Chrome Web Store

种草星球,TikTok批量建联,达人建联,达人管理,自动提报

by [email protected] · 10 users · 5.0 rating
ada81877-fc25-50be-925e-277c37884f07 | v4.1.57
76/ 100
HIGH risk
-11 since v4.1.55
Analyst verdict
Review before use

The AI review rates the findings as likely false positive, but the risk score (76/100) still counts them.

Analysis record

Analysed
1 weeks ago
Version
v4.1.57
Artifact
SHA256 20E…05C
Source
Findings (non-IoC)

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

4 detail rows

YARA Rule Matches

1 rule
SeverityRuleHitsFilesMetadata
HIGHsupply chain sourcemap appended iife 1
js/chunk-vendors.js
-

Publisher Evidence

Limited evidence

[email protected]

Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.

Chrome does not expose the same publisher verification data as IDE stores, so this score is deliberately conservative.

29
Noisy-finding weight
x1.00
Publisher domain
No domain
Missing
Store verification signal
Limited signal
Limited
Extension portfolio
2
Portfolio

12 evidence rows available.

Finding Categories

1
Malware Signatures
2
Network

YARA Rules Matched

1 rule
supply chain sourcemap appended iife

Requested Permissions

46 permissions
tabs
Medium
declarativeNetRequest
Low
storage
Low
alarms
Low
scripting
Low
https://buyin.jinritemai.com/*
Low
https://affiliate.tiktokglobalshop.com/*
Low
https://affiliate.tiktokshopglobalselling.com/*
Low
https://affiliate-id.tokopedia.com/*
Low
https://www.wuyoukuajing.com/*
Low
https://eos.douyin.com/*
Low
*://*.tiktokshop.com/*
Low
*://*.tiktok.com/*
Low
*://*.tikclubs.com/*
Low
https://*.douyin.com/*
Low
*://*.jinritemai.com/*
Low
https://d.zcxq.com/*
Low
https://wd.zcxq.com/*
Low
https://zs.kwaixiaodian.com/*
Low
https://channels.weixin.qq.com/*
Low
https://*.weixin.qq.com/*
Low
https://liveplatform.taobao.com/*
Low
https://www.xiaohongshu.com/*
Low
*://*.xiaohongshu.com/*
Low
https://*.kwaixiaodian.com/*
Low
https://housengine.com/*
Low
https://www.amazon.com/*
Low
https://www.amazon.co.jp/*
Low
https://www.amazon.co.uk/*
Low
https://www.amazon.de/*
Low
https://www.amazon.fr/*
Low
https://www.amazon.es/*
Low
https://www.amazon.it/*
Low
https://www.amazon.ca/*
Low
https://www.amazon.in/*
Low
https://www.amazon.com.mx/*
Low
https://www.amazon.com.au/*
Low
https://www.amazon.ae/*
Low
https://www.amazon.nl/*
Low
https://www.amazon.pl/*
Low
https://www.amazon.se/*
Low
https://www.amazon.sa/*
Low
https://www.amazon.sg/*
Low
https://www.amazon.com.br/*
Low
https://www.amazon.com.tr/*
Low
https://sellercentral.amazon.com/*
Low

AI Security Report

AI Security Review

Evidence context: threat category none; evidence quality weak.

种草星球 (Zhongcaoxingqiu) is a browser extension targeting Chinese TikTok (Douyin) merchants, offering features like influencer outreach, group registration, sample management, and data analysis. The Chinese description translates to functions like "invitation influencer, group registration, sample management, data analysis." The developer is listed as [email protected], and the extension has only 2 users on the Chrome Web Store.

The most striking feature of the CVEQ findings profile is the overwhelming volume of 1,688 IoC findings paired with zero malware signatures and zero code-smell findings. This is a textbook false-positive pattern. Examining the specific IoC findings confirms this: entries like t.set.call, e.data.agencyinfo.name, e.message.data, window.location.search, refs.evaluate.show, refs.corpsshop.show, and refs.xhscollect.show are not domains at all — they are JavaScript property-access chains misread by the XIOC extractor from minified or bundled code. None of these are legitimate network endpoints. The only real domain detected, www-hj.douyin.com, is an official TikDouin subdomain and perfectly consistent with the extension's stated purpose as a Douyin merchant tool.

The single manifest-analysis finding, MANIFEST-SENSITIVE-PERM-TABS, reflects the tabs permission declared in manifest.json. This permission is standard and expected for any extension that interacts with browser tabs to assist with merchant operations on Douyin. The single network finding in js/background.js:1 simply detects a fetch call in the background script — a routine operation for any extension that communicates with backend APIs, especially one performing data analysis and influencer outreach.

A skeptic might point to the two critical-severity findings and the extension's extremely low user count (2 users) as concerning signals. However, no details are provided about what those critical findings specifically entail, and in the complete absence of malware signatures, code smells, suspicious domains, or obfuscation concerns, there is no substantive evidence of malice. The low user count simply indicates a newly published or niche tool, not a threat.

The complete absence of malware signatures, combined with IoC findings that are demonstrably garbage extractions from bundled JavaScript, means this extension produces no actionable security concerns despite its inflated finding count.

Key Reasons

  • Zero malware signatures detected despite 1,688 IoC findings
  • IoC findings are property-access chains (t.set.call, e.message.data) misread from bundled JS, not real domains
  • Only real domain detected (www-hj.douyin.com) matches the extension's stated Douyin merchant-tool purpose
  • tabs permission and fetch call in background.js are standard for extensions interacting with web APIs

False Positive Considerations

  • XIOC extractor misreads JavaScript property/method chains as domain names (t.set.call, e.data.agencyinfo.name, etc.)
  • 1,688 IoC findings are entirely garbage extractions from bundled or minified code, not real network indicators
  • Zero malware signatures and zero code-smell findings despite high finding count
  • Single tabs permission flagged as sensitive despite being standard for browser extensions

Reviewed 2026-05-30; recommended action: suppress false positive; model confidence 88%.

Chrome version history

Risk trend by version

6 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.

Selected
76
Change since first
+30
Change from previous
-11
Versions:
First analyzed version
4.0.76
May 29, 2026
Risk range
46 to 87
Across analyzed versions
Latest analyzed version
4.1.57
Sep 18, 2026
Selected version
high
Version
v4.1.57
1 weeks ago
Risk score
76
Findings
4
Change vs previous
-11

Pick any point on the chart to explore that version's code below.

About This Extension

深受 100+ TikTok亿级卖家和 10万+ TikTok 卖家信赖的达人营销插件,专为 TikTok 达人营销与履约管理 打造。支持 自动化、批量建联邀约达人,基于海量达人与带货数据,高效完成合作管理、履约跟进与效果分析。(联系微信:597921058)

Frequently Asked Questions