Saladict - Pop-up Dictionary
From the RiskyPlugins AI security review of the observed evidence.
Analysis record
- Analysed
- 5 days ago
- Version
- v7.22.9
- Artifact
- SHA256 518…135
- Source
- Findings (non-IoC)
Evidence ledger
Ranked by severity · findings with a source location link to the code viewer
YARA Rule Matches
20 rules| Severity | Rule | Hits | Files | Metadata |
|---|---|---|---|---|
| HIGH | supply chain sourcemap appended iife | 1 | assets/vendor-antd.5a4e8a3e.js | - |
| LOW | postinstall file download | 46 | assets/content.c2dd6e12.jsassets/pdf/web/wasm/openjpeg_nowasm_fallback.jsassets/popup.2b1a9f2f.js +43 more | - |
| LOW | NoUseWeakRandom | 16 | assets/7.ee7c3046.jsassets/word-editor.c8f85a26.jsassets/23.543333d1.js +13 more | - |
| LOW | NoUseEval | 1 | assets/pdf/build/pdf.sandbox.mjs | - |
| LOW | SQLInjection | 2 | assets/23.543333d1.jsassets/wordpage.5ac75104.js | - |
| LOW | InsecureDownload | 2 | assets/options.fa4bc784.jsassets/background.c6319c36.js | - |
| LOW | postinstall registry modification | 9 | assets/vendor-dexie.cc0f05df.jsassets/vendor-dompurify.ac604f03.jsassets/options.fa4bc784.js +6 more | - |
| LOW | postinstall system command | 40 | assets/vendor-antd.5a4e8a3e.js_metadata/verified_contents.jsonassets/vendor-dompurify.ac604f03.js +37 more | - |
| LOW | postinstall file manipulation | 86 | assets/42.0c3afc96.jsassets/pdf/web/locale/ja/viewer.ftlassets/vendor-dompurify.ac604f03.js +83 more | - |
| LOW | postinstall crypto operations | 18 | assets/background.c6319c36.jsassets/vendor-dexie.cc0f05df.jsassets/vendor-react.3e80723c.js +15 more | - |
| LOW | postinstall network communication | 52 | assets/20.3b05ec29.jsassets/39.829673a0.jsassets/pdf/web/standard_fonts/FoxitDingbats.pfb +49 more | - |
| LOW | OriginsNotVerified | 5 | assets/wordpage.5ac75104.jsassets/selection.23e11196.jsassets/popup.2b1a9f2f.js +2 more | - |
| LOW | postinstall environment access | 1 | assets/pdf/web/standard_fonts/LICENSE_LIBERATION | - |
| LOW | AlertStatementsShouldNotBeUsed | 1 | assets/options.fa4bc784.js | - |
| LOW | postinstall obfuscation | 33 | assets/pdf/web/wasm/openjpeg_nowasm_fallback.jsassets/vendor-react.3e80723c.jsassets/browser-polyfill.min.js +30 more | - |
| LOW | LocalStorageShouldNotBeUsed | 11 | assets/content.c2dd6e12.jsassets/popup.2b1a9f2f.jsassets/word-editor.c8f85a26.js +8 more | - |
| LOW | credential metamask extension | 8 | assets/word-editor.c8f85a26.jsassets/background.c6319c36.jsassets/options.fa4bc784.js +5 more | - |
| LOW | DebuggerStatementsShouldNotBeUsed | 5 | assets/vendor-dexie.cc0f05df.jsassets/pdf/web/debugger.mjsassets/pdf/web/wasm/quickjs-eval.wasm +2 more | - |
| LOW | postinstall persistence mechanism | 21 | assets/pdf/web/standard_fonts/LiberationSans-Regular.ttfassets/vendor-dexie.cc0f05df.jsassets/vendor-dompurify.ac604f03.js +18 more | - |
| LOW | credential env files | 5 | assets/options.fa4bc784.jsassets/background.c6319c36.jsassets/22.085dfe59.js +2 more | - |
Network Indicators
Concrete URLs, domains, IPs, emails, and hashes extracted from the analyzed artifact.
Network indicators are queued for lazy loading
Scroll this section into view to load the detailed rows.
Publisher Evidence
Limited evidencerumosky
Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.
Edge does not expose the same publisher verification data as IDE stores, so this score is deliberately conservative.
13 evidence rows available.
Finding Categories
YARA Rules Matched
20 rules(363 hits)AI Security Report
AI Security Review
Evidence context: threat category typosquatting; evidence quality moderate.
This extension claims to be "Saladict - Pop-up Dictionary and Page Translator" by developer "rumosky" with 0 users and unknown version. The evidence presents conflicting signals that require runtime analysis to resolve.
The network findings are benign: all 35 network detections originate from assets/pdf/build/pdf.worker.js and assets/pdf/build/pdf.js, which are legitimate PDF.js library files. These fetch and xmlhttprequest calls are expected behavior for PDF rendering functionality, not suspicious network activity. This aligns with the extension's described feature of "PDF selection searching."
However, the malware signature count of 441 is significant and warrants investigation. According to the threat model, malware signatures co-located with obfuscation in the same file indicate malicious behavior. The evidence shows only 1 obfuscation finding, but the specific file locations of the 441 malware signatures are not provided in the findings bucket. This prevents determining whether signatures originate from legitimate bundled libraries (common false positive pattern) or actual malicious code.
The extension metadata raises red flags: version is "unknown" and user count is 0. The legitimate Saladict extension has thousands of users and a different developer attribution. This could indicate typosquatting, but could also be a new or regional variant. The developer name "rumosky" does not match the known Saladict publisher.
The 1959 IoC findings are high-volume noise that requires domain-level inspection. Without seeing specific domains, these could be garbage IoCs from the extractor or legitimate dictionary API endpoints. The guidelines state IoC COUNT alone is meaningless; only specific suspicious domains matter.
Counterargument: A skeptic would argue this is the legitimate Saladict extension with false positives from bundled PDF.js and dictionary libraries, since the network findings are clearly from legitimate code. However, the unknown version field, zero users, and 441 malware signatures create genuine uncertainty that cannot be resolved without inspecting the actual malware signature locations and comparing against the legitimate extension's codebase.
Runtime analysis is required to determine if this is a malicious clone impersonating Saladict or a legitimate extension with inflated false positive counts.
Key Reasons
- 441 malware signatures require location verification to distinguish bundled code from actual malware
- Version field is unknown, preventing comparison with legitimate Saladict versions
- Zero users and developer name mismatch with known Saladict publisher suggest possible typosquatting
- Network findings are benign PDF.js library calls, not suspicious activity
False Positive Considerations
- Bundled PDF.js library files triggering network findings
- High IoC count from dictionary API endpoints or blocklist data
- Malware signatures potentially from bundled dependencies in dist/ files
Reviewed 2026-04-27; recommended action: runtime analysis; model confidence 65%.
Edge version history
Risk trend by version
9 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.
Pick any point on the chart to explore that version's code below.
Source Code Not Available
Source code is not available for this version of the extension.
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace
PrintFriendly: Print, PDF Editor & Full Page Screenshot
Unknown Developer
Boomerang for Gmail
Unknown Developer
OrbitNote
Unknown Developer
AdBlock — block ads across the web
Unknown Developer
Whatfix Studio
Unknown Developer
AI Grammar Checker & Paraphraser – LanguageTool
Unknown Developer