APIVoid Phishing Reminder
The AI review rates the findings as likely false positive, but the risk score (55/100) still counts them.
Analysis record
- Analysed
- 3 months ago
- Version
- v1.3
- Artifact
- SHA256 8A2…55C
- Source
- Findings (non-IoC)
Evidence ledger
Ranked by severity · findings with a source location link to the code viewer
Network Indicators
Concrete URLs, domains, IPs, emails, and hashes extracted from the analyzed artifact.
Network indicators are queued for lazy loading
Scroll this section into view to load the detailed rows.
Publisher Evidence
Limited evidenceAPIVoid
Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.
Firefox does not expose the same publisher verification data as IDE stores, so this score is deliberately conservative.
13 evidence rows available.
Finding Categories
Requested Permissions
4 permissionsAccess and modify data on every website you visit
AI Security Report
AI Security Review
Risky Plugins reviewed this extension with an AI-assisted security workflow on 2026-05-31. The review verdict is likely false positive with 84% confidence.
Recommended action: suppress false positive. Evidence context: threat category none; evidence quality moderate.
The extension’s source files contain a single network call in background.js:39 marked as NET-FETCH-background.js-39, which simply issues a fetch request. No other network‑related code, cookie manipulation, or credential‑handling logic is present. Most of the flagged items are domain indicators extracted from the generic string pool (extracted_from_files). The list includes domains such as nexi.it, nexigroup.com, next.me, nebankers.org, nfcf.or.kr, nhbankers.com, nib.ie, netdsb.com, nextcloud.com, netflix.com, and newyorkfed.org. These entries are typical of the XIOC extractor’s tendency to treat any quoted string that resembles a hostname as a potential indicator, even when the string is part of a comment, documentation, or a harmless configuration object. There are no matches for known malware signatures, no obfuscation patterns, and no code‑smell findings that would indicate dangerous functionality.
The extension’s description—"Warns you when entering credentials on potentially unfamiliar websites to help prevent phishing attacks."—suggests a legitimate security‑aid purpose. However, the manifest lacks a developer name, and the user count is listed as zero, which is often a signal of low‑visibility or abandoned extensions. Despite this, the absence of any code that actually reads form fields, accesses cookies, or communicates sensitive data means the extension does not demonstrate credential‑theft capabilities.
The most striking aspect of the evidence is the sheer volume of IoC entries (3,740). This aligns with a known false‑positive pattern where the XIOC extractor reports every domain‑like token it encounters, inflating the finding count without indicating real malicious intent. None of the reported domains are exclusive command‑and‑control servers; many (e.g., netflix.com, nextcloud.com) are well‑known public services. The presence of banking‑oriented domains such as nebankers.org and nhbankers.com might raise concern, but without accompanying code that contacts these hosts, the risk remains speculative.
A skeptic could argue that the extension’s design—to monitor credential entry—might be a cover for exfiltrating passwords to the listed domains, especially given the lack of a verified developer. While that is a reasonable hypothesis, the analysis of the codebase finds no API calls that read input fields, no usage of the chrome.webRequest or chrome.cookies APIs, and no payload construction targeting the listed hosts. The single fetch call in background.js does not include a URL or data payload in the static analysis, indicating that it is likely a placeholder or a benign telemetry request. Without concrete evidence of data collection or transmission to the suspicious domains, the claim of active credential theft is unsupported.
In conclusion, the findings are best explained by the known behavior of the XIOC extractor and a low‑complexity extension that does not perform harmful actions. Monitoring for future updates is advisable, but the current evidence does not justify a higher threat classification.
Key Reasons
- No malware signatures or obfuscation detected
- Only one simple fetch call in background.js
- Domain IoCs stem from generic string extraction
- Lack of credential‑access or cookie‑handling code
False Positive Considerations
- IoC extractor garbage
- High IoC count from generic strings
- No malicious code patterns
- Absence of obfuscation or code‑smell findings
Source Code Not Available
Source code is not available for this version of the extension.
About This Extension
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace