Is "Images ON/OFF" on Chrome Web Store Safe to Install?

[email protected] · chrome · v3.2.0.0

Use this extension to disable/enable images on the current site. It's a simple switch: click to disable, click to enable. It works on "per host" basis and will disable images for the given host (the currently selected tab), not for all hosts. There are some options available, but basically, the extension does just that and nothing more.

Risk Assessment

Analyzed
51.17
out of 100
MEDIUM

83 security findings detected across all analyzers

Chrome extension requesting 4 permissions

Severity Breakdown

0
Critical
11
High
72
Medium
0
Low
0
Info

Finding Categories

11
Malware Signatures
70
IoC Indicators

YARA Rules Matched

7 rules(11 hits)
postinstall file manipulation postinstall network communication postinstall system command postinstall persistence mechanism postinstall environment access postinstall crypto operations postinstall obfuscation

Requested Permissions

4 permissions
tabs
Medium
contentSettings
Low
contextMenus
Low
storage
Low

About This Extension

Use this extension to disable/enable images on the current site. It's a simple switch: click to disable, click to enable. It works on "per host" basis and will disable images for the given host (the currently selected tab), not for all hosts. There are some options available, but basically, the extension does just that and nothing more.

Detailed Findings

12 total

YARA Rule Matches

7 rules

Indicators of Compromise

Network indicators, suspicious strings, and potential IoCs extracted during analysis

URLs
22
IP Addresses
5
Domains
13
Strings
70

All Indicators · 70

IP
detected IP: 0::

XIOC detected IP: 0::

extracted_from_files

Domain
detected Domain: github.com

XIOC detected Domain: github.com

extracted_from_files

Hash
detected MD5 Hash: 7EF4B24E569711E78657FDB16E7D5F54

XIOC detected MD5 Hash: 7EF4B24E569711E78657FDB16E7D5F54

extracted_from_files

Hash
detected MD5 Hash: 7EF4B24F569711E78657FDB16E7D5F54

XIOC detected MD5 Hash: 7EF4B24F569711E78657FDB16E7D5F54

extracted_from_files

Hash
detected MD5 Hash: 7EF4B24C569711E78657FDB16E7D5F54

XIOC detected MD5 Hash: 7EF4B24C569711E78657FDB16E7D5F54

extracted_from_files

Hash
detected MD5 Hash: 7EF4B24D569711E78657FDB16E7D5F54

XIOC detected MD5 Hash: 7EF4B24D569711E78657FDB16E7D5F54

extracted_from_files

Hash
detected MD5 Hash: 46839138569A11E7AE23851DA56BA1BB

XIOC detected MD5 Hash: 46839138569A11E7AE23851DA56BA1BB

extracted_from_files

Hash
detected MD5 Hash: 46839137569A11E7AE23851DA56BA1BB

XIOC detected MD5 Hash: 46839137569A11E7AE23851DA56BA1BB

extracted_from_files

Hash
detected MD5 Hash: 659951C0569711E7B6D1FD464A818F21

XIOC detected MD5 Hash: 659951C0569711E7B6D1FD464A818F21

extracted_from_files

Hash
detected MD5 Hash: 9F8C2874569A11E79081D0ADEED3D384

XIOC detected MD5 Hash: 9F8C2874569A11E79081D0ADEED3D384

extracted_from_files

Hash
detected MD5 Hash: 9F8C2873569A11E79081D0ADEED3D384

XIOC detected MD5 Hash: 9F8C2873569A11E79081D0ADEED3D384

extracted_from_files

Hash
detected MD5 Hash: BCCB81BE7656E711AE40C27EA502CE1E

XIOC detected MD5 Hash: BCCB81BE7656E711AE40C27EA502CE1E

extracted_from_files

Hash
detected MD5 Hash: 716067DC569711E7BF4EF17AA3FF7319

XIOC detected MD5 Hash: 716067DC569711E7BF4EF17AA3FF7319

extracted_from_files

Hash
detected MD5 Hash: 716067DD569711E7BF4EF17AA3FF7319

XIOC detected MD5 Hash: 716067DD569711E7BF4EF17AA3FF7319

extracted_from_files

Hash
detected MD5 Hash: 716067DA569711E7BF4EF17AA3FF7319

XIOC detected MD5 Hash: 716067DA569711E7BF4EF17AA3FF7319

extracted_from_files

Hash
detected MD5 Hash: 5A3EFB60569711E780C6A689990B3462

XIOC detected MD5 Hash: 5A3EFB60569711E780C6A689990B3462

extracted_from_files

Hash
detected MD5 Hash: 5A3EFB61569711E780C6A689990B3462

XIOC detected MD5 Hash: 5A3EFB61569711E780C6A689990B3462

extracted_from_files

Hash
detected MD5 Hash: 5A3EFB5E569711E780C6A689990B3462

XIOC detected MD5 Hash: 5A3EFB5E569711E780C6A689990B3462

extracted_from_files

URL
detected URL: http://www.gnu.org/licenses/

XIOC detected URL: http://www.gnu.org/licenses/

extracted_from_files

Hash
detected MD5 Hash: 659951C1569711E7B6D1FD464A818F21

XIOC detected MD5 Hash: 659951C1569711E7B6D1FD464A818F21

extracted_from_files

Hash
detected MD5 Hash: 659951C2569711E7B6D1FD464A818F21

XIOC detected MD5 Hash: 659951C2569711E7B6D1FD464A818F21

extracted_from_files

Hash
detected MD5 Hash: 659951BF569711E7B6D1FD464A818F21

XIOC detected MD5 Hash: 659951BF569711E7B6D1FD464A818F21

extracted_from_files

Hash
detected MD5 Hash: 43D2C24931F1E211964FB5A681E3029D

XIOC detected MD5 Hash: 43D2C24931F1E211964FB5A681E3029D

extracted_from_files

Hash
detected MD5 Hash: 18BA675BF13611E29371CF0B2EC7F3FF

XIOC detected MD5 Hash: 18BA675BF13611E29371CF0B2EC7F3FF

extracted_from_files

Hash
detected MD5 Hash: 18BA675AF13611E29371CF0B2EC7F3FF

XIOC detected MD5 Hash: 18BA675AF13611E29371CF0B2EC7F3FF

extracted_from_files

Hash
detected MD5 Hash: 3FEB604FF13411E29CACE88F13E6920D

XIOC detected MD5 Hash: 3FEB604FF13411E29CACE88F13E6920D

extracted_from_files

Hash
detected MD5 Hash: 3FEB604EF13411E29CACE88F13E6920D

XIOC detected MD5 Hash: 3FEB604EF13411E29CACE88F13E6920D

extracted_from_files

Hash
detected MD5 Hash: 5B111581F13411E2A304BE1B7D525DAC

XIOC detected MD5 Hash: 5B111581F13411E2A304BE1B7D525DAC

extracted_from_files

Hash
detected MD5 Hash: 5B111580F13411E2A304BE1B7D525DAC

XIOC detected MD5 Hash: 5B111580F13411E2A304BE1B7D525DAC

extracted_from_files

URL
detected URL: https://singleclickapps.com/images-on-off

XIOC detected URL: https://singleclickapps.com/images-on-off

extracted_from_files

URL
detected URL: http://crbug.com/112091

XIOC detected URL: http://crbug.com/112091

extracted_from_files

URL
detected URL: https://bugs.webkit.org/show_bug.cgi?id=63367

XIOC detected URL: https://bugs.webkit.org/show_bug.cgi?id=63367

extracted_from_files

URL
detected URL: https://singleclickapps.com/images-on-off/

XIOC detected URL: https://singleclickapps.com/images-on-off/

extracted_from_files

Hash
detected MD5 Hash: C55FE16202CCE11183EEB8674FD492E8

XIOC detected MD5 Hash: C55FE16202CCE11183EEB8674FD492E8

extracted_from_files

Hash
detected MD5 Hash: D5CB9C10F13611E28203F8923BC05510

XIOC detected MD5 Hash: D5CB9C10F13611E28203F8923BC05510

extracted_from_files

Hash
detected MD5 Hash: D5CB9C0FF13611E28203F8923BC05510

XIOC detected MD5 Hash: D5CB9C0FF13611E28203F8923BC05510

extracted_from_files

URL
detected URL: https://www.extensions-hub.com/partners/uninstalled/?name=Images+ON%2FOFF&propRef=Images-ON-OFF');

XIOC detected URL: https://www.extensions-hub.com/partners/uninstalled/?name=Images+ON%2FOFF&propRef=Images-ON-OFF');

extracted_from_files

URL
detected URL: http://www.w3.org/1999/02/22-rdf-syntax-ns#

XIOC detected URL: http://www.w3.org/1999/02/22-rdf-syntax-ns#

extracted_from_files

URL
detected URL: http://ns.adobe.com/xap/1.0/mm/

XIOC detected URL: http://ns.adobe.com/xap/1.0/mm/

extracted_from_files

URL
detected URL: http://ns.adobe.com/xap/1.0/sType/ResourceRef#

XIOC detected URL: http://ns.adobe.com/xap/1.0/sType/ResourceRef#

extracted_from_files

URL
detected URL: http://ns.adobe.com/xap/1.0/

XIOC detected URL: http://ns.adobe.com/xap/1.0/

extracted_from_files

URL
detected URL: https://clients2.google.com/service/update2/crx

XIOC detected URL: https://clients2.google.com/service/update2/crx

extracted_from_files

URL
detected URL: https://github.com/SingleClickApps

XIOC detected URL: https://github.com/SingleClickApps

extracted_from_files

URL
detected URL: http://www.maximelebreton.com/

XIOC detected URL: http://www.maximelebreton.com/

extracted_from_files

URL
detected URL: https://github.com/maximelebreton/quick-javascript-switcher/

XIOC detected URL: https://github.com/maximelebreton/quick-javascript-switcher/

extracted_from_files

URL
detected URL: https://singleclickapps.com/images-on-off/instructions.html',

XIOC detected URL: https://singleclickapps.com/images-on-off/instructions.html',

extracted_from_files

URL
detected URL: https://www.extensions-hub.com/partners/installed/?name=Images+ON%2FOFF&propRef=Images-ON-OFF',

XIOC detected URL: https://www.extensions-hub.com/partners/installed/?name=Images+ON%2FOFF&propRef=Images-ON-OFF',

extracted_from_files

URL
detected URL: https://singleclickapps.com/images-on-off-3-2/',

XIOC detected URL: https://singleclickapps.com/images-on-off-3-2/',

extracted_from_files

URL
detected URL: https://www.extensions-hub.com/partners/updated/?name=Images+ON%2FOFF&propRef=Images-ON-OFF

XIOC detected URL: https://www.extensions-hub.com/partners/updated/?name=Images+ON%2FOFF&propRef=Images-ON-OFF

extracted_from_files

Domain
detected Domain: crbug.com

XIOC detected Domain: crbug.com

extracted_from_files

Domain
detected Domain: bugs.webkit.org

XIOC detected Domain: bugs.webkit.org

extracted_from_files

URL
detected URL: http://www.gnu.org/licenses/gpl.html

XIOC detected URL: http://www.gnu.org/licenses/gpl.html

extracted_from_files

URL
detected URL: http://fsf.org/

XIOC detected URL: http://fsf.org/

extracted_from_files

Hash
detected MD5 Hash: 5A3EFB5F569711E780C6A689990B3462

XIOC detected MD5 Hash: 5A3EFB5F569711E780C6A689990B3462

extracted_from_files

URL
detected URL: http://www.gnu.org/philosophy/why-not-lgpl.html

XIOC detected URL: http://www.gnu.org/philosophy/why-not-lgpl.html

extracted_from_files

URL
detected URL: http://singleclickapps.com/

XIOC detected URL: http://singleclickapps.com/

extracted_from_files

Domain
detected Domain: www.maximelebreton.com

XIOC detected Domain: www.maximelebreton.com

extracted_from_files

Domain
detected Domain: www.extensions-hub.com

XIOC detected Domain: www.extensions-hub.com

extracted_from_files

Domain
detected Domain: www.singleclickapps.com

XIOC detected Domain: www.singleclickapps.com

extracted_from_files

Domain
detected Domain: tab.id

XIOC detected Domain: tab.id

extracted_from_files

Domain
detected Domain: www.w3.org

XIOC detected Domain: www.w3.org

extracted_from_files

Domain
detected Domain: ns.adobe.com

XIOC detected Domain: ns.adobe.com

extracted_from_files

Domain
detected Domain: clients2.google.com

XIOC detected Domain: clients2.google.com

extracted_from_files

IP
detected IP: 3.2.0.0

XIOC detected IP: 3.2.0.0

extracted_from_files

IP
detected IP: ed::bef

XIOC detected IP: ed::bef

extracted_from_files

IP
detected IP: ::

XIOC detected IP: ::

extracted_from_files

Domain
detected Domain: www.gnu.org

XIOC detected Domain: www.gnu.org

extracted_from_files

Domain
detected Domain: fsf.org

XIOC detected Domain: fsf.org

extracted_from_files

Domain
detected Domain: singleclickapps.com

XIOC detected Domain: singleclickapps.com

extracted_from_files

Hash
detected MD5 Hash: 716067DB569711E7BF4EF17AA3FF7319

XIOC detected MD5 Hash: 716067DB569711E7BF4EF17AA3FF7319

extracted_from_files

Security Analysis Summary

Security Analysis Overview

Images ON/OFF is a Chrome Web Store extension published by [email protected]. Version 3.2.0.0 has been analyzed by the Risky Plugins security platform, receiving a risk score of 51.17/100 (MEDIUM risk) based on 83 security findings.

Risk Assessment

This extension presents moderate security risk. Several findings were detected that may warrant attention. Users should carefully review the permissions and findings before installation.

Findings Breakdown

  • High: 11 finding(s)
  • Medium: 72 finding(s)

What Was Analyzed

The security assessment covers multiple analysis categories:

  • Malware Detection: YARA rule matching against 2,400+ malware signatures
  • Secret Detection: Scanning for exposed API keys, tokens, and credentials
  • Static Analysis: Code-level security analysis for common vulnerability patterns
  • Network Analysis: Detection of suspicious network communications and endpoints
  • Obfuscation Detection: Identification of code obfuscation techniques

Developer Information

Images ON/OFF is published by [email protected] on the Chrome Web Store marketplace. The extension has approximately 20K users.

Recommendation

Exercise caution with this extension. Review the detailed findings and ensure the requested permissions align with the extension's stated functionality before installation.

Frequently Asked Questions