Firefox Add-ons Verified

OMICall

by Vihat Software · 1 users
b8a4e3ec-39cf-519f-9f0d-3646362ca685 | v2.0.40
58/ 100
MEDIUM risk
Risk verdict
Review before use

Score-based assessment (medium risk, 58/100). No analyst review available.

Analysis record

Analysed
3 months ago
Version
v2.0.40
Artifact
SHA256 5CE…8A3
Source
Findings (non-IoC)

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

3 detail rows

Network Indicators

Concrete URLs, domains, IPs, emails, and hashes extracted from the analyzed artifact.

328 total
...

Network indicators are queued for lazy loading

Scroll this section into view to load the detailed rows.

Publisher Evidence

Limited evidence

Vihat Software

Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.

Firefox does not expose the same publisher verification data as IDE stores, so this score is deliberately conservative.

42
Noisy-finding weight
x1.00
Publisher domain
vihatsoftware.com
Observed
Store verification signal
Limited signal
Limited
Extension portfolio
3
Portfolio

13 evidence rows available.

Finding Categories

1
Obfuscation
2
Network
328
IoC Indicators

Requested Permissions

4 permissions
<all_urls>

Access and modify data on every website you visit

Dangerous
activeTab
Medium
storage
Low
scripting
Low

AI Security Report

AI Security Review

Risky Plugins reviewed this extension with an AI-assisted security workflow on 2026-05-31. The review verdict is likely false positive with 80% confidence.

Recommended action: suppress false positive. Evidence context: threat category none; evidence quality moderate.

The OMICall extension has a large number of IoC findings, with 390 medium-severity IoC detections. However, upon closer inspection, these findings appear to be driven by the XIOC extractor, which is known to produce false positives. The detected domains, such as n.top-m.top, a.va, and r.iidxes.url.host, do not seem to be suspicious or malicious. Additionally, there are only two network findings, one of which is a fetch call to a Hubspot JavaScript file. There are no malware signatures or obfuscation findings that would indicate malicious intent. The extension's description and functionality suggest that it is a legitimate VoIP call feature extension. A potential counterargument could be that the large number of IoC findings indicates a potential threat, but given the nature of the findings and the lack of other suspicious indicators, it is likely that these findings are false positives. Therefore, the extension is likely a false positive.

Key Reasons

  • Large number of IoC findings driven by XIOC extractor
  • No malware signatures or obfuscation findings
  • Legitimate extension functionality and description

False Positive Considerations

  • IoC extractor garbage

Frequently Asked Questions