Kindredly - A safer, private web for families
From the RiskyPlugins AI security review of the observed evidence.
Analysis record
- Analysed
- 4 days ago
- Version
- v3.1.2
- Artifact
- SHA256 218…DE5
- Source
- Findings (non-IoC)
Is Kindredly - A safer, private web for families safe?
The extension declares no special permissions, so the supplied metadata does not show access to browser history, cookies, or all websites. Its listed endpoints include 0-t.top, a-1-e.padinfo.top, and a-t.porn, while NET-WEBSOCKET-js/hot-reloadANRsPRRO.js-1 points to WebSocket code in js/hot-reloadANRsPRRO.js:1:0. The endpoint list also includes a Google OAuth client endpoint, so the destinations need to be tied to features in the app.
The main warning is YARA--supply_chain_sourcemap_appended_iife at /tmp/extract-218f1e6c3d5a5ac5d7c637a564e75f047d7eb01d051b27e9b9e41d907f73ade5-3182759720/sandbox-nonet.html:177. If that match is real injected code, it could run code added to the extension package. OBFUSCATION-UNICODE_HEAVY-content-script-interact.js-2 at content-script-interact.js:2:0 adds a second file that needs inspection.
Some alerts have ordinary software explanations. OBFUSCATION-LARGE_WASM_FILE-modeldata/wasm/ort-wasm-simd-threaded.jsep.wasm-0 points to a model runtime, and NET-WEBSOCKET-js/hot-reloadANRsPRRO.js-1 points to hot-reload tooling. Those details explain scanner noise around packaged code, while sandbox-nonet.html:177 and the unusual endpoints still leave the package unresolved.
Evidence ledger
Ranked by severity · findings with a source location link to the code viewer
YARA Rule Matches
15 rules| Severity | Rule | Hits | Files | Metadata |
|---|---|---|---|---|
| HIGH | supply chain sourcemap appended iife | 1 | sandbox-nonet.html | - |
| LOW | postinstall file download | 142 | js/SubscriptionFeedCHZB2iEu.jsjs/AddItemDefaultDFJvgx-v.jsjs/UserLibraryCh8xgqE4.js +139 more | - |
| LOW | NoUseWeakRandom | 49 | js/UsageLimitWizardD8NbbLok.jsjs/FilteringOptionsComponentB_VzGnFF.jsjs/appLifecycle.storeDTNtqzGS.js +46 more | - |
| LOW | UntrustedContentShouldNotBeIncluded | 1 | js/EbookReaderC5kckFJi.js | - |
| LOW | UsingIntrusivePermissionsWithGeolocation | 2 | js/AppIFramea8rdVonG.jsjs/ItemC18gfuBV.js | - |
| LOW | SQLInjection | 4 | js/AppCreatorPageCBSImExv.jsjs/dexie2jmnBxhj.jsjs/ort.bundle.minCVbVYmDH.js +1 more | - |
| LOW | NoUseEval | 1 | js/vue3-lottie.es1R-1O5Wk.js | - |
| LOW | credential env files | 21 | js/heic2anyDpG77T-a.jsjs/ImportAppFromGit9SOYqxS-.jsjs/bgroutery97Sj9g4.js +18 more | - |
| LOW | postinstall persistence mechanism | 37 | js/registryDg8v9u6-.jsjs/bgroutery97Sj9g4.jsjs/jszip.minqIFW4f3u.js +34 more | - |
| LOW | credential skype data | 1 | js/deviceAppPolicyDBndb3z8.js | - |
| LOW | postinstall crypto operations | 126 | background.jsjs/thing-extractionmvodnKVL.jscontent-script-reddit-hide-other-distractions.js +123 more | - |
| LOW | postinstall file manipulation | 277 | js/LibraryHealthCleanupDQGwi-el.jsjs/AccessControlsPanelComponentDN3pq9vn.jsjs/TaskBarDlm8NnVI.js +274 more | - |
| LOW | postinstall environment access | 181 | js/UserLoginPrefsCpP4Laps.jsjs/useSimilarItemsCKM1xGeH.jsjs/ViewFeedItemDpG1Fjdd.js +178 more | - |
| LOW | postinstall registry modification | 2 | modeldata/Xenova/all-MiniLM-L6-v2/tokenizer.jsonjs/MySettingsDashboardlpoYUO2O.js | - |
| LOW | postinstall system command | 98 | js/CollectionPermissionsBTRLtiPj.jsjs/registryDg8v9u6-.jsjs/TaskModalDhvCMmn6.js +95 more | - |
Network Indicators
Concrete URLs, domains, IPs, emails, and hashes extracted from the analyzed artifact.
Network indicators are queued for lazy loading
Scroll this section into view to load the detailed rows.
Publisher Evidence
Limited evidencePublisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.
Chrome does not expose the same publisher verification data as IDE stores, so this score is deliberately conservative.
13 evidence rows available.
Finding Categories
YARA Rules Matched
15 rules(943 hits)Requested Permissions
16 permissionsExchange messages with programs outside the browser
Access and modify data on every website you visit
AI Security Report
AI Security Review
Evidence context: threat category unknown malware; evidence quality moderate.
The strongest signal is YARA--supply_chain_sourcemap_appended_iife, which matches /tmp/extract-218f1e6c3d5a5ac5d7c637a564e75f047d7eb01d051b27e9b9e41d907f73ade5-3182759720/sandbox-nonet.html:177. A supply-chain signature deserves direct inspection because the title describes code appended to an IIFE, a pattern that can hide an injected payload. The finding has no description, so the available record does not show whether the matched text is executable malware, a source-map artifact, or a scanner match against generated HTML.
The code also has two high-severity Unicode findings: OBFUSCATION-UNICODE_HEAVY-js/transformers.webMzzrW8vp.js-24 at js/transformers.webMzzrW8vp.js:24:0 and OBFUSCATION-UNICODE_HEAVY-content-script-interact.js-2 at content-script-interact.js:2:0. The content-script location gives this signal more weight than a finding confined to a locale file. Other findings point to generated or packaged components, including OBFUSCATION-LARGE_WASM_FILE-modeldata/wasm/ort-wasm-simd-threaded.jsep.wasm-0 at modeldata/wasm/ort-wasm-simd-threaded.jsep.wasm:0:0, OBFUSCATION-LARGE_BASE64-js/kokoroDiiYrAXS.js-1 at js/kokoroDiiYrAXS.js:1:0, and OBFUSCATION-FROMCHARCODE_BULK-js/item-name.utilsB25Dh-PW.js-5 at js/item-name.utilsB25Dh-PW.js:5:0. Those files can belong to model, image, or build tooling, so their titles alone do not establish hostile intent.
The network findings also need context. NET-WEBSOCKET-js/hot-reloadANRsPRRO.js-1 at js/hot-reloadANRsPRRO.js:1:0 is consistent with development tooling, while fetch and Socket.IO findings in js/baseBn6ukCMV.js identify communication code without naming its destination. The endpoint list includes 0-t.top, a-1-e.padinfo.top, and a-t.porn, which are unusual for a family browsing product. It also includes 2mdn.net, 2o7.net, and a Google OAuth client endpoint, so the endpoint list contains both ad or service infrastructure and domains that require validation. No host permissions or extension permissions are listed, which limits the demonstrated reach of any web-data collection claim.
A skeptic would point to modeldata/wasm/ort-wasm-simd-threaded.jsep.wasm:0:0, js/hot-reloadANRsPRRO.js:1:0, and the generated-looking filenames as reasons to treat the findings as build noise. That argument explains several obfuscation and network matches, and the empty descriptions on YARA--supply_chain_sourcemap_appended_iife and the Unicode findings leave important uncertainty. It does not resolve the supply-chain match in sandbox-nonet.html:177, the Unicode-heavy content script at content-script-interact.js:2:0, or the unusual endpoints 0-t.top and a-1-e.padinfo.top. Runtime tracing of those files and destination validation are needed before clearing the extension or requesting removal.
Key Reasons
YARA--supply_chain_sourcemap_appended_iifematched/tmp/extract-218f1e6c3d5a5ac5d7c637a564e75f047d7eb01d051b27e9b9e41d907f73ade5-3182759720/sandbox-nonet.html:177.OBFUSCATION-UNICODE_HEAVY-content-script-interact.js-2matchedcontent-script-interact.js:2:0, placing high Unicode obfuscation in a content script.- The listed endpoints include
0-t.top,a-1-e.padinfo.top, anda-t.porn, which require destination validation for a family browsing extension. OBFUSCATION-LARGE_WASM_FILE-modeldata/wasm/ort-wasm-simd-threaded.jsep.wasm-0andNET-WEBSOCKET-js/hot-reloadANRsPRRO.js-1provide plausible build-tool explanations for some alerts.
False Positive Considerations
- Generated or bundled runtime code in
modeldata/wasm/ort-wasm-simd-threaded.jsep.wasmandjs/kokoroDiiYrAXS.jscan trigger size, Base64, and indirect-function rules. NET-WEBSOCKET-js/hot-reloadANRsPRRO.js-1names hot-reload code, which is consistent with development tooling.OBFUSCATION-LARGE_BASE64-js/kokoroDiiYrAXS.js-1andOBFUSCATION-FROMCHARCODE_BULK-js/item-name.utilsB25Dh-PW.js-5can result from packaged assets or generated modules.- The endpoint list includes infrastructure such as
2mdn.net,2o7.net, and a Google OAuth client endpoint alongside unusual domains.
Reviewed 2026-09-29; recommended action: runtime analysis; model confidence 78%.
Chrome version history
Risk trend by version
4 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.
Pick any point on the chart to explore that version's code below.
Source Code Not Available
Source code is not available for this version of the extension.
About This Extension
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace
Edge Translate - Browser Translator | PDF Translation | MV3 | Open Source
[email protected]
Intelbras Cloud
[email protected]
SlingPlayer for DISH Anywhere
Unknown Developer
My Jobscore
[email protected]
种草星球-TikTok爆单神器,商品自动提报采集邀评【永久免费】
[email protected]
Open Headers
[email protected]