Macondo Utils
The AI review rates the findings as likely false positive, but the risk score (58/100) still counts them.
Analysis record
- Analysed
- 2 months ago
- Version
- v0.9.0
- Artifact
- SHA256 242…A9C
- Source
- Findings (non-IoC)
Evidence ledger
Ranked by severity · findings with a source location link to the code viewer
Network Indicators
Concrete URLs, domains, IPs, emails, and hashes extracted from the analyzed artifact.
Network indicators are queued for lazy loading
Scroll this section into view to load the detailed rows.
Publisher Evidence
Limited evidenceHridya Agrawal
Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.
Firefox does not expose the same publisher verification data as IDE stores, so this score is deliberately conservative.
12 evidence rows available.
Finding Categories
Requested Permissions
4 permissionsAI Security Report
AI Security Review
Evidence context: threat category none; evidence quality moderate.
Macondo Utils is a Firefox extension described as providing "quality-of-life improvements for Macondo, including better estimates, project labels, streak details, and goals tracking." The security findings are dominated by known false positive patterns rather than evidence of actual malicious behavior.
The most alarming statistic—166 IoC findings—is characteristic of the XIOC extractor's documented noise patterns. Of these 166 findings, only three specific domains are identified: 8.tj, 3.by, and w.tj (from findings titled XIOC-DOMAIN-8.tj, XIOC-DOMAIN-3.by, and XIOC-DOMAIN-w.tz). The remaining 163 IoC findings are almost certainly garbage artifacts: IPv6 fragments, property access chains misread as domains, or CDN infrastructure domains. This extraction noise is a well-documented issue with the tool and does not indicate malicious activity.
The nine network findings (NET-FETCH-content.js-1631, NET-FETCH-content.js-3664, NET-FETCH-content.js-3627, NET-FETCH-content.js-5383, NET-FETCH-content.js-1639, NET-FETCH-content.js-1623, NET-FETCH-content.js-3599, NET-FETCH-content.js-1615) are generic fetch call detections. These findings identify that content.js makes HTTP requests but do not reveal suspicious destinations. Any extension that communicates with a backend service will trigger these rules.
Critically, the findings show zero malware signatures and zero obfuscation findings. These are the actual indicators of malicious code. The absence of malware signatures means no known malicious patterns matched the extension's code. The absence of obfuscation means the code is readable and not attempting to hide its behavior.
The manifest analysis finding (MANIFEST-SENSITIVE-PERM-TABS in manifest.json) flags the tabs permission as potentially sensitive. This is a standard permission that legitimate productivity extensions require to read and modify webpage content. It is not inherently malicious.
Addressing the strongest counterargument: Critics might point to the anonymous developer (empty developer_name field) and unusual domains as evidence of risk. While the anonymous publisher is a legitimate concern, it alone does not indicate malicious intent. The three specific domains (8.tj, 3.by, w.tj) are unusual but cannot be confirmed as malicious without additional threat intelligence. More importantly, if this were a malicious extension, we would expect to see malware signatures, obfuscation, credential theft indicators, or typosquatting—none of which are present. The 166 IoC findings are a false alarm from a noisy detection system, not evidence of malicious behavior.
The extension's coherent description, lack of malware signatures, and absence of obfuscation strongly suggest this is a legitimate utility extension flagged by detection noise.
Key Reasons
- Zero malware signatures detected in the extension code
- Zero obfuscation findings—code is readable and not hiding behavior
- 166 IoC findings are characteristic of XIOC extractor noise, not actual malicious domains
- Network findings are generic fetch calls without suspicious destination evidence
- Extension has coherent description matching legitimate productivity utility purpose
False Positive Considerations
- XIOC extractor garbage (166 findings with only 3 specific domains)
- Generic network fetch detection rules
- Common manifest permission (tabs) flagged as sensitive
Reviewed 2026-06-03; recommended action: suppress false positive; model confidence 75%.
Firefox version history
Risk trend by version
5 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.
Pick any point on the chart to explore that version's code below.
Source Code Not Available
Source code is not available for this version of the extension.
About This Extension
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace
Flavortown Utils
Hridya Agrawal
Stardance Utils
Hridya Agrawal
VaultysHub extension
Vaultys
Kindredly - A safer, private web for families
Kindredly.ai
Malwarebytes Browser Guard
Malwarebytes
VHS - Dev Tools
Vihat Software