Firefox Add-ons Verified

VHS - Dev Tools

7cc87e47-b5fe-56b3-a943-65e62f9b9895 | v1.9.0
86/ 100
CRITICAL risk
No change since v1.8.3
Risk verdict
Do not install

Score-based assessment (critical risk, 86/100). No analyst review available.

Analysis record

Analysed
3 days ago
Version
v1.9.0
Artifact
SHA256 E46…F85
Source
Findings (non-IoC)

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

390 detail rows

YARA Rule Matches

19 rules
SeverityRuleHitsFilesMetadata
HIGHsupply chain sourcemap appended iife 1
assets/obfuscator-lib-CNw1if_5.js
-
LOWpostinstall persistence mechanism 22
assets/index.ts-Dje2ydRz.jsassets/sampleInputs-BpLFDust.jsassets/obfuscator-lib-CNw1if_5.js +19 more
-
LOWcredential env files 7
assets/obfuscator-lib-CNw1if_5.jsassets/css.worker-CXZsIV5y.jsassets/prettierFormat-C9K0XQwT.js +4 more
-
LOWRedirectToUnknownPath 1
assets/prettierFormat-C9K0XQwT.js
-
LOWNoUseEval 2
assets/obfuscator-lib-CNw1if_5.jsassets/format-D9087Evl.js
-
LOWNoUseWeakRandom 8
assets/format-D9087Evl.jsassets/demo-CQaSd4dj.jsassets/monacoSetup-DIKyMLmg.js +5 more
-
LOWpostinstall file download 44
assets/popup-BpHXuhxQ.jsassets/CurlPreview-C2td0EqN.jsassets/SvgViewer-CjtkxIWm.js +41 more
-
LOWSQLInjection 4
assets/monacoSetup-DIKyMLmg.jsassets/svgMinify-D3gDOZz2.jsassets/qrcode-BlnZpoVU.js +1 more
-
LOWLocalStorageShouldNotBeUsed 1
assets/useTheme-COtArcrH.js
-
LOWDebuggerStatementsShouldNotBeUsed 11
assets/WebToolsMenuContent-22OvTikv.jsassets/editor.worker-CRaYpIdo.jsassets/javascript-CsOJ_6xN.js +8 more
-
LOWpostinstall environment access 56
assets/settings-DyPHQe3v.jsassets/GoodPincode-D6XH2U_b.jsassets/svgMinify-D3gDOZz2.js +53 more
-
LOWpostinstall network communication 34
META-INF/manifest.mfassets/format-D9087Evl.jsassets/ViewerToolbar-DB3MjAZb.js +31 more
-
LOWOriginsNotVerified 7
assets/json.worker-C5PEkLU0.jsassets/editor.worker-CRaYpIdo.jsassets/index.ts-CWaUZJbb.js +4 more
-
LOWpostinstall crypto operations 36
manifest.jsonassets/viewer-Zd1G5wDX.jsassets/HelpMenuContent-DsFkK0Nz.js +33 more
-
LOWpostinstall system command 41
assets/css.worker-CXZsIV5y.jsassets/detectInput-TcF5UC3X.jsassets/sampleInputs-BpLFDust.js +38 more
-
LOWUsingShellInterpreterWhenExecutingOSCommands 1
assets/prettierFormat-C9K0XQwT.js
-
LOWpostinstall obfuscation 38
assets/css.worker-CXZsIV5y.jsassets/detectInput-TcF5UC3X.jsassets/sampleInputs-BpLFDust.js +35 more
-
LOWpostinstall registry modification 8
assets/json.worker-C5PEkLU0.jsassets/editor.worker-CRaYpIdo.jsassets/format-D9087Evl.js +5 more
-
LOWpostinstall file manipulation 55
assets/lspLanguageFeatures-CQYobNzb.jsassets/JsonParser-NHFoGUMe.jsassets/qrcode-BlnZpoVU.js +52 more
-

Network Indicators

Concrete URLs, domains, IPs, emails, and hashes extracted from the analyzed artifact.

638 total
...

Network indicators are queued for lazy loading

Scroll this section into view to load the detailed rows.

Publisher Evidence

Limited evidence

Vihat Software

Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.

Firefox does not expose the same publisher verification data as IDE stores, so this score is deliberately conservative.

42
Noisy-finding weight
x1.00
Publisher domain
vihatgroup.com
Observed
Store verification signal
Limited signal
Limited
Extension portfolio
2
Portfolio

12 evidence rows available.

Finding Categories

1
Malware Signatures
9
Obfuscation
4
Network
638
IoC Indicators

YARA Rules Matched

19 rules(377 hits)
supply chain sourcemap appended iife postinstall persistence mechanism credential env files RedirectToUnknownPath NoUseEval NoUseWeakRandom postinstall file download SQLInjection LocalStorageShouldNotBeUsed DebuggerStatementsShouldNotBeUsed postinstall environment access postinstall network communication OriginsNotVerified postinstall crypto operations postinstall system command UsingShellInterpreterWhenExecutingOSCommands +3 more

Requested Permissions

9 permissions
<all_urls>

Access and modify data on every website you visit

Dangerous
clipboardRead

Read data from your clipboard

High
cookies

Read and modify cookies on all sites

High
activeTab
Medium
storage
Low
clipboardWrite
Low
contextMenus
Low
scripting
Low
alarms
Low

Security Analysis Summary

Security Analysis Overview

VHS - Dev Tools is a Firefox Add-ons extension published by Vihat Software. Version 1.9.0 has been analyzed by the Risky Plugins security platform, receiving a risk score of 85.8/100 (CRITICAL risk) based on 1028 security findings.

Risk Assessment

This extension presents critical security risk. Severe issues were detected, potentially including malware indicators, exposed secrets, or dangerous behaviors. Installation is strongly discouraged until these issues are addressed.

Findings Breakdown

  • Critical: 1 finding(s)
  • High: 6 finding(s)
  • Medium: 645 finding(s)
  • Low: 376 finding(s)

What Was Analyzed

The security assessment covers multiple analysis categories:

  • Malware Detection: YARA rule matching against 2,400+ malware signatures
  • Secret Detection: Scanning for exposed API keys, tokens, and credentials
  • Static Analysis: Code-level security analysis for common vulnerability patterns
  • Network Analysis: Detection of suspicious network communications and endpoints
  • Obfuscation Detection: Identification of code obfuscation techniques

Developer Information

VHS - Dev Tools is published by Vihat Software on the Firefox Add-ons marketplace.

Recommendation

This extension is not recommended for installation without thorough manual review. Consider alternatives with lower risk scores, or contact the developer to address the identified security concerns.

Firefox version history

Risk trend by version

17 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.

Selected
86
Change since first
+27
Change from previous
No change
Versions:
First analyzed version
1.2.24
Jul 19, 2026
Risk range
58 to 86
Across analyzed versions
Latest analyzed version
1.9.0
Sep 17, 2026
Selected version
critical
Version
v1.9.0
3 days ago
Risk score
86
Findings
1028
Change vs previous
0

Pick any point on the chart to explore that version's code below.

About This Extension

<ol><li>Auto-upgrades raw log, data, markup, and code files opened directly in the browser with a rich editor, syntax highlighting, and emoji-rendered markdown previews</li><li>Popup auto-detect — paste anything and get an instant preview: 🔑 JWT decode 🕒 Date/epoch conversion 🎨 CSS Colors 🌈 CSS Gradient 🔗 URL parser ⏰ Cron expression explainer 🧩 Regex tester 🔡 Base64 decode 🔓 URI-encoded string decode 🖼 Data URI preview 🖌 SVG preview 🔐 Basic Auth decode 🍪 Cookie string preview 🪢 Flatted JSON inflate 🏷 TLV (EMVCo/VietQR) decode ☎ VOIP dial string, SIP message &amp; SDP session preview 📋 FreeSWITCH/Asterisk AMI event headers decode 🧬 Detect Tech-Stacks: scan the current tab for frameworks, CMS, and analytics platforms 🌐 cURL command → API request snippet</li><li>Standalone tools (open in new tab): 📝 Diff Compare 🔑 Safe Password Generator 🔒 Bcrypt Hash/Verify 🔐 CryptoJS Encrypt/Decrypt/Hash ✨ Code Formatter (Beautify/Minify/Obfuscate) 🍪 Cookies Viewer 🧾 QR Code tool: generate a styled QR code or scan one from an image, your camera, or the page itself 🅖 Gravatar Checker: look up a public Gravatar profile by email or hash — avatar, bio, verified accounts, links, and photo gallery</li><li>Right-click menu: fill/copy a random password, open selection as Log/JSON/Code, send selection to Diff Compare, or launch any tool</li><li>Customizable keyboard shortcuts for your most-used actions, with a Settings tab to view and rebind them</li><li>Web tools shortcut: quick links to handy external tools</li><li>60+ color themes to match your favorite editor, synced across tabs</li><li>Share any file to GitHub Gist, <a href="https://prod.outgoing.prod.webservices.mozgcp.net/v1/6235050f49f093307e68cd71aad3424b002551c3c0e4359ec003e2c5c9f66dcb/http%3A//dpaste.com" rel="nofollow">dpaste.com</a>, Pastebin, or a custom endpoint, and get an instant preview back when opening one of your own share links</li><li>Add-ons menu:<ul><li>One-click "Copy Paste Enable" to bypass pages that block copy/paste/right-click/selection, and</li><li>Opt-in "Selection Assist" to preview JWTs, dates, URLs, colors, and more from any text you select on a page</li></ul></li><li>IndexDB Exportor: list and download a tab's IndexedDB databases as JSON</li></ol>

Frequently Asked Questions