种草星球,TikTok批量建联,达人建联,达人管理,自动提报
The AI review rates the findings as likely false positive, but the risk score (76/100) still counts them.
Analysis record
- Analysed
- 1 weeks ago
- Version
- v4.1.57
- Artifact
- SHA256 20E…05C
- Source
- Findings (non-IoC)
Evidence ledger
Ranked by severity · findings with a source location link to the code viewer
YARA Rule Matches
1 rule| Severity | Rule | Hits | Files | Metadata |
|---|---|---|---|---|
| HIGH | supply chain sourcemap appended iife | 1 | js/chunk-vendors.js | - |
Publisher Evidence
Limited evidencePublisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.
Chrome does not expose the same publisher verification data as IDE stores, so this score is deliberately conservative.
12 evidence rows available.
Finding Categories
YARA Rules Matched
1 ruleRequested Permissions
46 permissionsAI Security Report
AI Security Review
Evidence context: threat category none; evidence quality weak.
种草星球 (Zhongcaoxingqiu) is a browser extension targeting Chinese TikTok (Douyin) merchants, offering features like influencer outreach, group registration, sample management, and data analysis. The Chinese description translates to functions like "invitation influencer, group registration, sample management, data analysis." The developer is listed as [email protected], and the extension has only 2 users on the Chrome Web Store.
The most striking feature of the CVEQ findings profile is the overwhelming volume of 1,688 IoC findings paired with zero malware signatures and zero code-smell findings. This is a textbook false-positive pattern. Examining the specific IoC findings confirms this: entries like t.set.call, e.data.agencyinfo.name, e.message.data, window.location.search, refs.evaluate.show, refs.corpsshop.show, and refs.xhscollect.show are not domains at all — they are JavaScript property-access chains misread by the XIOC extractor from minified or bundled code. None of these are legitimate network endpoints. The only real domain detected, www-hj.douyin.com, is an official TikDouin subdomain and perfectly consistent with the extension's stated purpose as a Douyin merchant tool.
The single manifest-analysis finding, MANIFEST-SENSITIVE-PERM-TABS, reflects the tabs permission declared in manifest.json. This permission is standard and expected for any extension that interacts with browser tabs to assist with merchant operations on Douyin. The single network finding in js/background.js:1 simply detects a fetch call in the background script — a routine operation for any extension that communicates with backend APIs, especially one performing data analysis and influencer outreach.
A skeptic might point to the two critical-severity findings and the extension's extremely low user count (2 users) as concerning signals. However, no details are provided about what those critical findings specifically entail, and in the complete absence of malware signatures, code smells, suspicious domains, or obfuscation concerns, there is no substantive evidence of malice. The low user count simply indicates a newly published or niche tool, not a threat.
The complete absence of malware signatures, combined with IoC findings that are demonstrably garbage extractions from bundled JavaScript, means this extension produces no actionable security concerns despite its inflated finding count.
Key Reasons
- Zero malware signatures detected despite 1,688 IoC findings
- IoC findings are property-access chains (t.set.call, e.message.data) misread from bundled JS, not real domains
- Only real domain detected (www-hj.douyin.com) matches the extension's stated Douyin merchant-tool purpose
- tabs permission and fetch call in background.js are standard for extensions interacting with web APIs
False Positive Considerations
- XIOC extractor misreads JavaScript property/method chains as domain names (t.set.call, e.data.agencyinfo.name, etc.)
- 1,688 IoC findings are entirely garbage extractions from bundled or minified code, not real network indicators
- Zero malware signatures and zero code-smell findings despite high finding count
- Single tabs permission flagged as sensitive despite being standard for browser extensions
Reviewed 2026-05-30; recommended action: suppress false positive; model confidence 88%.
Chrome version history
Risk trend by version
6 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.
Pick any point on the chart to explore that version's code below.
Source Code Not Available
Source code is not available for this version of the extension.
About This Extension
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace
种草星球-TikTok爆单神器,商品自动提报采集邀评【永久免费】
[email protected]
Edge Translate - Browser Translator | PDF Translation | MV3 | Open Source
[email protected]
Intelbras Cloud
[email protected]
SlingPlayer for DISH Anywhere
Unknown Developer
My Jobscore
[email protected]
Kindredly - A safer, private web for families
[email protected]