracted_from_files

URL
detected URL: https://cohost.org/chutils

XIOC detected URL: https://cohost.org/chutils

extracted_from_files

URL
detected URL: https://www.paypal.com/paypalme/dragongirled

XIOC detected URL: https://www.paypal.com/paypalme/dragongirled

extracted_from_files

Hash
detected MD5 Hash: c4b7ee45576b8776ba7331f35565ffb0

XIOC detected MD5 Hash: c4b7ee45576b8776ba7331f35565ffb0

extracted_from_files

Hash
detected SHA1 Hash: ab4a94b12432f028c9b60af3d777cdaa92f69711

XIOC detected SHA1 Hash: ab4a94b12432f028c9b60af3d777cdaa92f69711

extracted_from_files

URL
detected URL: https://www.BrailleInstitute.org/

XIOC detected URL: https://www.BrailleInstitute.org/

extracted_from_files

URL
detected URL: http://www.w3.org/2000/svg%27%3e%3cpath

XIOC detected URL: http://www.w3.org/2000/svg%27%3e%3cpath

extracted_from_files

URL
detected URL: http://www.w3.org/2000/svg%27

XIOC detected URL: http://www.w3.org/2000/svg%27

extracted_from_files

Domain
detected Domain: t8044da12b738bc4c4bf776d7799bb76c.c4b7ee45576b8776ba7331f35565ffb0.addons.mozilla.org

XIOC detected Domain: t8044da12b738bc4c4bf776d7799bb76c.c4b7ee45576b8776ba7331f35565ffb0.addons.mozilla.org

extracted_from_files

Domain
detected Domain: girldragon.neocities.org

XIOC detected Domain: girldragon.neocities.org

extracted_from_files

Domain
detected Domain: content-signature.mozilla.org

XIOC detected Domain: content-signature.mozilla.org

extracted_from_files

Domain
detected Domain: addons.mozilla.org

XIOC detected Domain: addons.mozilla.org

extracted_from_files

Domain
detected Domain: mozilla.com

XIOC detected Domain: mozilla.com

extracted_from_files

Domain
detected Domain: signingca1.addons.mozilla.org

XIOC detected Domain: signingca1.addons.mozilla.org

extracted_from_files

IP
detected IP: de::

XIOC detected IP: de::

extracted_from_files

Domain
detected Domain: jquery.org

XIOC detected Domain: jquery.org

extracted_from_files

IP
detected Domain: sodipodi.sourceforge.net

XIOC detected Domain: sodipodi.sourceforge.net

extracted_from_files

Domain
detected Domain: www.inkscape.org

XIOC detected Domain: www.inkscape.org

extracted_from_files

Domain
detected Domain: www.w3.org

XIOC detected Domain: www.w3.org

extracted_from_files

Domain
detected Domain: e.name

XIOC detected Domain: e.name

extracted_from_files

Domain
detected Domain: tab.id

XIOC detected Domain: tab.id

extracted_from_files

Domain
detected Domain: cohost.org

XIOC detected Domain: cohost.org

extracted_from_files

Domain
detected Domain: ue.call

XIOC detected Domain: ue.call

extracted_from_files

Domain
detected Domain: n.call

XIOC detected Domain: n.call

extracted_from_files

Domain
detected Domain: ce.map

XIOC detected Domain: ce.map

extracted_from_files

Domain
detected Domain: ae.call

XIOC detected Domain: ae.call

extracted_from_files

Domain
detected Domain: i.call

XIOC detected Domain: i.call

extracted_from_files

Domain
detected Domain: o.call

XIOC detected Domain: o.call

extracted_from_files

Domain
detected Domain: oe.flat.call

XIOC detected Domain: oe.flat.call

extracted_from_files

Domain
detected Domain: b.filter.id

XIOC detected Domain: b.filter.id

extracted_from_files

Domain
detected Domain: t.top

XIOC detected Domain: t.top

extracted_from_files

Domain
detected Domain: k.call

XIOC detected Domain: k.call

extracted_from_files

Domain
detected Domain: a.id

XIOC detected Domain: a.id

extracted_from_files

Domain
detected Domain: se.call

XIOC detected Domain: se.call

extracted_from_files

Domain
detected Domain: s.call

XIOC detected Domain: s.call

extracted_from_files

Domain
detected Domain: t.call

XIOC detected Domain: t.call

extracted_from_files

Domain
detected Domain: i.select

XIOC detected Domain: i.select

extracted_from_files

Domain
detected Domain: pe.call

XIOC detected Domain: pe.call

extracted_from_files

Domain
detected Domain: e.next

XIOC detected Domain: e.next

extracted_from_files

Domain
detected Domain: e.id

XIOC detected Domain: e.id

extracted_from_files

Domain
detected Domain: he.call

XIOC detected Domain: he.call

extracted_from_files

Domain
detected Domain: de.call

XIOC detected Domain: de.call

extracted_from_files

Domain
detected Domain: b.find.id

XIOC detected Domain: b.find.id

extracted_from_files

Domain
detected Domain: o.empty.fire

XIOC detected Domain: o.empty.fire

extracted_from_files

Domain
detected Domain: t.map

XIOC detected Domain: t.map

extracted_from_files

Domain
detected Domain: r.call

XIOC detected Domain: r.call

extracted_from_files

Domain
detected Domain: l.call

XIOC detected Domain: l.call

extracted_from_files

Domain
detected Domain: e.call

XIOC detected Domain: e.call

extracted_from_files

Domain
detected Domain: ce.support

XIOC detected Domain: ce.support

extracted_from_files

Domain
detected Domain: i.support

XIOC detected Domain: i.support

extracted_from_files

Domain
detected Domain: f.add.call

XIOC detected Domain: f.add.call

extracted_from_files

Domain
detected Domain: f.setup.call

XIOC detected Domain: f.setup.call

extracted_from_files

Domain
detected Domain: v.events

XIOC detected Domain: v.events

extracted_from_files

Domain
detected Domain: ke.td

XIOC detected Domain: ke.td

extracted_from_files

Domain
detected Domain: ke.th

XIOC detected Domain: ke.th

extracted_from_files

Domain
detected Domain: this.show

XIOC detected Domain: this.show

extracted_from_files

Domain
detected Domain: ce.style

XIOC detected Domain: ce.style

extracted_from_files

Domain
detected Domain: o.data

XIOC detected Domain: o.data

extracted_from_files

Domain
detected Domain: u.data

XIOC detected Domain: u.data

extracted_from_files

Domain
detected Domain: ce.event.handlers.call

XIOC detected Domain: ce.event.handlers.call

extracted_from_files

Domain
detected Domain: c.predispatch.call

XIOC detected Domain: c.predispatch.call

extracted_from_files

Domain
detected Domain: f.teardown.call

XIOC detected Domain: f.teardown.call

extracted_from_files

Domain
detected Domain: f.remove.call

XIOC detected Domain: f.remove.call

extracted_from_files

Domain
detected Domain: ce.event.global

XIOC detected Domain: ce.event.global

extracted_from_files

Domain
detected Domain: this.off

XIOC detected Domain: this.off

extracted_from_files

Domain
detected Domain: n.target

XIOC detected Domain: n.target

extracted_from_files

Domain
detected Domain: date.now

XIOC detected Domain: date.now

extracted_from_files

Domain
detected Domain: this.target

XIOC detected Domain: this.target

extracted_from_files

Domain
detected Domain: t.click

XIOC detected Domain: t.click

extracted_from_files

Domain
detected Domain: e.target

XIOC detected Domain: e.target

extracted_from_files

Domain
detected Domain: c.postdispatch.call

XIOC detected Domain: c.postdispatch.call

extracted_from_files

Domain
detected Domain: this.now

XIOC detected Domain: this.now

extracted_from_files

Domain
detected Domain: l.style

XIOC detected Domain: l.style

extracted_from_files

Domain
detected Domain: e.top

XIOC detected Domain: e.top

extracted_from_files

Domain
detected Domain: e.style

XIOC detected Domain: e.style

extracted_from_files

Domain
detected Domain: this.map

XIOC detected Domain: this.map

extracted_from_files

Domain
detected Domain: t.events

XIOC detected Domain: t.events

extracted_from_files

Domain
detected Domain: d.call

XIOC detected Domain: d.call

extracted_from_files

Domain
detected Domain: ce.fx.off

XIOC detected Domain: ce.fx.off

extracted_from_files

Domain
detected Domain: a.empty.fire

XIOC detected Domain: a.empty.fire

extracted_from_files

Domain
detected Domain: l.opts.fail

XIOC detected Domain: l.opts.fail

extracted_from_files

Domain
detected Domain: r.host

XIOC detected Domain: r.host

extracted_from_files

Domain
detected Domain: xt.host

XIOC detected Domain: xt.host

extracted_from_files

Domain
detected Domain: t.name

XIOC detected Domain: t.name

extracted_from_files

Domain
detected Domain: this.options.step.call

XIOC detected Domain: this.options.step.call

extracted_from_files

Domain
detected Domain: managedprojects.map

XIOC detected Domain: managedprojects.map

extracted_from_files

Domain
detected Domain: selector.click

XIOC detected Domain: selector.click

extracted_from_files

Domain
detected Domain: mt-4.flex.w-fit.flex-col.gap

XIOC detected Domain: mt-4.flex.w-fit.flex-col.gap

extracted_from_files

Domain
detected Domain: this.name

XIOC detected Domain: this.name

extracted_from_files

Domain
detected Domain: finish.call

XIOC detected Domain: finish.call

extracted_from_files

Domain
detected Domain: r.stop.call

XIOC detected Domain: r.stop.call

extracted_from_files

Domain
detected Domain: r.old.call

XIOC detected Domain: r.old.call

extracted_from_files

Domain
detected Domain: i.data

XIOC detected Domain: i.data

extracted_from_files

Domain
detected Domain: r.open

XIOC detected Domain: r.open

extracted_from_files

Domain
detected Domain: s.data

XIOC detected Domain: s.data

extracted_from_files

Domain
detected Domain: t.fail

XIOC detected Domain: t.fail

extracted_from_files

Domain
detected Domain: v.beforesend.call

XIOC detected Domain: v.beforesend.call

extracted_from_files

Domain
detected Domain: v.global

XIOC detected Domain: v.global

extracted_from_files

Domain
detected Domain: v.data

XIOC detected Domain: v.data

extracted_from_files

Domain
detected Domain: boolean.prototype.valueof.call

XIOC detected Domain: boolean.prototype.valueof.call

extracted_from_files

Domain
detected Domain: object.prototype.hasownproperty.call

XIOC detected Domain: object.prototype.hasownproperty.call

extracted_from_files

Domain
detected Domain: ce.now

XIOC detected Domain: ce.now

extracted_from_files

Domain
detected Domain: t.using.call

XIOC detected Domain: t.using.call

extracted_from_files

Domain
detected Domain: t.top-s.top

XIOC detected Domain: t.top-s.top

extracted_from_files

Domain
detected Domain: f.top

XIOC detected Domain: f.top

extracted_from_files

Domain
detected Domain: e.data

XIOC detected Domain: e.data

extracted_from_files

Domain
detected Domain: this.opts.style

XIOC detected Domain: this.opts.style

extracted_from_files

Domain
detected Domain: e.map

XIOC detected Domain: e.map

extracted_from_files

Domain
detected Domain: zone.name

XIOC detected Domain: zone.name

extracted_from_files

Domain
detected Domain: e.zone

XIOC detected Domain: e.zone

extracted_from_files

Domain
detected Domain: e.constructor.name

XIOC detected Domain: e.constructor.name

extracted_from_files

Domain
detected Domain: object.prototype.tostring.call

XIOC detected Domain: object.prototype.tostring.call

extracted_from_files

Domain
detected Domain: function.tostring.call

XIOC detected Domain: function.tostring.call

extracted_from_files

Domain
detected Domain: i.map

XIOC detected Domain: i.map

extracted_from_files

Domain
detected Domain: o.map

XIOC detected Domain: o.map

extracted_from_files

Domain
detected Domain: r.day

XIOC detected Domain: r.day

extracted_from_files

Domain
detected Domain: n.day

XIOC detected Domain: n.day

extracted_from_files

Domain
detected Domain: a.day

XIOC detected Domain: a.day

extracted_from_files

Domain
detected Domain: e.day

XIOC detected Domain: e.day

extracted_from_files

Domain
detected Domain: object.is

XIOC detected Domain: object.is

extracted_from_files

Domain
detected Domain: w.now

XIOC detected Domain: w.now

extracted_from_files

Domain
detected Domain: this.start.plus

XIOC detected Domain: this.start.plus

extracted_from_files

Domain
detected Domain: n.map

XIOC detected Domain: n.map

extracted_from_files

Domain
detected Domain: e.plus

XIOC detected Domain: e.plus

extracted_from_files

Domain
detected Domain: t.as

XIOC detected Domain: t.as

extracted_from_files

Domain
detected Domain: this.plus

XIOC detected Domain: this.plus

extracted_from_files

Domain
detected Domain: t.plus

XIOC detected Domain: t.plus

extracted_from_files

Domain
detected Domain: k.now

XIOC detected Domain: k.now

extracted_from_files

Domain
detected Domain: o.now

XIOC detected Domain: o.now

extracted_from_files

Domain
detected Domain: t.zone

XIOC detected Domain: t.zone

extracted_from_files

Domain
detected Domain: n.zone

XIOC detected Domain: n.zone

extracted_from_files

Domain
detected Domain: e.c.day

XIOC detected Domain: e.c.day

extracted_from_files

Domain
detected Domain: i.plus

XIOC detected Domain: i.plus

extracted_from_files

Domain
detected Domain: a.plus

XIOC detected Domain: a.plus

extracted_from_files

Domain
detected Domain: e.info

XIOC detected Domain: e.info

extracted_from_files

Domain
detected Domain: this.c.day

XIOC detected Domain: this.c.day

extracted_from_files

Domain
detected Domain: this.zone.name

XIOC detected Domain: this.zone.name

extracted_from_files

Domain
detected Domain: t.day

XIOC detected Domain: t.day

extracted_from_files

Domain
detected Domain: this.zone

XIOC detected Domain: this.zone

extracted_from_files

Domain
detected Domain: r.zone

XIOC detected Domain: r.zone

extracted_from_files

Domain
detected Domain: i.day

XIOC detected Domain: i.day

extracted_from_files

Domain
detected Domain: this.tokenizer.link

XIOC detected Domain: this.tokenizer.link

extracted_from_files

Domain
detected Domain: this.state.top

XIOC detected Domain: this.state.top

extracted_from_files

Domain
detected Domain: this.tokenizer.hr

XIOC detected Domain: this.tokenizer.hr

extracted_from_files

Domain
detected Domain: this.tokenizer.space

XIOC detected Domain: this.tokenizer.space

extracted_from_files

Domain
detected Domain: k.search

XIOC detected Domain: k.search

extracted_from_files

Domain
detected Domain: this.lexer.state.top

XIOC detected Domain: this.lexer.state.top

extracted_from_files

Domain
detected Domain: github.com

XIOC detected Domain: github.com

extracted_from_files

Domain
detected Domain: a.hooks.run

XIOC detected Domain: a.hooks.run

extracted_from_files

Domain
detected Domain: prismjs.com

XIOC detected Domain: prismjs.com

extracted_from_files

Domain
detected Domain: t.br

XIOC detected Domain: t.br

extracted_from_files

Domain
detected Domain: t.link

XIOC detected Domain: t.link

extracted_from_files

Domain
detected Domain: this.renderer.hr

XIOC detected Domain: this.renderer.hr

extracted_from_files

Domain
detected Domain: this.renderer.space

XIOC detected Domain: this.renderer.space

extracted_from_files

Domain
detected Domain: this.tokenizer.br

XIOC detected Domain: this.tokenizer.br

extracted_from_files

Domain
detected Domain: c.next

XIOC detected Domain: c.next

extracted_from_files

Domain
detected Domain: w.next

XIOC detected Domain: w.next

extracted_from_files

Domain
detected Domain: r.next

XIOC detected Domain: r.next

extracted_from_files

Domain
detected Domain: v.pattern.global

XIOC detected Domain: v.pattern.global

extracted_from_files

Domain
detected Domain: t.next

XIOC detected Domain: t.next

extracted_from_files

Domain
detected Domain: e.head.next

XIOC detected Domain: e.head.next

extracted_from_files

Domain
detected Domain: n.rest

XIOC detected Domain: n.rest

extracted_from_files

Domain
detected Domain: ie.call

XIOC detected Domain: ie.call

extracted_from_files

Domain
detected Domain: e.in

XIOC detected Domain: e.in

extracted_from_files

Domain
detected Domain: e.safe

XIOC detected Domain: e.safe

extracted_from_files

Domain
detected Domain: e.classes.map

XIOC detected Domain: e.classes.map

extracted_from_files

Domain
detected Domain: s.languages.css.atrule.inside.rest

XIOC detected Domain: s.languages.css.atrule.inside.rest

extracted_from_files

Domain
detected Domain: n.data

XIOC detected Domain: n.data

extracted_from_files

Domain
detected Domain: n.next

XIOC detected Domain: n.next

extracted_from_files

URL
detected URL: http://www.w3.org/1998/Math/MathML

XIOC detected URL: http://www.w3.org/1998/Math/MathML

extracted_from_files

Domain
detected Domain: s.store

XIOC detected Domain: s.store

extracted_from_files

Domain
detected Domain: purify.min.js.map

XIOC detected Domain: purify.min.js.map

extracted_from_files

Domain
detected Domain: n.ownerdocument.doctype.name

XIOC detected Domain: n.ownerdocument.doctype.name

extracted_from_files

Domain
detected Domain: re.call

XIOC detected Domain: re.call

extracted_from_files

Domain
detected Domain: h.show

XIOC detected Domain: h.show

extracted_from_files

Domain
detected Domain: oe.call

XIOC detected Domain: oe.call

extracted_from_files

Domain
detected Domain: window.location.search

XIOC detected Domain: window.location.search

extracted_from_files

URL
detected URL: http://www.w3.org/1999/xlink

XIOC detected URL: http://www.w3.org/1999/xlink

extracted_from_files

URL
detected URL: http://www.w3.org/1999/xhtml

XIOC detected URL: http://www.w3.org/1999/xhtml

extracted_from_files

Domain
detected Domain: preferences.bookmarks.options.page

XIOC detected Domain: preferences.bookmarks.options.page

extracted_from_files

Domain
detected Domain: headers.map

XIOC detected Domain: headers.map

extracted_from_files

Domain
detected Domain: posts.map

XIOC detected Domain: posts.map

extracted_from_files

Domain
detected Domain: bookmarks.map

XIOC detected Domain: bookmarks.map

extracted_from_files

Domain
detected Domain: projects.map

XIOC detected Domain: projects.map

extracted_from_files

Domain
detected Domain: blocks.map

XIOC detected Domain: blocks.map

extracted_from_files

Domain
detected Domain: div.ch

XIOC detected Domain: div.ch

extracted_from_files

Domain
detected Domain: button.ch

XIOC detected Domain: button.ch

extracted_from_files

Domain
detected Domain: ch-utils-collapseable.co

XIOC detected Domain: ch-utils-collapseable.co

extracted_from_files

Domain
detected Domain: bookmarkclones.map

XIOC detected Domain: bookmarkclones.map

extracted_from_files

Domain
detected Domain: article.co

XIOC detected Domain: article.co

extracted_from_files

Domain
detected Domain: commentarray.map

XIOC detected Domain: commentarray.map

extracted_from_files

Domain
detected Domain: postcache.map

XIOC detected Domain: postcache.map

extracted_from_files

Domain
detected Domain: row.map

XIOC detected Domain: row.map

extracted_from_files

Domain
detected Domain: this.dataset.target

XIOC detected Domain: this.dataset.target

extracted_from_files

Domain
detected Domain: exportlink.click

XIOC detected Domain: exportlink.click

extracted_from_files

Domain
detected Domain: exportlink.download

XIOC detected Domain: exportlink.download

extracted_from_files

Domain
detected Domain: event.target.id

XIOC detected Domain: event.target.id

extracted_from_files

Domain
detected Domain: bookmarkedtags.tags.map

XIOC detected Domain: bookmarkedtags.tags.map

extracted_from_files

Domain
detected Domain: help.antisoftware.club

XIOC detected Domain: help.antisoftware.club

extracted_from_files

Domain
detected Domain: svg.ch

XIOC detected Domain: svg.ch

extracted_from_files

Domain
detected Domain: svg.ml

XIOC detected Domain: svg.ml

extracted_from_files

Domain
detected Domain: followers.map

XIOC detected Domain: followers.map

extracted_from_files

Domain
detected Domain: cssloaders.github.io

XIOC detected Domain: cssloaders.github.io

extracted_from_files

Domain
detected Domain: notification.fromprojectids.map

XIOC detected Domain: notification.fromprojectids.map

extracted_from_files

Domain
detected Domain: notification.fromprojectids.constructor.name

XIOC detected Domain: notification.fromprojectids.constructor.name

extracted_from_files

Domain
detected Domain: newsharenotificationids.map

XIOC detected Domain: newsharenotificationids.map

extracted_from_files

Domain
detected Domain: notification.sharepostids.map

XIOC detected Domain: notification.sharepostids.map

extracted_from_files

Domain
detected Domain: bugzilla.mozilla.org

XIOC detected Domain: bugzilla.mozilla.org

extracted_from_files

Domain
detected Domain: sharetree.map

XIOC detected Domain: sharetree.map

extracted_from_files

Domain
detected Domain: comment.children.map

XIOC detected Domain: comment.children.map

extracted_from_files

Domain
detected Domain: rows.map

XIOC detected Domain: rows.map

extracted_from_files

Domain
detected Domain: imgs.map

XIOC detected Domain: imgs.map

extracted_from_files

Domain
detected Domain: tags.map

XIOC detected Domain: tags.map

extracted_from_files

Domain
detected Domain: notifications.map

XIOC detected Domain: notifications.map

extracted_from_files

Domain
detected Domain: notification.sharepost.tags.map

XIOC detected Domain: notification.sharepost.tags.map

extracted_from_files

Domain
detected Domain: notification.notifyingprojects.map

XIOC detected Domain: notification.notifyingprojects.map

extracted_from_files

Domain
detected Domain: notification.id

XIOC detected Domain: notification.id

extracted_from_files

Domain
detected Domain: datetime.date

XIOC detected Domain: datetime.date

extracted_from_files

Domain
detected Domain: elem.click

XIOC detected Domain: elem.click

extracted_from_files

Domain
detected Domain: elems.map

XIOC detected Domain: elems.map

extracted_from_files

Domain
detected Domain: result.map

XIOC detected Domain: result.map

extracted_from_files

Domain
detected Domain: menu.style

XIOC detected Domain: menu.style

extracted_from_files

Domain
detected Domain: target.style

XIOC detected Domain: target.style

extracted_from_files

Domain
detected Domain: svg.group

XIOC detected Domain: svg.group

extracted_from_files

Domain
detected Domain: response.result.data

XIOC detected Domain: response.result.data

extracted_from_files

Domain
detected Domain: result.data

XIOC detected Domain: result.data

extracted_from_files

Domain
detected Domain: response.map

XIOC detected Domain: response.map

extracted_from_files

Domain
detected Domain: response.constructor.name

XIOC detected Domain: response.constructor.name

extracted_from_files

Domain
detected Domain: anchors.map

XIOC detected Domain: anchors.map

extracted_from_files

Domain
detected Domain: developer.mozilla.org

XIOC detected Domain: developer.mozilla.org

extracted_from_files

Domain
detected Domain: moment.github.io

XIOC detected Domain: moment.github.io

extracted_from_files

Domain
detected Domain: cws.map

XIOC detected Domain: cws.map

extracted_from_files

IP
detected Domain: relationships.like

XIOC detected Domain: relationships.like

extracted_from_files

Domain
detected Domain: audio.play

XIOC detected Domain: audio.play

extracted_from_files

Domain
detected Domain: storedata.map

XIOC detected Domain: storedata.map

extracted_from_files

Domain
detected Domain: options.store

XIOC detected Domain: options.store

extracted_from_files

Domain
detected Domain: datastores.map

XIOC detected Domain: datastores.map

extracted_from_files

Domain
detected Domain: console.info

XIOC detected Domain: console.info

extracted_from_files

Domain
detected Domain: raw.githubusercontent.com

XIOC detected Domain: raw.githubusercontent.com

extracted_from_files

Domain
detected Domain: installedfeatures.map

XIOC detected Domain: installedfeatures.map

extracted_from_files

Domain
detected Domain: tree.map

XIOC detected Domain: tree.map

extracted_from_files

Domain
detected Domain: block.map

XIOC detected Domain: block.map

extracted_from_files

Domain
detected Domain: sortedblocks.map

XIOC detected Domain: sortedblocks.map

extracted_from_files

Domain
detected Domain: post.tags.map

XIOC detected Domain: post.tags.map

extracted_from_files

Domain
detected Domain: button.click

XIOC detected Domain: button.click

extracted_from_files

Domain
detected Domain: preference.new

XIOC detected Domain: preference.new

extracted_from_files

Domain
detected Domain: dataset.new

XIOC detected Domain: dataset.new

extracted_from_files

Domain
detected Domain: changelog.md

XIOC detected Domain: changelog.md

extracted_from_files

Domain
detected Domain: www.paypal.com

XIOC detected Domain: www.paypal.com

extracted_from_files

Domain
detected Domain: www.brailleinstitute.org

XIOC detected Domain: www.brailleinstitute.org

extracted_from_files

Domain
detected Domain: obj.children.constructor.name

XIOC detected Domain: obj.children.constructor.name

extracted_from_files

Domain
detected Domain: iframely.net

XIOC detected Domain: iframely.net

extracted_from_files

Domain
detected Domain: location.search

XIOC detected Domain: location.search

extracted_from_files

URL
detected URL: https://cohost.org/static/a09d966cd188c9ebaa4c.png',

XIOC detected URL: https://cohost.org/static/a09d966cd188c9ebaa4c.png',

extracted_from_files

URL
detected URL: https://cohost.org/static/bfa6d6316fd95ae76803.png',

XIOC detected URL: https://cohost.org/static/bfa6d6316fd95ae76803.png',

extracted_from_files

URL
detected URL: https://cohost.org/static/fa883e2377fea8945237.png',

XIOC detected URL: https://cohost.org/static/fa883e2377fea8945237.png',

extracted_from_files

Domain
detected Domain: option.credit

XIOC detected Domain: option.credit

extracted_from_files

Domain
detected Domain: feature.links.map

XIOC detected Domain: feature.links.map

extracted_from_files

Domain
detected Domain: feature.name

XIOC detected Domain: feature.name

extracted_from_files

URL
detected URL: http://sodipodi.sourceforge.net/DTD/sodipodi-0.dtd

XIOC detected URL: http://sodipodi.sourceforge.net/DTD/sodipodi-0.dtd

extracted_from_files

URL
detected URL: http://www.inkscape.org/namespaces/inkscape

XIOC detected URL: http://www.inkscape.org/namespaces/inkscape

extracted_from_files

URL
detected URL: http://www.inkscape.org/)

XIOC detected URL: http://www.inkscape.org/)

extracted_from_files

URL
detected URL: http://www.w3.org/2000/svg

XIOC detected URL: http://www.w3.org/2000/svg

extracted_from_files

URL
detected URL: http://addons.mozilla.org/ca/crl.pem0N

XIOC detected URL: http://addons.mozilla.org/ca/crl.pem0N

extracted_from_files

Other
detected Email: [email protected]

XIOC detected Email: [email protected]

extracted_from_files

URL
detected URL: https://cohost.org/rc/project/notifications?a',

XIOC detected URL: https://cohost.org/rc/project/notifications?a',

extracted_from_files

URL
detected URL: https://github.com/enchanted-sword/ch-utils

XIOC detected URL: https://github.com/enchanted-sword/ch-utils

extracted_from_files

URL
detected URL: https://github.com/enchanted-sword/ch-utils/blob/main/CHANGELOG.md

XIOC detected URL: https://github.com/enchanted-sword/ch-utils/blob/main/CHANGELOG.md

extracted_from_files

URL
detected URL: https://github.com/enchanted-sword/ch-utils/issues/

XIOC detected URL: https://github.com/enchanted-sword/ch-utils/issues/

extracted_from_files

URL
detected URL: https://prismjs.com/download.html#themes=prism-tomorrow&languages=markup+css&plugins=custom-class+unescaped-markup

XIOC detected URL: https://prismjs.com/download.html#themes=prism-tomorrow&languages=markup+css&plugins=custom-class+unescaped-markup

extracted_from_files

URL
detected URL: https://github.com/markedjs/marked.

XIOC detected URL: https://github.com/markedjs/marked.

extracted_from_files

URL
detected URL: https://github.com/markedjs/marked

XIOC detected URL: https://github.com/markedjs/marked

extracted_from_files

URL
detected URL: https://cohost.org/rc/posts/unpublished',

XIOC detected URL: https://cohost.org/rc/posts/unpublished',

extracted_from_files

URL
detected URL: https://cohost.org/rc/project/inbox',

XIOC detected URL: https://cohost.org/rc/project/inbox',

extracted_from_files

URL
detected URL: https://cohost.org/$

XIOC detected URL: https://cohost.org/$

extracted_from_files

URL
detected URL: https://cohost.org/rc/search',

XIOC detected URL: https://cohost.org/rc/search',

extracted_from_files

URL
detected URL: https://cohost.org/rc/artist-alley',

XIOC detected URL: https://cohost.org/rc/artist-alley',

extracted_from_files

URL
detected URL: https://cohost.org/rc/liked-posts',

XIOC detected URL: https://cohost.org/rc/liked-posts',

extracted_from_files

URL
detected URL: https://cohost.org/#',

XIOC detected URL: https://cohost.org/#',

extracted_from_files

URL
detected URL: https://cohost.org/rc/dashboard')))

XIOC detected URL: https://cohost.org/rc/dashboard')))

extracted_from_files

URL
detected URL: https://cohost.org/'

XIOC detected URL: https://cohost.org/'

extracted_from_files

URL
detected URL: https://cohost.org/rc/user/settings',

XIOC detected URL: https://cohost.org/rc/user/settings',

extracted_from_files

URL
detected URL: https://cohost.org/rc/project/followers',

XIOC detected URL: https://cohost.org/rc/project/followers',

extracted_from_files

URL
detected URL: https://cohost.org/rc/project/following',

XIOC detected URL: https://cohost.org/rc/project/following',

extracted_from_files

URL
detected URL: https://bugzilla.mozilla.org/show_bug.cgi?id=1896299

XIOC detected URL: https://bugzilla.mozilla.org/show_bug.cgi?id=1896299

extracted_from_files

URL
detected URL: https://cohost.org/rc/project/notifications

XIOC detected URL: https://cohost.org/rc/project/notifications

extracted_from_files

URL
detected URL: https://help.antisoftware.club/support/home',

XIOC detected URL: https://help.antisoftware.club/support/home',

extracted_from_files

URL
detected URL: https://cohost.org/rc/project/notifications',

XIOC detected URL: https://cohost.org/rc/project/notifications',

extracted_from_files

URL
detected URL: https://cssloaders.github.io/*/

XIOC detected URL: https://cssloaders.github.io/*/

extracted_from_files

URL
detected URL: https://developer.mozilla.org/en-US/docs/Web/JavaScript/Reference/Global_Objects/Intl/DateTimeFormat#using_options

XIOC detected URL: https://developer.mozilla.org/en-US/docs/Web/JavaScript/Reference/Global_Objects/Intl/DateTimeFormat#using_options

extracted_from_files

URL
detected URL: https://moment.github.io/luxon/api-docs/index.html#datetimetolocalestring

XIOC detected URL: https://moment.github.io/luxon/api-docs/index.html#datetimetolocalestring

extracted_from_files

URL
detected URL: https://cohost.org$

XIOC detected URL: https://cohost.org$

extracted_from_files

URL
detected URL: https://cohost.org/rc/search

XIOC detected URL: https://cohost.org/rc/search

extracted_from_files

URL
detected URL: https://cohost.org/api$

XIOC detected URL: https://cohost.org/api$

extracted_from_files

URL
detected URL: https://cohost.org/')[1];

XIOC detected URL: https://cohost.org/')[1];

extracted_from_files

URL
detected URL: https://cohost.org/

XIOC detected URL: https://cohost.org/

extracted_from_files

URL
detected URL: https://cohost.org/static/5cf84d596a2c422967de.png',

XIOC detected URL: https://cohost.org/static/5cf84d596a2c422967de.png',

extracted_from_files

URL
detected URL: https://cohost.org/static/9a6014af31fb1ca65a1f.png',

XIOC detected URL: https://cohost.org/static/9a6014af31fb1ca65a1f.png',

extracted_from_files

URL
detected URL: https://cohost.org/static/17aa2d48956926005de9.png',

XIOC detected URL: https://cohost.org/static/17aa2d48956926005de9.png',

extracted_from_files

URL
detected URL: https://cohost.org/static/41454e429d62b5cb7963.png',

XIOC detected URL: https://cohost.org/static/41454e429d62b5cb7963.png',

extracted_from_files

URL
detected URL: https://cohost.org/static/f59b84127fa7b6c48b6c.png',

XIOC detected URL: https://cohost.org/static/f59b84127fa7b6c48b6c.png',

extracted_from_files

URL
detected URL: https://help.antisoftware.club/a/solutions/articles/62000225024',

XIOC detected URL: https://help.antisoftware.club/a/solutions/articles/62000225024',

extracted_from_files

URL
detected URL: https://cohost.org/rc/tagged/$

XIOC detected URL: https://cohost.org/rc/tagged/$

extracted_from_files

URL
detected URL: https://cohost.org/static/11c5493261064ffa82c0.png',

XIOC detected URL: https://cohost.org/static/11c5493261064ffa82c0.png',

extracted_from_files

URL
detected URL: https://cohost.org/static/ae53a8b5de7c919100e6.png',

XIOC detected URL: https://cohost.org/static/ae53a8b5de7c919100e6.png',

extracted_from_files

URL
detected URL: https://cohost.org/static/d2753b632211c395538e.png',

XIOC detected URL: https://cohost.org/static/d2753b632211c395538e.png',

extracted_from_files

URL
detected URL: https://cohost.org/static/b59709333449a01e3e0a.png',

XIOC detected URL: https://cohost.org/static/b59709333449a01e3e0a.png',

extracted_from_files

URL
detected URL: https://cohost.org/static/c4f3f2c6b9ffb85934e7.png',

XIOC detected URL: https://cohost.org/static/c4f3f2c6b9ffb85934e7.png',

extracted_from_files

URL
detected URL: https://cohost.org/static/ebbf360236a95b62bdfc.png',

XIOC detected URL: https://cohost.org/static/ebbf360236a95b62bdfc.png',

extracted_from_files

URL
detected URL: https://cohost.org/static/014b0a8cc35206ef151d.png',

XIOC detected URL: https://cohost.org/static/014b0a8cc35206ef151d.png',

extracted_from_files

URL
detected URL: https://cohost.org/static/3bc3a1c5272e2ceb8712.png',

XIOC detected URL: https://cohost.org/static/3bc3a1c5272e2ceb8712.png',

extracted_from_files

URL
detected URL: https://cohost.org/static/228d3a13bd5f7796b434.png',

XIOC detected URL: https://cohost.org/static/228d3a13bd5f7796b434.png',

extracted_from_files

URL
detected URL: https://cohost.org/static/90058099e741e483208a.png',

XIOC detected URL: https://cohost.org/static/90058099e741e483208a.png',

extracted_from_files

URL
detected URL: https://cohost.org/static/9559ff8058a895328d76.png',

XIOC detected URL: https://cohost.org/static/9559ff8058a895328d76.png',

extracted_from_files

URL
detected URL: https://cohost.org/static/d7ec7f057e6fb15a94cc.png',

XIOC detected URL: https://cohost.org/static/d7ec7f057e6fb15a94cc.png',

extracted_from_files

URL
detected URL: https://cohost.org/static/b25a9fdf230219087003.png',

XIOC detected URL: https://cohost.org/static/b25a9fdf230219087003.png',

extracted_from_files

URL
detected URL: https://cohost.org/static/3633c116f0941d94d237.png',

XIOC detected URL: https://cohost.org/static/3633c116f0941d94d237.png',

extracted_from_files

URL
detected URL: https://cohost.org/static/e5d55348f39c65a20148.png',

XIOC detected URL: https://cohost.org/static/e5d55348f39c65a20148.png',

extracted_from_files

URL
detected URL: https://cohost.org/static/c45b6d8f9de20f725b98.png',

XIOC detected URL: https://cohost.org/static/c45b6d8f9de20f725b98.png',

extracted_from_files

URL
detected URL: https://cohost.org/static/53635f5fe850274b1a7d.png',

XIOC detected URL: https://cohost.org/static/53635f5fe850274b1a7d.png',

extracted_from_files

URL
detected URL: https://cohost.org/static/99c7fbf98de865cc9726.png',

XIOC detected URL: https://cohost.org/static/99c7fbf98de865cc9726.png',

extracted_from_files

URL
detected URL: https://cohost.org/static/cb9a5640d7ef7b361a1a.png',

XIOC detected URL: https://cohost.org/static/cb9a5640d7ef7b361a1a.png',

extracted_from_files

URL
detected URL: https://cohost.org/static/530f8cf75eac87716702.png',

XIOC detected URL: https://cohost.org/static/530f8cf75eac87716702.png',

extracted_from_files

URL
detected URL: https://cohost.org/static/9bb403f3822c6457baf6.png',

XIOC detected URL: https://cohost.org/static/9bb403f3822c6457baf6.png',

extracted_from_files

URL
detected URL: https://www.BrailleInstitute.org/http://helloapplied.comBraille

XIOC detected URL: https://www.BrailleInstitute.org/http://helloapplied.comBraille

extracted_from_files

URL
detected URL: http://www.w3.org/2000/svg',

XIOC detected URL: http://www.w3.org/2000/svg',

extracted_from_files

URL
detected URL: https://iframely.net/api/iframe?app=1&url=$

XIOC detected URL: https://iframely.net/api/iframe?app=1&url=$

extracted_from_files

URL
detected URL: https://raw.githubusercontent.com/enchanted-sword/ch-utils/ab4a94b12432f028c9b60af3d777cdaa92f69711/src/icons/icon.svg'

XIOC detected URL: https://raw.githubusercontent.com/enchanted-sword/ch-utils/ab4a94b12432f028c9b60af3d777cdaa92f69711/src/icons/icon.svg'

extracted_from_files

Domain
detected Domain: option.list.map

XIOC detected Domain: option.list.map

extracted_from_files

Domain
detected Domain: suboption.name

XIOC detected Domain: suboption.name

extracted_from_files

Domain
detected Domain: l.opts.start.call

XIOC detected Domain: l.opts.start.call

extracted_from_files

Domain
detected Domain: option.name

XIOC detected Domain: option.name

extracted_from_files

Security Analysis Summary

Security Analysis Overview

CHUtils is a Firefox Add-ons extension published by dragongirlsnout. Version 1.5.1 has been analyzed by the Risky Plugins security platform, receiving a risk score of 57.11/100 (MEDIUM risk) based on 458 security findings.

Risk Assessment

This extension presents moderate security risk. Several findings were detected that may warrant attention. Users should carefully review the permissions and findings before installation.

Findings Breakdown

  • High: 106 finding(s)
  • Medium: 352 finding(s)

What Was Analyzed

The security assessment covers multiple analysis categories:

  • Malware Detection: YARA rule matching against 2,400+ malware signatures
  • Secret Detection: Scanning for exposed API keys, tokens, and credentials
  • Static Analysis: Code-level security analysis for common vulnerability patterns
  • Network Analysis: Detection of suspicious network communications and endpoints
  • Obfuscation Detection: Identification of code obfuscation techniques

Developer Information

CHUtils is published by dragongirlsnout on the Firefox Add-ons marketplace. The extension has approximately 80 users.

Recommendation

Exercise caution with this extension. Review the detailed findings and ensure the requested permissions align with the extension's stated functionality before installation.

Frequently Asked Questions