Chrome Web Store

Kindredly - A safer, private web for families

by [email protected] · 20 users · 5.0 rating
a80ebb0a-1903-5559-a735-5034cf734507 | v3.1.2
86/ 100
CRITICAL risk
No change since v3.1.1
Analyst verdict
Needs follow up

From the RiskyPlugins AI security review of the observed evidence.

Analysis record

Analysed
4 days ago
Version
v3.1.2
Artifact
SHA256 218…DE5
Source
Findings (non-IoC)

Is Kindredly - A safer, private web for families safe?

The extension declares no special permissions, so the supplied metadata does not show access to browser history, cookies, or all websites. Its listed endpoints include 0-t.top, a-1-e.padinfo.top, and a-t.porn, while NET-WEBSOCKET-js/hot-reloadANRsPRRO.js-1 points to WebSocket code in js/hot-reloadANRsPRRO.js:1:0. The endpoint list also includes a Google OAuth client endpoint, so the destinations need to be tied to features in the app.

The main warning is YARA--supply_chain_sourcemap_appended_iife at /tmp/extract-218f1e6c3d5a5ac5d7c637a564e75f047d7eb01d051b27e9b9e41d907f73ade5-3182759720/sandbox-nonet.html:177. If that match is real injected code, it could run code added to the extension package. OBFUSCATION-UNICODE_HEAVY-content-script-interact.js-2 at content-script-interact.js:2:0 adds a second file that needs inspection.

Some alerts have ordinary software explanations. OBFUSCATION-LARGE_WASM_FILE-modeldata/wasm/ort-wasm-simd-threaded.jsep.wasm-0 points to a model runtime, and NET-WEBSOCKET-js/hot-reloadANRsPRRO.js-1 points to hot-reload tooling. Those details explain scanner noise around packaged code, while sandbox-nonet.html:177 and the unusual endpoints still leave the package unresolved.

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

1000 detail rows
Showing 25 of 57 · highest severity first

YARA Rule Matches

10 rules
SeverityRuleHitsFilesMetadata
HIGHsupply chain sourcemap appended iife 1
sandbox-nonet.html
-
LOWpostinstall crypto operations 128
background.jsjs/thing-extractionmvodnKVL.jscontent-script-reddit-hide-other-distractions.js +125 more
-
LOWpostinstall file manipulation 277
js/LibraryHealthCleanupDQGwi-el.jsjs/AccessControlsPanelComponentDN3pq9vn.jsjs/TaskBarDlm8NnVI.js +274 more
-
LOWpostinstall environment access 181
js/UserLoginPrefsCpP4Laps.jsjs/familyPolicyRulesD0Q0QFkb.jsjs/useLibraryBrowseAxesBb9KV2SC.js +178 more
-
LOWpostinstall registry modification 20
modeldata/Xenova/all-MiniLM-L6-v2/tokenizer.jsonjs/MySettingsDashboardlpoYUO2O.jsjs/MyUserFilesBGAHCzCz.js +17 more
-
LOWpostinstall system command 128
js/CollectionPermissionsBTRLtiPj.jsjs/registryDg8v9u6-.jsjs/TaskModalDhvCMmn6.js +125 more
-
LOWcredential steam data 1
js/deviceAppPolicyDBndb3z8.js
-
LOWpostinstall network communication 161
content-script-reddit-hide-comments.jsmodeldata/Xenova/all-MiniLM-L6-v2/tokenizer.jsonjs/ImageClassTestDIo_q5ug.js +158 more
-
LOWpostinstall obfuscation 45
js/EbookReaderC5kckFJi.jsjs/bgroutery97Sj9g4.jsalpine.min.js +42 more
-
LOWOriginsNotVerified 1
js/EbookReaderC5kckFJi.js
-

Network Indicators

Concrete URLs, domains, IPs, emails, and hashes extracted from the analyzed artifact.

1,524 total
...

Network indicators are queued for lazy loading

Scroll this section into view to load the detailed rows.

Publisher Evidence

Limited evidence

[email protected]

Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.

Chrome does not expose the same publisher verification data as IDE stores, so this score is deliberately conservative.

24
Noisy-finding weight
x1.00
Publisher domain
No domain
Missing
Store verification signal
Limited signal
Limited
Extension portfolio
1
Portfolio

13 evidence rows available.

Finding Categories

1
Malware Signatures
9
Obfuscation
46
Network
1,524
IoC Indicators

YARA Rules Matched

10 rules(943 hits)
supply chain sourcemap appended iife postinstall crypto operations postinstall file manipulation postinstall environment access postinstall registry modification postinstall system command credential steam data postinstall network communication postinstall obfuscation OriginsNotVerified

Requested Permissions

16 permissions
nativeMessaging

Exchange messages with programs outside the browser

Dangerous
<all_urls>

Access and modify data on every website you visit

Dangerous
https://*/*
Dangerous
http://*/*
Dangerous
activeTab
Medium
tabs
Medium
bookmarks
Medium
scripting
Low
storage
Low
unlimitedStorage
Low
alarms
Low
webNavigation
Low
contextMenus
Low
sidePanel
Low
search
Low
offscreen
Low

AI Security Report

AI Security Review

Evidence context: threat category unknown malware; evidence quality moderate.

The strongest signal is YARA--supply_chain_sourcemap_appended_iife, which matches /tmp/extract-218f1e6c3d5a5ac5d7c637a564e75f047d7eb01d051b27e9b9e41d907f73ade5-3182759720/sandbox-nonet.html:177. A supply-chain signature deserves direct inspection because the title describes code appended to an IIFE, a pattern that can hide an injected payload. The finding has no description, so the available record does not show whether the matched text is executable malware, a source-map artifact, or a scanner match against generated HTML.

The code also has two high-severity Unicode findings: OBFUSCATION-UNICODE_HEAVY-js/transformers.webMzzrW8vp.js-24 at js/transformers.webMzzrW8vp.js:24:0 and OBFUSCATION-UNICODE_HEAVY-content-script-interact.js-2 at content-script-interact.js:2:0. The content-script location gives this signal more weight than a finding confined to a locale file. Other findings point to generated or packaged components, including OBFUSCATION-LARGE_WASM_FILE-modeldata/wasm/ort-wasm-simd-threaded.jsep.wasm-0 at modeldata/wasm/ort-wasm-simd-threaded.jsep.wasm:0:0, OBFUSCATION-LARGE_BASE64-js/kokoroDiiYrAXS.js-1 at js/kokoroDiiYrAXS.js:1:0, and OBFUSCATION-FROMCHARCODE_BULK-js/item-name.utilsB25Dh-PW.js-5 at js/item-name.utilsB25Dh-PW.js:5:0. Those files can belong to model, image, or build tooling, so their titles alone do not establish hostile intent.

The network findings also need context. NET-WEBSOCKET-js/hot-reloadANRsPRRO.js-1 at js/hot-reloadANRsPRRO.js:1:0 is consistent with development tooling, while fetch and Socket.IO findings in js/baseBn6ukCMV.js identify communication code without naming its destination. The endpoint list includes 0-t.top, a-1-e.padinfo.top, and a-t.porn, which are unusual for a family browsing product. It also includes 2mdn.net, 2o7.net, and a Google OAuth client endpoint, so the endpoint list contains both ad or service infrastructure and domains that require validation. No host permissions or extension permissions are listed, which limits the demonstrated reach of any web-data collection claim.

A skeptic would point to modeldata/wasm/ort-wasm-simd-threaded.jsep.wasm:0:0, js/hot-reloadANRsPRRO.js:1:0, and the generated-looking filenames as reasons to treat the findings as build noise. That argument explains several obfuscation and network matches, and the empty descriptions on YARA--supply_chain_sourcemap_appended_iife and the Unicode findings leave important uncertainty. It does not resolve the supply-chain match in sandbox-nonet.html:177, the Unicode-heavy content script at content-script-interact.js:2:0, or the unusual endpoints 0-t.top and a-1-e.padinfo.top. Runtime tracing of those files and destination validation are needed before clearing the extension or requesting removal.

Key Reasons

  • YARA--supply_chain_sourcemap_appended_iife matched /tmp/extract-218f1e6c3d5a5ac5d7c637a564e75f047d7eb01d051b27e9b9e41d907f73ade5-3182759720/sandbox-nonet.html:177.
  • OBFUSCATION-UNICODE_HEAVY-content-script-interact.js-2 matched content-script-interact.js:2:0, placing high Unicode obfuscation in a content script.
  • The listed endpoints include 0-t.top, a-1-e.padinfo.top, and a-t.porn, which require destination validation for a family browsing extension.
  • OBFUSCATION-LARGE_WASM_FILE-modeldata/wasm/ort-wasm-simd-threaded.jsep.wasm-0 and NET-WEBSOCKET-js/hot-reloadANRsPRRO.js-1 provide plausible build-tool explanations for some alerts.

False Positive Considerations

  • Generated or bundled runtime code in modeldata/wasm/ort-wasm-simd-threaded.jsep.wasm and js/kokoroDiiYrAXS.js can trigger size, Base64, and indirect-function rules.
  • NET-WEBSOCKET-js/hot-reloadANRsPRRO.js-1 names hot-reload code, which is consistent with development tooling.
  • OBFUSCATION-LARGE_BASE64-js/kokoroDiiYrAXS.js-1 and OBFUSCATION-FROMCHARCODE_BULK-js/item-name.utilsB25Dh-PW.js-5 can result from packaged assets or generated modules.
  • The endpoint list includes infrastructure such as 2mdn.net, 2o7.net, and a Google OAuth client endpoint alongside unusual domains.

Reviewed 2026-09-29; recommended action: runtime analysis; model confidence 78%.

Chrome version history

Risk trend by version

4 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.

Selected
86
Change since first
+22
Change from previous
No change
Versions:
First analyzed version
1.0.35
Mar 11, 2026
Risk range
64 to 86
Across analyzed versions
Latest analyzed version
3.1.2
Sep 27, 2026
Selected version
critical
Version
v3.1.2
4 days ago
Risk score
86
Findings
3024
Change vs previous
No change

Pick any point on the chart to explore that version's code below.

About This Extension

Kindredly helps families create a safer, more meaningful web experience together. Build private collections of trusted websites, videos, and resources. Share them with family members through a private, family-only network designed to make it easy to pass along what matters. With family-friendly browsing, content filtering, and usage limits, Kindredly helps reduce distractions, avoid junk, and guide kids toward higher-quality content. Kindredly is built for families who want more than basic blocking. It combines private sharing, guided browsing, and healthier digital habits in one place. Sensitive family content stays private, with end-to-end encryption built into the platform. Features: - Build and share private collections with family members - Family-only sharing through a private internal network - Library-first browsing for access to trusted content - Content filtering and usage limits - Fewer distractions and a more focused web experience - Free version available with no ads The internet has amazing educational and enriching content, but it is also full of noise, addictive distractions, and inappropriate material. Kindredly helps families get to the good stuff faster and create a better web experience together. -- Change Log -- - 8/8/2026 - introduced daily check-in which requires restricted users to "check-in" with parents before using the web that day - simplified UI for library and subscription pages - improved search performance for large libraries - 7/1/2026 - fixed bug allowing users to visit channels of videos in there library without explicit channel permissions - improved sync efficiency - reduced download size - 6/26/2026 - addressed login issues - 5/24/2026 - ui and performance improvements - 4/26/2026 - performance fixes - darkmode flash fix - 4/15/2026 - fixed issues with usage logging/time tracking - 4/11/2026 - performance improvements - 3/18/2026 - fix publishing issue - 2/25/2026 - Device-only Mode (no account needed with all data stored on device) - Introduction of advanced parental controls - UI improvements

Frequently Asked Questions