Firefox Add-ons

Stardance Utils

by Hridya Agrawal · 8 users · 5.0 rating
ade32a40-f156-5072-8c9a-b58099f01409 | v0.1.5
55/ 100
MEDIUM risk
+5 since v0.1.3
Analyst verdict
Review before use

The AI review rates the findings as likely false positive, but the risk score (55/100) still counts them.

Analysis record

Analysed
1 months ago
Version
v0.1.5
Artifact
SHA256 B0F…58D
Source
Findings (non-IoC)

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

48 detail rows

YARA Rule Matches

10 rules
SeverityRuleHitsFilesMetadata
LOWpostinstall file download 5
projects.jsai-check.jsshared.js +2 more
-
LOWSQLInjection 1
projects.js
-
LOWNoUseWeakRandom 2
openai-verify.jsbackground.js
-
LOWLocalStorageShouldNotBeUsed 1
shared.js
-
LOWpostinstall crypto operations 3
content.jsprojects.jsshared.js
-
LOWpostinstall system command 8
shop.jsprojects.jsopenai-verify.js +5 more
-
LOWpostinstall file manipulation 11
content.jsonboarding.jsshop.js +8 more
-
LOWpostinstall obfuscation 3
openai-verify.jsai-check.jsshared.js
-
LOWpostinstall network communication 6
content.jsopenai-verify.jsai-check.js +3 more
-
LOWpostinstall persistence mechanism 1
content.js
-

Network Indicators

Concrete URLs, domains, IPs, emails, and hashes extracted from the analyzed artifact.

36 total
...

Network indicators are queued for lazy loading

Scroll this section into view to load the detailed rows.

Publisher Evidence

Limited evidence

Hridya Agrawal

Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.

Firefox does not expose the same publisher verification data as IDE stores, so this score is deliberately conservative.

48
Noisy-finding weight
x1.00
Publisher domain
No domain
Missing
Store verification signal
Limited signal
Limited
Extension portfolio
12
Portfolio

12 evidence rows available.

Finding Categories

7
Network
36
IoC Indicators

YARA Rules Matched

10 rules(41 hits)
postinstall file download SQLInjection NoUseWeakRandom LocalStorageShouldNotBeUsed postinstall crypto operations postinstall system command postinstall file manipulation postinstall obfuscation postinstall network communication postinstall persistence mechanism

Requested Permissions

8 permissions
storage
Low
https://stardance.hackclub.com/*
Low
https://raffle.stardance.hackclub.com/*
Low
https://api.github.com/*
Low
https://openai.com/*
Low
https://openai.com/research/verify*
Low
https://openai.com/*/research/verify*
Low
https://openai.com/*-*/research/verify*
Low

AI Security Report

AI Security Review

Evidence context: threat category none; evidence quality moderate.

This Stardance utility extension shows 61 total findings, but the nature of these findings points to automated extraction errors rather than malicious behavior. The 57 IoC detections are dominated by known false positive patterns: property access chains misread as domains like date.now and stardance-utils-emoji-autocomplete-item.is, legitimate infrastructure domains including addons.mozilla.org and openai.com, and a marketing attribution service at ns.attribution.com. The email address [email protected] references Hack Club, a legitimate developer organization.

The four network findings in content.js (lines 394, 635, 1212, 1872) represent standard fetch calls that any functional browser extension requires. There are zero malware signatures, zero obfuscation detections, and zero code-smell findings—these are the indicators that actually matter when assessing malicious intent.

The only potentially concerning domain is clearbutton.click, which could be an affiliate or ad-serving domain. However, without accompanying malware signatures, credential access patterns, or obfuscation, a single domain reference does not establish malicious behavior. Many legitimate extensions integrate third-party services for analytics or attribution.

The strongest counterargument is the combination of an anonymous developer (empty developer name), zero users, and version 0.0.3 suggesting a newly published extension. These factors warrant caution, but they do not constitute evidence of malicious behavior. Anonymous publishers are common for utility extensions, and new extensions naturally have zero users initially. The absence of malware signatures and obfuscation in a codebase with 61 findings is itself evidence against malicious intent—actual malware typically triggers at least some signature or obfuscation detections.

The evidence quality is moderate because the IoC extractor produced mostly garbage findings while the actual security-relevant categories (malware signatures, obfuscation, credential patterns) all returned zero. The extension's description as a Stardance utility is consistent with the benign nature of the code patterns detected. Without evidence of credential theft, browser hijacking, proxyware functionality, or malware delivery, the high finding count should be dismissed as known false positive noise from the analysis pipeline.

Key Reasons

  • Zero malware signatures despite 61 total findings
  • Zero obfuscation detections
  • IoCs are known false positive patterns (property chains, legitimate domains)
  • No credential or session theft indicators
  • Network findings are standard fetch calls

False Positive Considerations

  • Property access chains misread as domains (date.now, .is suffixes)
  • Legitimate infrastructure domains (mozilla.org, openai.com)
  • Marketing attribution services (attribution.com)
  • Email addresses extracted as IoCs (hackclub.com)

Reviewed 2026-06-03; recommended action: suppress false positive; model confidence 82%.

Firefox version history

Risk trend by version

5 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.

Selected
55
Change since first
+5
Change from previous
+5
Versions:
First analyzed version
0.0.3
Jun 3, 2026
Risk range
49 to 55
Across analyzed versions
Latest analyzed version
0.1.5
Aug 26, 2026
Selected version
medium
Version
v0.1.5
1 months ago
Risk score
55
Findings
84
Change vs previous
+5

Pick any point on the chart to explore that version's code below.

About This Extension

The missing constellation of features. A growing suite of quality-of-life enhancements for the Stardance platform. From custom themes to project insights, keyboard shortcuts, and UI refinements and so much more, everything you wish Stardance already had. Current features: • Custom sidebar typography • More coming soon Designed to make the Stardance experience smoother, faster, and better looking.

Frequently Asked Questions