Шедеврум без рекламы
Confirmed member of a tracked malicious supply-chain campaign.
Analysis record
- Analysed
- 5 months ago
- Version
- v1.5
- Artifact
- SHA256 55B…14B
- Source
- Findings (non-IoC)
Evidence ledger
Ranked by severity · findings with a source location link to the code viewer
YARA Rule Matches
11 rules| Severity | Rule | Hits | Files | Metadata |
|---|---|---|---|---|
| LOW | postinstall persistence mechanism | 16 | font/Nunito/Nunito-BoldItalic.ttffont/Nunito/Nunito-ExtraBoldItalic.ttffont/Nunito/Nunito-Italic.ttf +13 more | - |
| LOW | postinstall file download | 1 | check.js | - |
| LOW | SQLInjection | 1 | jquery.js | - |
| LOW | NoUseWeakRandom | 1 | jquery.js | - |
| LOW | LocalStorageShouldNotBeUsed | 1 | page/main.js | - |
| LOW | postinstall crypto operations | 2 | jquery.js_metadata/verified_contents.json | - |
| LOW | postinstall file manipulation | 3 | jquery.jspage/main.jscheck.js | - |
| LOW | postinstall environment access | 1 | check.js | - |
| LOW | postinstall obfuscation | 1 | jquery.js | - |
| LOW | postinstall network communication | 3 | jquery.jspage/style.csspage/night.css | - |
| LOW | postinstall system command | 3 | font/Nunito/Nunito-Bold.ttfjquery.jspage/style.css | - |
Network Indicators
Concrete URLs, domains, IPs, emails, and hashes extracted from the analyzed artifact.
Network indicators are queued for lazy loading
Scroll this section into view to load the detailed rows.
Publisher Evidence
Limited evidencePublisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.
Chrome does not expose the same publisher verification data as IDE stores, so this score is deliberately conservative.
12 evidence rows available.
Finding Categories
YARA Rules Matched
11 rules(33 hits)AI Security Report
AI Security Review
Risky Plugins reviewed this extension with an AI-assisted security workflow on 2026-04-22. The review verdict is benign but powerful with 85% confidence.
Recommended action: no action. Evidence context: threat category none; evidence quality weak.
The "Шедеврум без рекламы" (Shedevrum without ads) extension is a Chrome extension with 117 users, published by developer [email protected]. The extension's stated purpose is to block advertisements on Shedevrum, a Russian AI-powered image generation platform.
Critical Security Observation: The security analysis found ZERO findings across all categories. The findings_by_category object is completely empty, meaning no malware signatures, no suspicious network indicators, no code-smell patterns, no obfuscation detections, and no credential access patterns were identified. This absence of findings is a strong positive signal—if the extension contained malicious code, we would expect to see at least some code-smell or network findings from the automated analysis.
The extension's purpose is legitimate and well-defined: ad blocking for a specific platform. Ad blockers inherently have the capability to modify web page content and intercept network requests, which are powerful capabilities that could theoretically be misused. However, there is no evidence of such misuse in this extension. The name is in Russian, matching the target platform's language, with no evidence of typosquatting or impersonation of well-known extensions like Dark Reader or uBlock.
The developer attribution uses an email address ([email protected]) rather than a company name, which is common for small, independent developers but provides less accountability than a verified organization. The extension has a published version number (1.5), indicating it's an active, maintained project.
Strongest Counterargument: The empty findings could indicate an incomplete or failed analysis rather than a clean scan. However, the extension has a valid version number (1.5) and user count (117), indicating it's a real, active extension that has been through the store's review process. If the analysis had failed to run, we would expect to see indicators like version "unknown" or missing metadata. The complete absence of findings across all security categories is more consistent with a clean, legitimate extension than a failed analysis.
Given the legitimate purpose, zero security findings, and no evidence of malicious behavior, this extension presents no security concerns for its intended use case.
Key Reasons
- Zero security findings across all categories
- Legitimate ad-blocking purpose for specific platform
- No evidence of typosquatting or impersonation
- No malware signatures or suspicious network indicators
Source Code Not Available
Source code is not available for this version of the extension.
About This Extension
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace
ВПН для Gemini / VPN for Gemini
[email protected]
ВПН для ЧатГПТ / ChatGPT
[email protected]
Edge Translate - Text Selection Translation
[email protected]
Citrix Workspace
[email protected]
Edge Translate - Browser Translator | PDF Translation | MV3 | Open Source
[email protected]
Intelbras Cloud
[email protected]