Is "CheoX68 Reply PRO" on Chrome Web Store Safe to Install?

[email protected] · chrome · v1.2.0

CheoX68 Reply PRO is a tool for using Deepseek or gemini AI ...generate comment and auto comment a post of tweeter ( X ) like a human Kaito Yaps Snap Check AI Chat @cheox68

Risk Assessment

Analyzed
84.75
out of 100
HIGH

173 security findings detected across all analyzers

Chrome extension requesting 16 permissions

Severity Breakdown

0
Critical
0
High
117
Medium
56
Low
0
Info

Finding Categories

3
Network
108
IoC Indicators

YARA Rules Matched

7 rules(56 hits)
postinstall file manipulation postinstall network communication postinstall system command NoUseWeakRandom postinstall crypto operations postinstall file download postinstall persistence mechanism

Requested Permissions

16 permissions
activeTab
Medium
tabs
Medium
storage
Low
contextMenus
Low
alarms
Low
https://twitter.com/*
Low
https://x.com/*
Low
https://pro.x.com/*
Low
https://www.binance.com/*
Low
https://generativelanguage.googleapis.com/*
Low
https://openrouter.ai/*
Low
https://api.openai.com/*
Low
https://api.deepseek.com/*
Low
https://api.anthropic.com/*
Low
https://api.x.ai/*
Low
https://key.nodeaz.com/*
Low

About This Extension

CheoX68 Reply PRO is a tool for using Deepseek or gemini AI ...generate comment and auto comment a post of tweeter ( X ) like a human Kaito Yaps Snap Check AI Chat @cheox68

Detailed Findings

60 total

YARA Rule Matches

7 rules

Indicators of Compromise

Network indicators, suspicious strings, and potential IoCs extracted during analysis

URLs
45
IP Addresses
4
Domains
59
Strings
108

All Indicators · 108

Domain
detected Domain: generativelanguage.googleapis.com

XIOC detected Domain: generativelanguage.googleapis.com

extracted_from_files

Domain
detected Domain: rect.top

XIOC detected Domain: rect.top

extracted_from_files

Domain
detected Domain: this.save

XIOC detected Domain: this.save

extracted_from_files

Domain
detected Domain: chrome.runtime.id

XIOC detected Domain: chrome.runtime.id

extracted_from_files

Domain
detected Domain: manifest.name

XIOC detected Domain: manifest.name

extracted_from_files

Domain
detected Domain: date.now

XIOC detected Domain: date.now

extracted_from_files

Domain
detected Domain: key.nodeaz.com

XIOC detected Domain: key.nodeaz.com

extracted_from_files

IP
detected IP: ::af

XIOC detected IP: ::af

extracted_from_files

IP
detected IP: e::af

XIOC detected IP: e::af

extracted_from_files

IP
detected IP: ed::af

XIOC detected IP: ed::af

extracted_from_files

Domain
detected Domain: tweetcontent.author

XIOC detected Domain: tweetcontent.author

extracted_from_files

Domain
detected Domain: api.x.ai

XIOC detected Domain: api.x.ai

extracted_from_files

Domain
detected Domain: api.anthropic.com

XIOC detected Domain: api.anthropic.com

extracted_from_files

Domain
detected Domain: api.deepseek.com

XIOC detected Domain: api.deepseek.com

extracted_from_files

IP
detected IP: ::bef

XIOC detected IP: ::bef

extracted_from_files

URL
detected URL: https://makersuite.google.com/app/apikey

XIOC detected URL: https://makersuite.google.com/app/apikey

extracted_from_files

URL
detected URL: https://x.com/home

XIOC detected URL: https://x.com/home

extracted_from_files

URL
detected URL: https://x.com/*

XIOC detected URL: https://x.com/*

extracted_from_files

URL
detected URL: https://twitter.com/*',

XIOC detected URL: https://twitter.com/*',

extracted_from_files

URL
detected URL: https://x.com/*']

XIOC detected URL: https://x.com/*']

extracted_from_files

URL
detected URL: https://api.x.ai/v1/chat/completions',

XIOC detected URL: https://api.x.ai/v1/chat/completions',

extracted_from_files

URL
detected URL: https://platform.deepseek.com/api_keys

XIOC detected URL: https://platform.deepseek.com/api_keys

extracted_from_files

URL
detected URL: https://console.anthropic.com/

XIOC detected URL: https://console.anthropic.com/

extracted_from_files

URL
detected URL: https://docs.x.ai/docs/tutorial

XIOC detected URL: https://docs.x.ai/docs/tutorial

extracted_from_files

URL
detected URL: https://openrouter.ai/models

XIOC detected URL: https://openrouter.ai/models

extracted_from_files

URL
detected URL: https://platform.openai.com/docs/models

XIOC detected URL: https://platform.openai.com/docs/models

extracted_from_files

URL
detected URL: https://docs.x.ai/docs/models

XIOC detected URL: https://docs.x.ai/docs/models

extracted_from_files

Domain
detected Domain: types.news

XIOC detected Domain: types.news

extracted_from_files

URL
detected URL: https://www.binance.com/*/square/*

XIOC detected URL: https://www.binance.com/*/square/*

extracted_from_files

URL
detected URL: https://www.binance.com/*

XIOC detected URL: https://www.binance.com/*

extracted_from_files

URL
detected URL: https://makersuite.google.com/app/apikey'

XIOC detected URL: https://makersuite.google.com/app/apikey'

extracted_from_files

URL
detected URL: https://cdnjs.cloudflare.com/ajax/libs/font-awesome/6.0.0/css/all.min.css

XIOC detected URL: https://cdnjs.cloudflare.com/ajax/libs/font-awesome/6.0.0/css/all.min.css

extracted_from_files

URL
detected URL: https://key.nodeaz.com/pricing.php

XIOC detected URL: https://key.nodeaz.com/pricing.php

extracted_from_files

URL
detected URL: https://openrouter.ai/keys

XIOC detected URL: https://openrouter.ai/keys

extracted_from_files

URL
detected URL: https://platform.openai.com/api-keys

XIOC detected URL: https://platform.openai.com/api-keys

extracted_from_files

URL
detected URL: https://openrouter.ai/*

XIOC detected URL: https://openrouter.ai/*

extracted_from_files

URL
detected URL: https://api.openai.com/*

XIOC detected URL: https://api.openai.com/*

extracted_from_files

URL
detected URL: https://api.deepseek.com/*

XIOC detected URL: https://api.deepseek.com/*

extracted_from_files

URL
detected URL: https://api.anthropic.com/*

XIOC detected URL: https://api.anthropic.com/*

extracted_from_files

URL
detected URL: https://api.x.ai/*

XIOC detected URL: https://api.x.ai/*

extracted_from_files

URL
detected URL: https://key.nodeaz.com/*

XIOC detected URL: https://key.nodeaz.com/*

extracted_from_files

URL
detected URL: https://pro.x.com/*

XIOC detected URL: https://pro.x.com/*

extracted_from_files

URL
detected URL: https://cdnjs.cloudflare.com/ajax/libs/font-awesome/6.5.1/css/all.min.css');

XIOC detected URL: https://cdnjs.cloudflare.com/ajax/libs/font-awesome/6.5.1/css/all.min.css');

extracted_from_files

URL
detected URL: https://clients2.google.com/service/update2/crx

XIOC detected URL: https://clients2.google.com/service/update2/crx

extracted_from_files

URL
detected URL: https://twitter.com/*

XIOC detected URL: https://twitter.com/*

extracted_from_files

URL
detected URL: https://generativelanguage.googleapis.com/*

XIOC detected URL: https://generativelanguage.googleapis.com/*

extracted_from_files

URL
detected URL: https://api.anthropic.com/v1/messages

XIOC detected URL: https://api.anthropic.com/v1/messages

extracted_from_files

URL
detected URL: https://api.x.ai/v1/chat/completions

XIOC detected URL: https://api.x.ai/v1/chat/completions

extracted_from_files

URL
detected URL: https://generativelanguage.googleapis.com/v1beta/models/gemini-2.5-flash-lite:generateContent',

XIOC detected URL: https://generativelanguage.googleapis.com/v1beta/models/gemini-2.5-flash-lite:generateContent',

extracted_from_files

URL
detected URL: https://openrouter.ai/api/v1/chat/completions',

XIOC detected URL: https://openrouter.ai/api/v1/chat/completions',

extracted_from_files

URL
detected URL: https://api.openai.com/v1/chat/completions',

XIOC detected URL: https://api.openai.com/v1/chat/completions',

extracted_from_files

URL
detected URL: https://api.deepseek.com/v1/chat/completions',

XIOC detected URL: https://api.deepseek.com/v1/chat/completions',

extracted_from_files

URL
detected URL: https://api.anthropic.com/v1/messages',

XIOC detected URL: https://api.anthropic.com/v1/messages',

extracted_from_files

URL
detected URL: https://key.nodeaz.com/verify.php';

XIOC detected URL: https://key.nodeaz.com/verify.php';

extracted_from_files

URL
detected URL: https://generativelanguage.googleapis.com/v1beta/models/gemini-2.5-flash-lite:generateContent

XIOC detected URL: https://generativelanguage.googleapis.com/v1beta/models/gemini-2.5-flash-lite:generateContent

extracted_from_files

URL
detected URL: https://openrouter.ai/api/v1/chat/completions

XIOC detected URL: https://openrouter.ai/api/v1/chat/completions

extracted_from_files

URL
detected URL: https://t.me/+wWoIosScyUY0ZDNl

XIOC detected URL: https://t.me/+wWoIosScyUY0ZDNl

extracted_from_files

URL
detected URL: https://x.com

XIOC detected URL: https://x.com

extracted_from_files

URL
detected URL: https://api.openai.com/v1/chat/completions

XIOC detected URL: https://api.openai.com/v1/chat/completions

extracted_from_files

URL
detected URL: https://api.deepseek.com/v1/chat/completions

XIOC detected URL: https://api.deepseek.com/v1/chat/completions

extracted_from_files

Domain
detected Domain: keys.map

XIOC detected Domain: keys.map

extracted_from_files

Domain
detected Domain: a.click

XIOC detected Domain: a.click

extracted_from_files

Domain
detected Domain: api.openai.com

XIOC detected Domain: api.openai.com

extracted_from_files

Domain
detected Domain: tab.id

XIOC detected Domain: tab.id

extracted_from_files

Domain
detected Domain: openrouter.ai

XIOC detected Domain: openrouter.ai

extracted_from_files

Domain
detected Domain: mobile.twitter.com

XIOC detected Domain: mobile.twitter.com

extracted_from_files

URL
detected URL: https://key.nodeaz.com/verify.php

XIOC detected URL: https://key.nodeaz.com/verify.php

extracted_from_files

Domain
detected Domain: platform.openai.com

XIOC detected Domain: platform.openai.com

extracted_from_files

Domain
detected Domain: platform.deepseek.com

XIOC detected Domain: platform.deepseek.com

extracted_from_files

Domain
detected Domain: console.anthropic.com

XIOC detected Domain: console.anthropic.com

extracted_from_files

Domain
detected Domain: docs.x.ai

XIOC detected Domain: docs.x.ai

extracted_from_files

Domain
detected Domain: activetab.id

XIOC detected Domain: activetab.id

extracted_from_files

Domain
detected Domain: hometab.id

XIOC detected Domain: hometab.id

extracted_from_files

Domain
detected Domain: t.id

XIOC detected Domain: t.id

extracted_from_files

Domain
detected Domain: location.host

XIOC detected Domain: location.host

extracted_from_files

Domain
detected Domain: overlay.id

XIOC detected Domain: overlay.id

extracted_from_files

Domain
detected Domain: styletag.id

XIOC detected Domain: styletag.id

extracted_from_files

Domain
detected Domain: repostbutton.click

XIOC detected Domain: repostbutton.click

extracted_from_files

Domain
detected Domain: pro.x.com

XIOC detected Domain: pro.x.com

extracted_from_files

Domain
detected Domain: www.binance.com

XIOC detected Domain: www.binance.com

extracted_from_files

Domain
detected Domain: makersuite.google.com

XIOC detected Domain: makersuite.google.com

extracted_from_files

Domain
detected Domain: textarea.click

XIOC detected Domain: textarea.click

extracted_from_files

Domain
detected Domain: autoreplybtn.click

XIOC detected Domain: autoreplybtn.click

extracted_from_files

Domain
detected Domain: newreplybtn.click

XIOC detected Domain: newreplybtn.click

extracted_from_files

Domain
detected Domain: tweetbutton.click

XIOC detected Domain: tweetbutton.click

extracted_from_files

Domain
detected Domain: sendbtn.click

XIOC detected Domain: sendbtn.click

extracted_from_files

Domain
detected Domain: agg.total

XIOC detected Domain: agg.total

extracted_from_files

Domain
detected Domain: e.target

XIOC detected Domain: e.target

extracted_from_files

Domain
detected Domain: style.id

XIOC detected Domain: style.id

extracted_from_files

Domain
detected Domain: event.target

XIOC detected Domain: event.target

extracted_from_files

Domain
detected Domain: replybutton.click

XIOC detected Domain: replybutton.click

extracted_from_files

Domain
detected Domain: node.data

XIOC detected Domain: node.data

extracted_from_files

Domain
detected Domain: repostbtn.click

XIOC detected Domain: repostbtn.click

extracted_from_files

Domain
detected Domain: quotemenuitem.click

XIOC detected Domain: quotemenuitem.click

extracted_from_files

Domain
detected Domain: svg.bn

XIOC detected Domain: svg.bn

extracted_from_files

Domain
detected Domain: chrome.storage

XIOC detected Domain: chrome.storage

extracted_from_files

Domain
detected Domain: r.top

XIOC detected Domain: r.top

extracted_from_files

Domain
detected Domain: replybtn.click

XIOC detected Domain: replybtn.click

extracted_from_files

Domain
detected Domain: postbtn.click

XIOC detected Domain: postbtn.click

extracted_from_files

Domain
detected Domain: config.storage

XIOC detected Domain: config.storage

extracted_from_files

Domain
detected Domain: strings.consequences.map

XIOC detected Domain: strings.consequences.map

extracted_from_files

Domain
detected Domain: postcontent.author

XIOC detected Domain: postcontent.author

extracted_from_files

Domain
detected Domain: formattingrules.map

XIOC detected Domain: formattingrules.map

extracted_from_files

Domain
detected Domain: content.parts

XIOC detected Domain: content.parts

extracted_from_files

Domain
detected Domain: alarm.name

XIOC detected Domain: alarm.name

extracted_from_files

Domain
detected Domain: bnc-reply-toast.info

XIOC detected Domain: bnc-reply-toast.info

extracted_from_files

Domain
detected Domain: placeholder.click

XIOC detected Domain: placeholder.click

extracted_from_files

Domain
detected Domain: recent.map

XIOC detected Domain: recent.map

extracted_from_files

Security Analysis Summary

Security Analysis Overview

CheoX68 Reply PRO is a Chrome Web Store extension published by [email protected]. Version 1.2.0 has been analyzed by the Risky Plugins security platform, receiving a risk score of 84.75/100 (HIGH risk) based on 173 security findings.

Risk Assessment

This extension presents critical security risk. Severe issues were detected, potentially including malware indicators, exposed secrets, or dangerous behaviors. Installation is strongly discouraged until these issues are addressed.

Findings Breakdown

  • Medium: 117 finding(s)
  • Low: 56 finding(s)

What Was Analyzed

The security assessment covers multiple analysis categories:

  • Malware Detection: YARA rule matching against 2,400+ malware signatures
  • Secret Detection: Scanning for exposed API keys, tokens, and credentials
  • Static Analysis: Code-level security analysis for common vulnerability patterns
  • Network Analysis: Detection of suspicious network communications and endpoints
  • Obfuscation Detection: Identification of code obfuscation techniques

Developer Information

CheoX68 Reply PRO is published by [email protected] on the Chrome Web Store marketplace. The extension has approximately 55 users.

Recommendation

This extension is not recommended for installation without thorough manual review. Consider alternatives with lower risk scores, or contact the developer to address the identified security concerns.

Frequently Asked Questions