Microsoft Edge Add-ons Verified

Saladict - Pop-up Dictionary

a7427e20-6d7a-5345-98b6-6bd2be499f49 | v7.22.9
84/ 100
HIGH risk
+19 since v7.22.8
Analyst verdict
Needs follow up

From the RiskyPlugins AI security review of the observed evidence.

Analysis record

Analysed
5 days ago
Version
v7.22.9
Artifact
SHA256 518…135
Source
Findings (non-IoC)

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

854 detail rows
Showing 25 of 491 · highest severity first

YARA Rule Matches

20 rules
SeverityRuleHitsFilesMetadata
HIGHsupply chain sourcemap appended iife 1
assets/vendor-antd.5a4e8a3e.js
-
LOWpostinstall file download 46
assets/content.c2dd6e12.jsassets/pdf/web/wasm/openjpeg_nowasm_fallback.jsassets/popup.2b1a9f2f.js +43 more
-
LOWNoUseWeakRandom 16
assets/7.ee7c3046.jsassets/word-editor.c8f85a26.jsassets/23.543333d1.js +13 more
-
LOWNoUseEval 1
assets/pdf/build/pdf.sandbox.mjs
-
LOWSQLInjection 2
assets/23.543333d1.jsassets/wordpage.5ac75104.js
-
LOWInsecureDownload 2
assets/options.fa4bc784.jsassets/background.c6319c36.js
-
LOWpostinstall registry modification 9
assets/vendor-dexie.cc0f05df.jsassets/vendor-dompurify.ac604f03.jsassets/options.fa4bc784.js +6 more
-
LOWpostinstall system command 40
assets/vendor-antd.5a4e8a3e.js_metadata/verified_contents.jsonassets/vendor-dompurify.ac604f03.js +37 more
-
LOWpostinstall file manipulation 86
assets/42.0c3afc96.jsassets/pdf/web/locale/ja/viewer.ftlassets/vendor-dompurify.ac604f03.js +83 more
-
LOWpostinstall crypto operations 18
assets/background.c6319c36.jsassets/vendor-dexie.cc0f05df.jsassets/vendor-react.3e80723c.js +15 more
-
LOWpostinstall network communication 52
assets/20.3b05ec29.jsassets/39.829673a0.jsassets/pdf/web/standard_fonts/FoxitDingbats.pfb +49 more
-
LOWOriginsNotVerified 5
assets/wordpage.5ac75104.jsassets/selection.23e11196.jsassets/popup.2b1a9f2f.js +2 more
-
LOWpostinstall environment access 1
assets/pdf/web/standard_fonts/LICENSE_LIBERATION
-
LOWAlertStatementsShouldNotBeUsed 1
assets/options.fa4bc784.js
-
LOWpostinstall obfuscation 33
assets/pdf/web/wasm/openjpeg_nowasm_fallback.jsassets/vendor-react.3e80723c.jsassets/browser-polyfill.min.js +30 more
-
LOWLocalStorageShouldNotBeUsed 11
assets/content.c2dd6e12.jsassets/popup.2b1a9f2f.jsassets/word-editor.c8f85a26.js +8 more
-
LOWcredential metamask extension 8
assets/word-editor.c8f85a26.jsassets/background.c6319c36.jsassets/options.fa4bc784.js +5 more
-
LOWDebuggerStatementsShouldNotBeUsed 5
assets/vendor-dexie.cc0f05df.jsassets/pdf/web/debugger.mjsassets/pdf/web/wasm/quickjs-eval.wasm +2 more
-
LOWpostinstall persistence mechanism 21
assets/pdf/web/standard_fonts/LiberationSans-Regular.ttfassets/vendor-dexie.cc0f05df.jsassets/vendor-dompurify.ac604f03.js +18 more
-
LOWcredential env files 5
assets/options.fa4bc784.jsassets/background.c6319c36.jsassets/22.085dfe59.js +2 more
-

Network Indicators

Concrete URLs, domains, IPs, emails, and hashes extracted from the analyzed artifact.

562 total
...

Network indicators are queued for lazy loading

Scroll this section into view to load the detailed rows.

Publisher Evidence

Limited evidence

rumosky

Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.

Edge does not expose the same publisher verification data as IDE stores, so this score is deliberately conservative.

38
Noisy-finding weight
x1.00
Publisher domain
saladict.crimx.com
Observed
Store verification signal
Limited signal
Limited
Extension portfolio
2
Portfolio

13 evidence rows available.

Finding Categories

1
Malware Signatures
14
Obfuscation
12
Network
562
IoC Indicators

YARA Rules Matched

20 rules(363 hits)
supply chain sourcemap appended iife postinstall file download NoUseWeakRandom NoUseEval SQLInjection InsecureDownload postinstall registry modification postinstall system command postinstall file manipulation postinstall crypto operations postinstall network communication OriginsNotVerified postinstall environment access AlertStatementsShouldNotBeUsed postinstall obfuscation LocalStorageShouldNotBeUsed +4 more

AI Security Report

AI Security Review

Evidence context: threat category typosquatting; evidence quality moderate.

This extension claims to be "Saladict - Pop-up Dictionary and Page Translator" by developer "rumosky" with 0 users and unknown version. The evidence presents conflicting signals that require runtime analysis to resolve.

The network findings are benign: all 35 network detections originate from assets/pdf/build/pdf.worker.js and assets/pdf/build/pdf.js, which are legitimate PDF.js library files. These fetch and xmlhttprequest calls are expected behavior for PDF rendering functionality, not suspicious network activity. This aligns with the extension's described feature of "PDF selection searching."

However, the malware signature count of 441 is significant and warrants investigation. According to the threat model, malware signatures co-located with obfuscation in the same file indicate malicious behavior. The evidence shows only 1 obfuscation finding, but the specific file locations of the 441 malware signatures are not provided in the findings bucket. This prevents determining whether signatures originate from legitimate bundled libraries (common false positive pattern) or actual malicious code.

The extension metadata raises red flags: version is "unknown" and user count is 0. The legitimate Saladict extension has thousands of users and a different developer attribution. This could indicate typosquatting, but could also be a new or regional variant. The developer name "rumosky" does not match the known Saladict publisher.

The 1959 IoC findings are high-volume noise that requires domain-level inspection. Without seeing specific domains, these could be garbage IoCs from the extractor or legitimate dictionary API endpoints. The guidelines state IoC COUNT alone is meaningless; only specific suspicious domains matter.

Counterargument: A skeptic would argue this is the legitimate Saladict extension with false positives from bundled PDF.js and dictionary libraries, since the network findings are clearly from legitimate code. However, the unknown version field, zero users, and 441 malware signatures create genuine uncertainty that cannot be resolved without inspecting the actual malware signature locations and comparing against the legitimate extension's codebase.

Runtime analysis is required to determine if this is a malicious clone impersonating Saladict or a legitimate extension with inflated false positive counts.

Key Reasons

  • 441 malware signatures require location verification to distinguish bundled code from actual malware
  • Version field is unknown, preventing comparison with legitimate Saladict versions
  • Zero users and developer name mismatch with known Saladict publisher suggest possible typosquatting
  • Network findings are benign PDF.js library calls, not suspicious activity

False Positive Considerations

  • Bundled PDF.js library files triggering network findings
  • High IoC count from dictionary API endpoints or blocklist data
  • Malware signatures potentially from bundled dependencies in dist/ files

Reviewed 2026-04-27; recommended action: runtime analysis; model confidence 65%.

Edge version history

Risk trend by version

9 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.

Selected
84
Change since first
+19
Change from previous
+19
Versions:
First analyzed version
7.22.0
May 5, 2026
Risk range
65 to 84
Across analyzed versions
Latest analyzed version
7.22.9
Sep 26, 2026
Selected version
high
Version
v7.22.9
5 days ago
Risk score
84
Findings
1416
Change vs previous
+19

Pick any point on the chart to explore that version's code below.

Frequently Asked Questions