Stardance Utils
The AI review rates the findings as likely false positive, but the risk score (55/100) still counts them.
Analysis record
- Analysed
- 1 months ago
- Version
- v0.1.5
- Artifact
- SHA256 B0F…58D
- Source
- Findings (non-IoC)
Evidence ledger
Ranked by severity · findings with a source location link to the code viewer
YARA Rule Matches
10 rules| Severity | Rule | Hits | Files | Metadata |
|---|---|---|---|---|
| LOW | postinstall file download | 5 | projects.jsai-check.jsshared.js +2 more | - |
| LOW | SQLInjection | 1 | projects.js | - |
| LOW | NoUseWeakRandom | 2 | openai-verify.jsbackground.js | - |
| LOW | LocalStorageShouldNotBeUsed | 1 | shared.js | - |
| LOW | postinstall crypto operations | 3 | content.jsprojects.jsshared.js | - |
| LOW | postinstall system command | 8 | shop.jsprojects.jsopenai-verify.js +5 more | - |
| LOW | postinstall file manipulation | 11 | content.jsonboarding.jsshop.js +8 more | - |
| LOW | postinstall obfuscation | 3 | openai-verify.jsai-check.jsshared.js | - |
| LOW | postinstall network communication | 6 | content.jsopenai-verify.jsai-check.js +3 more | - |
| LOW | postinstall persistence mechanism | 1 | content.js | - |
Network Indicators
Concrete URLs, domains, IPs, emails, and hashes extracted from the analyzed artifact.
Network indicators are queued for lazy loading
Scroll this section into view to load the detailed rows.
Publisher Evidence
Limited evidenceHridya Agrawal
Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.
Firefox does not expose the same publisher verification data as IDE stores, so this score is deliberately conservative.
12 evidence rows available.
Finding Categories
YARA Rules Matched
10 rules(41 hits)Requested Permissions
8 permissionsAI Security Report
AI Security Review
Evidence context: threat category none; evidence quality moderate.
This Stardance utility extension shows 61 total findings, but the nature of these findings points to automated extraction errors rather than malicious behavior. The 57 IoC detections are dominated by known false positive patterns: property access chains misread as domains like date.now and stardance-utils-emoji-autocomplete-item.is, legitimate infrastructure domains including addons.mozilla.org and openai.com, and a marketing attribution service at ns.attribution.com. The email address [email protected] references Hack Club, a legitimate developer organization.
The four network findings in content.js (lines 394, 635, 1212, 1872) represent standard fetch calls that any functional browser extension requires. There are zero malware signatures, zero obfuscation detections, and zero code-smell findings—these are the indicators that actually matter when assessing malicious intent.
The only potentially concerning domain is clearbutton.click, which could be an affiliate or ad-serving domain. However, without accompanying malware signatures, credential access patterns, or obfuscation, a single domain reference does not establish malicious behavior. Many legitimate extensions integrate third-party services for analytics or attribution.
The strongest counterargument is the combination of an anonymous developer (empty developer name), zero users, and version 0.0.3 suggesting a newly published extension. These factors warrant caution, but they do not constitute evidence of malicious behavior. Anonymous publishers are common for utility extensions, and new extensions naturally have zero users initially. The absence of malware signatures and obfuscation in a codebase with 61 findings is itself evidence against malicious intent—actual malware typically triggers at least some signature or obfuscation detections.
The evidence quality is moderate because the IoC extractor produced mostly garbage findings while the actual security-relevant categories (malware signatures, obfuscation, credential patterns) all returned zero. The extension's description as a Stardance utility is consistent with the benign nature of the code patterns detected. Without evidence of credential theft, browser hijacking, proxyware functionality, or malware delivery, the high finding count should be dismissed as known false positive noise from the analysis pipeline.
Key Reasons
- Zero malware signatures despite 61 total findings
- Zero obfuscation detections
- IoCs are known false positive patterns (property chains, legitimate domains)
- No credential or session theft indicators
- Network findings are standard fetch calls
False Positive Considerations
- Property access chains misread as domains (date.now, .is suffixes)
- Legitimate infrastructure domains (mozilla.org, openai.com)
- Marketing attribution services (attribution.com)
- Email addresses extracted as IoCs (hackclub.com)
Reviewed 2026-06-03; recommended action: suppress false positive; model confidence 82%.
Firefox version history
Risk trend by version
5 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.
Pick any point on the chart to explore that version's code below.
Source Code Not Available
Source code is not available for this version of the extension.
About This Extension
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace
Flavortown Utils
Hridya Agrawal
Macondo Utils
Hridya Agrawal
VaultysHub extension
Vaultys
Kindredly - A safer, private web for families
Kindredly.ai
Malwarebytes Browser Guard
Malwarebytes
VHS - Dev Tools
Vihat Software