ChatGPT Sidebar
The AI review rates the findings as likely false positive, but the risk score (65/100) still counts them.
Analysis record
- Analysed
- 6 months ago
- Version
- v5.1.4
- Artifact
- SHA256 D64…02C
- Source
- Findings (non-IoC)
Evidence ledger
Ranked by severity · findings with a source location link to the code viewer
YARA Rule Matches
10 rules| Severity | Rule | Hits | Files | Metadata |
|---|---|---|---|---|
| LOW | postinstall persistence mechanism | 6 | content-scripts/pageActions.jscontent-scripts/content.jscontent-scripts/smartAnalyzer.js +3 more | - |
| LOW | LocalStorageShouldNotBeUsed | 1 | chunks/sidepanel-Bkev1piE.js | - |
| LOW | DebuggerStatementsShouldNotBeUsed | 2 | chunks/sidepanel-Bkev1piE.jscontent-scripts/content.js | - |
| LOW | postinstall file download | 7 | content-scripts/pageActions.jscontent-scripts/content.jscontent-scripts/smartAnalyzer.js +4 more | - |
| LOW | NoUseWeakRandom | 7 | content-scripts/pageActions.jscontent-scripts/content.jscontent-scripts/smartAnalyzer.js +4 more | - |
| LOW | postinstall obfuscation | 6 | background.jscontent-scripts/smartAnalyzer.jschunks/sidepanel-Bkev1piE.js +3 more | - |
| LOW | postinstall crypto operations | 8 | content-scripts/smartAnalyzer.jscontent-scripts/pageActions.jscontent-scripts/content.js +5 more | - |
| LOW | postinstall file manipulation | 8 | content-scripts/smartAnalyzer.jschunks/sidepanel-Bkev1piE.jsbackground.js +5 more | - |
| LOW | postinstall system command | 8 | content-scripts/smartAnalyzer.jschunks/sidepanel-Bkev1piE.jsbackground.js +5 more | - |
| LOW | postinstall network communication | 7 | content-scripts/smartAnalyzer.jschunks/sidepanel-Bkev1piE.jsbackground.js +4 more | - |
Network Indicators
Concrete URLs, domains, IPs, emails, and hashes extracted from the analyzed artifact.
Network indicators are queued for lazy loading
Scroll this section into view to load the detailed rows.
Publisher Evidence
Limited evidencePublisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.
Chrome does not expose the same publisher verification data as IDE stores, so this score is deliberately conservative.
12 evidence rows available.
Finding Categories
YARA Rules Matched
10 rules(60 hits)Requested Permissions
18 permissionsAccess and modify data on every website you visit
AI Security Report
AI Security Review
Evidence context: threat category none; evidence quality moderate.
This extension named 'ChatGPT Sidebar' from developer '[email protected]' presents a mixed signal profile that requires careful interpretation. The most critical observation is the complete absence of malware signatures (0 malware-signature findings, 0 malware findings), which is the strongest indicator against confirmed malicious behavior.
The 563 IoC findings are overwhelmingly benign. The XIOC-DOMAIN-google.com, XIOC-DOMAIN-clients2.google.com, and XIOC-DOMAIN-youtube.com findings reference legitimate Google and YouTube infrastructure. The XIOC-URL-http://www.w3.org/2000/svg finding is a W3C namespace declaration, not an actual network call. The cv.iptc.org domain belongs to the International Press Telecommunications Council's image verification service. While XIOC-DOMAIN-g.sc and XIOC-DOMAIN-p.tj are shortened URL domains that warrant scrutiny, shortened URLs alone do not constitute malicious behavior without evidence of data exfiltration or command-and-control activity.
The network findings show fetch calls in background.js:2, content-scripts/smartAnalyzer.js:1, and content-scripts/content.js at lines 1 and 2. These are generic network call detections that do not specify destination domains or indicate malicious data transmission. The MANIFEST-SENSITIVE-PERM-TABS finding in manifest.json is expected behavior for a sidebar extension that needs to interact with browser tabs to display ChatGPT functionality.
The 60 code-smell findings are classified as low severity and match known false-positive patterns per CVEQ documentation. These include basic JavaScript patterns that trigger rules like postinstall_*, credential_*, and code-quality checks on any non-trivial JavaScript. The 2 obfuscation findings are insufficient to indicate malicious intent without malware signatures co-located in the same files.
Strongest counterargument: A skeptic would argue that an extension claiming to be 'ChatGPT Sidebar' with only 5 users, published by an anonymous Gmail address ([email protected]) rather than a verified OpenAI or known developer, is likely attempting to impersonate legitimate ChatGPT extensions and collect user data. The version number 5.1.4 suggests multiple iterations, potentially testing different approaches. However, this counterargument relies on circumstantial signals rather than concrete evidence. There is no credential theft pattern, no session cookie extraction code, no data exfiltration to suspicious domains, and no malware signatures. The IoC findings do not show traffic to known malicious infrastructure. While the anonymous publisher is a legitimate concern, the absence of actual malicious behavior evidence means the findings are more likely false positives from bundled code and generic pattern matching rather than confirmed malicious activity.
Key Reasons
- Zero malware signatures detected despite 632 total findings
- IoC findings are predominantly benign Google/YouTube/W3C domains
- Code-smell findings (60) are known false-positive patterns
- Network findings show generic fetch calls without malicious destinations
False Positive Considerations
- IoC extractor matching benign infrastructure domains (google.com, youtube.com)
- Code-smell rules firing on standard JavaScript patterns
- W3C namespace URL misidentified as network IoC
- Bundled code generating multiplicative IoC findings
Reviewed 2026-04-29; recommended action: monitor; model confidence 72%.
Source Code Not Available
Source code is not available for this version of the extension.
About This Extension
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace
XB, block all ads
[email protected]
Zent Translate
[email protected]
Google Translate in Side Panel
[email protected]
Pinterest Image Downloader | Futoo
[email protected]
YT Subtitle - Video Summarizer & Translator
[email protected]
gTab
[email protected]