Wikipedia Search
Confirmed member of a tracked malicious supply-chain campaign.
Analysis record
- Analysed
- 6 months ago
- Version
- v1.4
- Artifact
- SHA256 4F9…5E9
- Source
- Findings (non-IoC)
Evidence ledger
Ranked by severity · findings with a source location link to the code viewer
YARA Rule Matches
7 rules| Severity | Rule | Hits | Files | Metadata |
|---|---|---|---|---|
| LOW | postinstall crypto operations | 2 | _metadata/verified_contents.jsonjs/jquery.js | - |
| LOW | postinstall file manipulation | 1 | js/jquery.js | - |
| LOW | postinstall obfuscation | 1 | js/jquery.js | - |
| LOW | postinstall network communication | 2 | js/jquery.jspopup/main.html | - |
| LOW | postinstall system command | 1 | js/jquery.js | - |
| LOW | SQLInjection | 1 | js/jquery.js | - |
| LOW | NoUseWeakRandom | 1 | js/jquery.js | - |
Network Indicators
Concrete URLs, domains, IPs, emails, and hashes extracted from the analyzed artifact.
Network indicators are queued for lazy loading
Scroll this section into view to load the detailed rows.
Publisher Evidence
Limited evidencePublisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.
Chrome does not expose the same publisher verification data as IDE stores, so this score is deliberately conservative.
11 evidence rows available.
Finding Categories
YARA Rules Matched
7 rules(9 hits)Requested Permissions
2 permissionsAI Security Report
AI Security Review
Risky Plugins reviewed this extension with an AI-assisted security workflow on 2026-04-28. The review verdict is likely false positive with 85% confidence.
Recommended action: suppress false positive. Evidence context: threat category none; evidence quality moderate.
This extension exhibits a classic false-positive inflation pattern. The 103 IoC findings are entirely garbage from the XIOC extractor misreading JavaScript property access chains as domains. Every single IoC finding follows this pattern: r.stop.call, s.fx.off, finish.call, v.beforesend.call, a.empty.fire, t.fail, and this.name are not real domains—they are property access chains like r.stop.call() being incorrectly extracted as domain strings. This is a well-documented false positive source in the CVEQ platform.
The actual network behavior is benign. The two network findings are legitimate jQuery AJAX calls in popup/main.js at lines 39 and 75. These are standard HTTP requests, almost certainly to Wikipedia's public API for search functionality, which matches the extension's stated purpose. There is no evidence of browser hijacking, credential theft, or data exfiltration.
Zero malware signatures were detected. Zero obfuscation was detected. The 9 code-smell findings are classified as low severity and match known noise patterns (basic Node.js patterns, API key references, code quality rules). These should not drive a verdict per the triage guidelines.
The extension has an anonymous developer ([email protected]) and very low user count (50), which are minor concerns but not evidence of malicious behavior. The name "Wikipedia Search" is generic but not typosquatting any specific extension.
Counterargument: A skeptic might argue that the anonymous developer and high finding count (114 total) suggest hidden malicious intent. However, the finding count is meaningless when 91% of findings are known XIOC false positives. The actual code evidence—zero malware signatures, zero obfuscation, legitimate jQuery AJAX calls—shows no malicious behavior. Anonymous developers publish benign extensions regularly; the code itself, not the developer identity, determines the verdict. Without actual suspicious domains, malware signatures, or obfuscation, there is no evidence of harm.
Key Reasons
- All 103 IoC findings are property access chain false positives (r.stop.call, s.fx.off, finish.call)
- Zero malware signatures detected
- Zero obfuscation detected
- Network calls are legitimate jQuery AJAX in popup/main.js
- No suspicious actual domains found
False Positive Considerations
- XIOC property access chain extraction
- Code-smell rules on basic patterns
- Finding count inflation from garbage IoCs
Source Code Not Available
Source code is not available for this version of the extension.
About This Extension
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace
Бесплатный ВПН для Ютуб без ограничений в России
[email protected]
Discord VPN | Расширение для браузера – надежный доступ к Discord
[email protected]
VPNtube - Ютуб без замедления
[email protected]
VPN для ChatGPT
[email protected]
РуТрекер VPN - расширение для доступа к сайту
[email protected]
VPN для LinkedIn
[email protected]